SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 325 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 325

Select 34.2 Perform risk assessment and manage risk.

A financial services company stores regulated customer data in Snowflake and has identified the following risks during a quarterly security review: service accounts use long-lived passwords, a broad custom role can both read sensitive tables and create outbound network rules for external access, and there is limited visibility into whether privileged users are making direct changes outside approved deployment pipelines. The security engineer must recommend controls that most effectively reduce these risks while preserving operational continuity. Which TWO actions should the engineer recommend?

  1. A

    Replace password-based service account authentication with key-pair authentication, and enforce periodic key rotation for those accounts

  2. B

    Split the broad custom role into separate least-privilege roles so data access privileges are separated from network and integration administration privileges

  3. C

    Disable ACCOUNTADMIN for all users and move all administrative tasks to SYSADMIN because SYSADMIN can fully replace ACCOUNTADMIN for security operations

  4. D

    Rely on masking policies alone to reduce the risk of privileged misuse, because administrators with object privileges will be prevented from viewing clear-text data in all cases

  5. E

    Implement monitoring and review of account usage and access history to detect privileged changes and direct access patterns outside approved processes

Show answer and explanation

Correct answers: A, B, E

Explanation

The best answers are 1, 2, and 5 because they directly map to the identified risks using standard security engineering principles: strong authentication, least privilege/separation of duties, and monitoring/detection. For Snowflake, best practices include minimizing password use for service accounts in favor of stronger programmatic authentication methods such as key-pair authentication; reducing privilege concentration through role-based access control; and using Snowflake metadata views and governance-related access history to review privileged behavior and data access patterns. Option 3 is attractive because limiting ACCOUNTADMIN is recommended, but it overstates SYSADMIN's role and is not a precise or sufficient risk treatment. Option 4 overrelies on masking policies, which are valuable for data protection but do not replace broader controls needed for risk management. Relevant Snowflake guidance includes documentation and best practices around key-pair authentication, system-defined roles and least-privilege role design, and auditing/monitoring through account usage and access history.

  • A. Correct.

    Correct. For service principals and non-interactive access, key-pair authentication is a stronger alternative to long-lived passwords because it reduces password exposure risk and supports managed rotation practices. This directly addresses the identified risk around service accounts using static credentials. In Snowflake, key-pair authentication is a common best practice for programmatic access, especially when combined with governance over private key storage and rotation.

  • B. Correct.

    Correct. This is a classic risk reduction control based on least privilege and separation of duties. A single role that can both read sensitive data and administer outbound connectivity creates excessive concentration of privilege and increases the blast radius of misuse or compromise. Separating data access from network/integration administration reduces insider and credential-compromise risk without removing needed capabilities from the organization.

  • C. Incorrect.

    Incorrect. Although reducing use of ACCOUNTADMIN is a valid best practice, this option is wrong because SYSADMIN is not a full replacement for ACCOUNTADMIN in all security and account-level administrative scenarios. Certain account-level security operations require higher-level administrative privileges. The misconception is that simply moving everything to SYSADMIN eliminates risk; in practice, Snowflake recommends limiting and tightly controlling ACCOUNTADMIN usage rather than assuming it can be eliminated for all functions.

  • D. Incorrect.

    Incorrect. Masking policies are an important data protection mechanism, but they are not a complete control for privileged misuse in all cases. Depending on role design, policy context, ownership, and administrative capabilities, masking does not by itself solve the broader risk of excessive privilege or unauthorized configuration changes. The misconception is treating masking as a substitute for role separation, authentication hardening, and monitoring.

  • E. Correct.

    Correct. Risk management includes detective controls in addition to preventive controls. Monitoring Snowflake usage metadata, query activity, and access history helps identify direct privileged access, object changes, or deviations from approved deployment pipelines. This addresses the stated lack of visibility and supports ongoing risk assessment, incident detection, and auditability.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam