SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 32 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 32

Single answerDefine, configure, and enforce Multi-Factor Authentication (MFA):

A security engineer at a company using Snowflake native authentication must strengthen interactive sign-in security for human users. The company wants MFA enforced for all employees who sign in through the Snowflake web interface and SnowSQL, but service accounts used by automated jobs must continue to authenticate non-interactively without MFA prompts. Which approach best meets these requirements?

  1. A

    Create or update an authentication policy that requires MFA for users authenticating with password-based sign-in, assign the policy to employee users or their account scope, and keep service accounts out of that policy or migrate them to key-pair authentication.

  2. B

    Enable MFA at the warehouse level so that any user running queries from the web interface or SnowSQL must complete MFA before the warehouse starts.

  3. C

    Configure a network policy to allow only corporate IP ranges; this enforces MFA for employees while exempting service accounts that connect from approved subnets.

  4. D

    Require users to rotate passwords every 30 days and disable client session caching in SnowSQL; this provides equivalent protection to MFA while preserving automation.

Show answer and explanation

Correct answer: A

Explanation

The best solution is to use Snowflake authentication policies to require MFA for human users who authenticate with native username/password sign-in, while treating service accounts separately so automated processes are not disrupted. In practice, organizations commonly enforce MFA for workforce identities and move non-human accounts away from password-based authentication to stronger non-interactive methods such as key-pair authentication. This aligns with Snowflake security best practices: use MFA for interactive user access, use authentication policies to define and enforce sign-in requirements, and avoid using human-style password authentication for service accounts where automation is required. Network policies and password rotation are complementary controls, but they do not satisfy the requirement to define and enforce MFA.

  • A. Correct.

    Correct. In Snowflake, MFA enforcement for native password-based sign-ins is handled through authentication policies, which can define MFA requirements. This is the appropriate control for interactive human access through Snowsight/classic web UI and supported clients such as SnowSQL when using username/password authentication. To avoid breaking automation, service accounts should either be excluded from the MFA-enforced scope or, preferably, use a non-interactive method such as key-pair authentication instead of password-based login.

  • B. Incorrect.

    Incorrect. MFA is not configured or enforced at the warehouse level. Warehouses control compute resources, not authentication behavior. A candidate might choose this option if they confuse execution controls with identity controls, but Snowflake authentication settings are managed through security features such as authentication policies, not virtual warehouse configuration.

  • C. Incorrect.

    Incorrect. Network policies restrict which IP addresses can connect, but they do not enforce MFA. Limiting access by source network is a useful layered security measure, yet it is not a substitute for multi-factor authentication. This option reflects a common misconception that trusted network location can replace identity verification.

  • D. Incorrect.

    Incorrect. Password rotation and client session settings can improve hygiene, but they do not provide a second authentication factor. MFA specifically requires an additional factor beyond the password. Disabling caching may increase login frequency, but it still does not meet the requirement to enforce MFA for interactive users.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam