SnowPro Advanced: Security Engineer Question 298
Single answerSnowflake Compliance CenterA financial services company uses Snowflake to store customer data across several databases. The security team has enabled Snowflake Compliance Center to help identify regulated data and evaluate whether sensitive columns are properly protected. During an internal review, the team finds several columns containing personal data that were automatically classified but are not tagged with the organization's required governance tags. The team wants the fastest way to identify these gaps centrally and use the results to drive remediation workflows. Which Snowflake Compliance Center capability should they use?
- A
Use the Sensitive Data Status dashboard to review columns that have sensitivity classifications but are missing required tags
- B
Use Network Rules to compare classified columns against governance tag assignments across all databases
- C
Use Access History to automatically assign tags to columns that were classified as sensitive but not yet tagged
- D
Use the Login History view to identify users who queried classified columns without governance tags
Show answer and explanation
Correct answer: A
Explanation
This question tests whether the candidate understands the practical role of Snowflake Compliance Center in monitoring sensitive data governance posture, not just discovering data. Compliance Center surfaces findings that help organizations assess whether classified sensitive data is adequately governed, including whether expected controls such as tags are present. In this scenario, the requirement is to quickly identify gaps centrally and feed remediation workflows, which aligns with the Sensitive Data Status dashboard rather than operational security logs or unrelated networking controls. Snowflake best practices emphasize using data classification together with governance artifacts such as tags, masking policies, and monitoring views to operationalize protection of regulated data.
- A. Correct.
Correct. In Snowflake Compliance Center, the Sensitive Data Status dashboard is designed to provide a centralized view of sensitive data posture, including discovery and governance gaps such as classified columns that are not yet protected or tagged according to policy. This is the most direct capability for identifying missing governance coverage and prioritizing remediation.
- B. Incorrect.
Incorrect. Network Rules control allowed or blocked network locations for connectivity-related security configurations. They are not a Compliance Center feature for evaluating whether classified data has corresponding governance tags.
- C. Incorrect.
Incorrect. Access History is useful for auditing query activity and data access patterns, but it does not automatically assign governance tags to classified columns. Tagging and remediation workflows must be performed through appropriate governance processes and supporting features, not through Access History itself.
- D. Incorrect.
Incorrect. Login History tracks authentication events, not data classification or tagging posture. While login auditing can support security investigations, it does not help centrally identify columns that were classified as sensitive but are missing required governance tags.