SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 30 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 30

Single answerImplement authenticators, passkeys, and IdP-driven access

A company uses Microsoft Entra ID as its corporate identity provider and wants all workforce users to access Snowsight through single sign-on. The security team also wants to reduce password-related risk by allowing users to sign in with phishing-resistant passkeys at the IdP, while ensuring Snowflake does not store or validate user passwords for these users. Which configuration best meets these requirements?

  1. A

    Configure a SAML2 security integration with Entra ID for Snowsight, set the affected Snowflake users to use the EXTERNALBROWSER authenticator, and enforce passkeys in Entra ID as part of the IdP sign-in policy.

  2. B

    Configure a SCIM integration with Entra ID, set the affected Snowflake users to use the SNOWFLAKE authenticator, and require users to register passkeys directly in Snowflake.

  3. C

    Configure a SAML2 security integration with Entra ID for Snowsight, set the affected Snowflake users to use the EXTERNAL_OAUTH authenticator, and enforce passkeys in Snowflake network policies.

  4. D

    Configure key-pair authentication for all users, set the affected Snowflake users to use the SNOWFLAKE_JWT authenticator, and rely on Entra ID to provide passkeys for interactive Snowsight login.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to federate Snowsight access with the enterprise IdP using a SAML2 security integration and use EXTERNALBROWSER for the workforce users who should authenticate through the IdP. In this design, authentication strength features such as passkeys, FIDO2, or other phishing-resistant methods are enforced by the IdP, not by Snowflake itself. This satisfies the requirement for IdP-driven access and avoids Snowflake-native password validation for those users.

Key distinctions that matter on the exam: SCIM handles identity lifecycle management, not login authentication; EXTERNAL_OAUTH is for OAuth token-based access, not the standard SAML browser SSO flow for Snowsight; and SNOWFLAKE_JWT with key-pair auth is for non-interactive or programmatic use cases rather than workforce SSO. These patterns are consistent with Snowflake documentation on federated authentication, security integrations, authenticators, and client authentication methods.

  • A. Correct.

    Correct. For IdP-driven workforce access to Snowsight, Snowflake commonly uses a SAML2 security integration with the enterprise IdP. Setting users to the EXTERNALBROWSER authenticator supports browser-based federated authentication flows through the external identity provider. If the organization wants phishing-resistant passkeys, those are implemented and enforced at the IdP layer, such as Entra ID authentication methods and conditional access policies. This approach aligns with the requirement that Snowflake not manage passwords for these federated users.

  • B. Incorrect.

    Incorrect. SCIM is for provisioning and deprovisioning users and groups, not for interactive authentication into Snowflake. The SNOWFLAKE authenticator means Snowflake-native username/password authentication, which directly conflicts with the requirement to avoid Snowflake-managed passwords. Also, passkeys are not registered directly in Snowflake for workforce login in this scenario; they are handled by the identity provider.

  • C. Incorrect.

    Incorrect. A SAML2 integration is relevant for SSO, but EXTERNAL_OAUTH is not the right authenticator for standard Snowsight workforce SAML sign-in. EXTERNAL_OAUTH is used for OAuth-based access patterns, typically for client applications using tokens issued by an external authorization server. Network policies control network access restrictions such as allowed IP addresses, not passkey enforcement.

  • D. Incorrect.

    Incorrect. Key-pair authentication with SNOWFLAKE_JWT is primarily for programmatic access, service users, and automation scenarios, not for human interactive sign-in to Snowsight. Even if Entra ID supports passkeys, that does not make SNOWFLAKE_JWT an appropriate mechanism for browser-based SSO into Snowsight.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam