SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 309 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 309

Select 2Identify and catalog critical assets within Snowflake

A security engineer has been asked to create an inventory of the most critical data assets in Snowflake before implementing tighter access controls. The organization wants a repeatable approach that identifies which tables and columns contain sensitive data and ties that information to governance metadata that can later drive policy decisions. Which TWO actions should the engineer take to best meet this requirement?

  1. A

    Use Snowflake's sensitive data classification capabilities to scan target databases and schemas, then review the generated sensitivity metadata for tables and columns.

  2. B

    Apply tags to identified objects and use those tags as governance metadata to catalog critical assets and support downstream policy management.

  3. C

    Query WAREHOUSE_METERING_HISTORY to determine which tables are most critical based on compute consumption, and classify those as sensitive assets.

  4. D

    Rely on network policies to determine which schemas contain regulated data, since network policies are attached to the most critical assets.

  5. E

    Grant ACCOUNTADMIN to data stewards so they can manually inspect all objects and maintain the asset inventory in spreadsheets.

Show answer and explanation

Correct answers: A, B

Explanation

The best practice approach is to first discover likely sensitive data using Snowflake's classification capabilities and then persist governance context by applying tags to the relevant databases, schemas, tables, or columns. This supports an auditable and repeatable inventory of critical assets that can later drive masking, monitoring, and access governance. By contrast, warehouse usage data and network policies do not identify sensitive data assets, and broad ACCOUNTADMIN access undermines security. Relevant Snowflake documentation areas include data classification, object tagging, and governance features such as tag-based policy management.

  • A. Correct.

    Correct. Snowflake provides sensitive data classification capabilities that can inspect supported objects and identify likely sensitive data categories at the table and column level. This is a practical first step for discovering and cataloging critical assets because it produces metadata that security teams can review and validate rather than relying entirely on manual inspection.

  • B. Correct.

    Correct. Tags are a core Snowflake governance feature and are commonly used to label sensitive or business-critical data assets. After identifying sensitive objects, applying tags creates durable metadata that can be queried, reported on, and used with other governance controls such as tag-based masking policies, making this a strong approach for cataloging critical assets.

  • C. Incorrect.

    Incorrect. Warehouse metering history shows compute usage for warehouses, not data sensitivity or business criticality of specific tables and columns. High compute usage does not imply that an object contains regulated or sensitive data, so this would be a misleading basis for identifying critical assets.

  • D. Incorrect.

    Incorrect. Network policies control allowed network locations for user authentication to Snowflake; they are not a mechanism for discovering or cataloging sensitive schemas or tables. Choosing this option reflects a confusion between perimeter access controls and data governance metadata.

  • E. Incorrect.

    Incorrect. Granting ACCOUNTADMIN broadly violates least-privilege principles and is not an appropriate method for cataloging assets. Manual spreadsheet tracking is also error-prone and not scalable. Snowflake governance should rely on metadata, roles, and built-in capabilities instead of elevated administrative access for routine discovery tasks.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam