SnowPro Advanced: Security Engineer Question 300
Single answerSecurity certificationsA healthcare company is performing vendor due diligence before moving protected health information (PHI) workloads to Snowflake. The security team must validate which formal third-party certifications or attestations Snowflake holds so they can map them to internal control requirements for healthcare, privacy, and general security governance. Which Snowflake assurance report or certification would be the MOST directly relevant for demonstrating support for handling healthcare-regulated workloads in this scenario?
- A
HITRUST CSF certification
- B
PCI DSS merchant certification
- C
FedRAMP High provisional authorization
- D
Common Criteria EAL4+ certification
Show answer and explanation
Correct answer: A
Explanation
For healthcare-oriented vendor due diligence, the most directly relevant Snowflake security certification in this set is HITRUST CSF certification. Snowflake publishes information about its compliance and security assurance programs, and candidates should be able to map certifications to the business problem rather than simply recognize certification names. In practice, healthcare organizations commonly review artifacts such as HITRUST, HIPAA-related documentation such as BAAs where applicable, and broader assurance reports like SOC 1/SOC 2 depending on their internal control framework. PCI DSS is centered on payment card data, FedRAMP is for U.S. government authorization contexts, and Common Criteria is not the typical cloud assurance evidence requested for PHI hosting decisions. This question tests the ability to select the certification that best matches the regulated workload and industry context, which is consistent with Snowflake security best practices and published compliance documentation.
- A. Correct.
Correct. HITRUST CSF is directly relevant to healthcare-focused security and compliance due diligence because it maps to healthcare and broader security control frameworks and is commonly requested when organizations evaluate platforms for workloads involving PHI. For a healthcare company trying to assess Snowflake's certifications in the context of regulated healthcare data, HITRUST is the most directly aligned option among those listed.
- B. Incorrect.
Incorrect. PCI DSS relates to protecting payment card data environments, not specifically healthcare-regulated workloads or PHI. While PCI compliance can be important for organizations that process cardholder data, it does not most directly address the healthcare assurance objective described in the scenario.
- C. Incorrect.
Incorrect. FedRAMP authorization is aimed at U.S. federal government cloud use. Even if a platform has certain government-related authorizations, FedRAMP High is not the most directly relevant assurance artifact for a private healthcare company evaluating PHI workload alignment. In addition, choosing this option would reflect a common mistake of selecting a rigorous certification that is not tied to the actual regulatory context in the question.
- D. Incorrect.
Incorrect. Common Criteria EAL certifications are generally associated with evaluation of specific IT products against security functional requirements, not the kind of cloud service assurance healthcare compliance teams typically request for PHI vendor due diligence. This option is plausible because it sounds security-focused, but it is not the most relevant fit for the scenario.