SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 31 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 31

Single answerDefine, configure, and enforce Multi-Factor Authentication (MFA):

A security engineer at a company using Snowflake needs to tighten interactive access for privileged users. The company uses native Snowflake authentication for ACCOUNTADMIN and SECURITYADMIN users, while most developers authenticate through federated SSO. The requirement is to ensure that privileged users must complete a second authentication factor when signing in to Snowsight or the Classic Console, without disrupting existing SSO-based access for other users. Which action should the security engineer take?

  1. A

    Configure a network policy that allows privileged users to connect only from corporate IP ranges, because network policies enforce MFA for native Snowflake logins.

  2. B

    Alter each privileged user to require MFA for Snowflake client connections and web login, using Snowflake’s user-level MFA setting for accounts that use native authentication.

  3. C

    Create a session policy with a short idle timeout and attach it to privileged users, because session policies trigger MFA re-verification for sensitive roles.

  4. D

    Enable MFA only at the identity provider, because Snowflake cannot enforce MFA for users authenticated natively through Snowflake credentials.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to enforce MFA on the specific privileged users who authenticate natively with Snowflake. This is the most targeted solution because it strengthens access for ACCOUNTADMIN and SECURITYADMIN users while leaving existing federated SSO workflows unchanged for the rest of the organization. In Snowflake, MFA is relevant to interactive user authentication and is distinct from controls such as network policies and session policies. Network policies limit source IPs, and session policies govern session lifecycle behavior, but neither provides a second authentication factor. Best practice for privileged access is to require MFA for human administrators, especially when they use native Snowflake credentials. Snowflake documentation on user authentication and MFA describes configuring MFA for native users and separately integrating federated authentication with an IdP when MFA is managed externally.

  • A. Incorrect.

    Incorrect. Network policies restrict where users can connect from by IP address, but they do not enforce multi-factor authentication. They are commonly used as a compensating control for location-based access restriction, not as an MFA mechanism.

  • B. Correct.

    Correct. For users authenticating with native Snowflake username/password credentials, Snowflake supports user-level MFA enrollment and enforcement for interactive sign-in experiences such as Snowsight and the Classic Console. Applying MFA to the privileged native-authenticated users meets the requirement without changing the federated SSO experience for the broader developer population.

  • C. Incorrect.

    Incorrect. Session policies control session behavior such as idle timeout and session duration. They do not add a second authentication factor or force MFA during login. A short timeout may reduce exposure from unattended sessions, but it does not satisfy an MFA requirement.

  • D. Incorrect.

    Incorrect. MFA can be enforced through an external identity provider for federated SSO users, but Snowflake also supports MFA for users authenticated directly by Snowflake. This option reflects the misconception that MFA is only possible through SSO.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam