SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 313 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 313

Select 3Apply threat modeling methodologies to identify potential threats specific to Snowflake:

A financial services company is migrating a highly regulated analytics platform to Snowflake. The security engineer is leading a STRIDE-based threat modeling workshop for a new architecture that includes Snowflake databases, external stages in cloud object storage, service accounts used by ETL tools, and BI users connecting through SSO. The team identifies the following concerns and wants to prioritize the ones that are most specific to Snowflake’s security model and data access patterns. Which TWO threats should be treated as the most relevant Snowflake-specific risks in this scenario?

  1. A

    A role granted broad USAGE and SELECT privileges could inherit access through Snowflake’s RBAC hierarchy and expose sensitive tables to unintended users if role design is not carefully constrained.

  2. B

    An attacker could exploit a missing host-based firewall rule on the Snowflake virtual warehouse to gain shell access to the compute nodes and extract cached table data.

  3. C

    Misconfigured external stage access or storage integration trust settings could allow unauthorized access to data files in cloud storage used by Snowflake loading and unloading workflows.

  4. D

    A compromised BI user session could bypass all Snowflake authorization checks because SSO authentication disables role-based access control after login.

  5. E

    Long-lived credentials for programmatic service accounts, if not rotated or replaced with stronger authentication patterns, could be abused to access Snowflake data and perform actions under a trusted identity.

Show answer and explanation

Correct answers: A, C, E

Explanation

The best answers are 1, 3, and 5 because they focus on threat surfaces that are highly relevant to real Snowflake deployments: RBAC design and privilege inheritance, data movement through external stages/storage integrations, and non-human identity security for programmatic access. In a STRIDE exercise, these map well to Spoofing, Tampering, Information Disclosure, and Elevation of Privilege. Snowflake security best practices emphasize least privilege with roles, careful management of grants and inherited access, and secure configuration of external stages and storage integrations because Snowflake commonly interacts with cloud object storage for loading and unloading data. They also emphasize strong authentication and disciplined handling of service credentials. By contrast, option 2 is incorrect because Snowflake does not expose customer-manageable compute hosts, and option 4 is incorrect because SSO affects authentication, not the enforcement of Snowflake roles and privileges. Relevant Snowflake documentation areas include Access Control Overview, Role-Based Access Control, storage integrations and external stages, and authentication/security best practices for users and service accounts.

  • A. Correct.

    Correct. This is a core Snowflake-specific threat area. Snowflake relies heavily on role-based access control, including role hierarchy and privilege inheritance. In a threat model, excessive grants, inherited privileges, and poorly separated functional roles are realistic attack paths that can lead to unauthorized disclosure of regulated data. This aligns with threats in the Elevation of Privilege and Information Disclosure categories in STRIDE.

  • B. Incorrect.

    Incorrect. Customers do not manage host-based firewalls or gain shell access to Snowflake-managed compute nodes. Snowflake is a managed service, and virtual warehouses are not exposed to customers as operating systems they can log into or harden with network firewall rules. This distractor reflects an on-premises or IaaS mindset rather than Snowflake’s shared responsibility model.

  • C. Correct.

    Correct. External stages and storage integrations are a major Snowflake-specific threat surface because data movement often crosses trust boundaries between Snowflake and cloud object storage. If bucket/container permissions, IAM trust policies, or integration configuration are too broad, attackers may access staged files outside intended workflows. This is a practical Information Disclosure and Tampering concern in Snowflake environments.

  • D. Incorrect.

    Incorrect. SSO authenticates the user, but it does not disable Snowflake authorization. After authentication, Snowflake still enforces roles and object privileges. A compromised session is still a valid threat, but the statement is wrong because it claims authorization checks are bypassed entirely. The misconception is confusing authentication federation with authorization enforcement.

  • E. Correct.

    Correct. Service accounts used by ETL tools are common in Snowflake deployments, and long-lived passwords or keys increase the risk of credential theft and misuse. In threat modeling, trusted non-human identities should be evaluated for spoofing and privilege abuse. Snowflake best practices favor stronger authentication controls and limiting account privileges, making this a realistic Snowflake-specific risk.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam