SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 306 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 306

Single answer4.1 Perform threat modeling, identification, and analyses.

A financial services company is migrating a fraud analytics workload to Snowflake. The environment will store PCI-related transaction data and expose curated datasets to internal analysts, a third-party data science partner, and an application team that accesses Snowflake through service users. During a threat-modeling workshop, the security engineer is asked to identify the MOST significant threat that should be prioritized first because it could lead to broad unauthorized data exposure even if network controls are configured correctly. Which risk should the security engineer prioritize?

  1. A

    Users are assigned highly privileged roles such as ACCOUNTADMIN for routine querying and data sharing tasks, increasing the blast radius of credential compromise or misuse.

  2. B

    Snowflake virtual warehouses can auto-suspend after inactivity, which may delay query execution when analysts reconnect.

  3. C

    The company plans to use separate virtual warehouses for ETL and BI workloads, which could increase overall credit consumption.

  4. D

    Analysts will query large tables without clustering, which may reduce performance for selective filters.

Show answer and explanation

Correct answer: A

Explanation

This question tests the candidate's ability to distinguish true security threats from operational or cost concerns during threat modeling. In Snowflake, the most consequential risks often arise from identity, authentication, authorization, and governance failures rather than compute configuration. Because Snowflake uses role-based access control, overprivileged roles create a high-impact threat: if a user, service account, or partner identity is compromised, an attacker can access or grant access to sensitive data, modify security policies, or exfiltrate data across multiple databases and shares. Best practice is to apply least privilege, separate administrative duties, avoid routine use of high-level system roles, and grant only the minimum object privileges needed. Snowflake documentation and security best practices emphasize RBAC design, segregation of duties, and minimizing use of powerful built-in roles such as ACCOUNTADMIN for day-to-day tasks. In a threat-modeling exercise, this makes excessive privilege a higher-priority concern than warehouse tuning, clustering strategy, or credit consumption.

  • A. Correct.

    Correct. In threat modeling for Snowflake, excessive privilege assignment is a primary risk because Snowflake access is fundamentally controlled by roles and grants. If users or service principals routinely operate with powerful roles such as ACCOUNTADMIN, SECURITYADMIN, or similarly overprivileged custom roles, compromise of those credentials can result in broad data exposure, privilege escalation, grant manipulation, or policy changes. This remains a major threat even when network policies, private connectivity, or IP restrictions are in place, because a valid authenticated session with excessive authorization can still access sensitive objects. Prioritizing least privilege, role separation, and scoped access is a core mitigation.

  • B. Incorrect.

    Incorrect. Auto-suspend is a cost and usability behavior, not a primary security threat. While it can affect user experience due to warehouse resume latency, it does not materially increase the likelihood of unauthorized data exposure. A candidate might choose this if they confuse operational inconvenience with security risk.

  • C. Incorrect.

    Incorrect. Using separate warehouses for workload isolation is generally a good operational design choice and may improve performance governance. Although it can affect cost management, it is not a leading threat in a security-focused threat model for unauthorized access or data leakage. This distractor targets the misconception that all architecture decisions are security risks.

  • D. Incorrect.

    Incorrect. Lack of clustering can affect query performance and cost efficiency, but it is not a major security threat. Poor performance can have indirect operational impact, yet it does not inherently create unauthorized access paths. This option is plausible because performance issues are common in migrations, but they are not the highest-priority threat in this scenario.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam