SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 327 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 327

Single answerUse Snowflake Horizon Catalog to enable security best practices and compliance

A financial services company is preparing for an internal compliance audit. The security team must quickly identify which data assets contain sensitive fields such as Social Security numbers and bank account numbers, ensure those assets have business context and ownership recorded, and enable governance teams to discover this information centrally across the Snowflake environment. The company wants to use Snowflake Horizon Catalog to support these security and compliance goals with minimal custom development. Which approach best meets these requirements?

  1. A

    Use Snowflake Horizon Catalog with sensitive data classification, apply tags to classified columns, and curate catalog metadata such as descriptions and owners so governance teams can search and review assets centrally.

  2. B

    Create network policies for all users and rely on login history to determine which tables are likely to contain regulated data, then document ownership in an external spreadsheet.

  3. C

    Enable Tri-Secret Secure and customer-managed keys so Horizon Catalog automatically infers data owners, classifies all regulated fields, and blocks noncompliant queries by default.

  4. D

    Use only object tags created manually on databases and schemas, because Horizon Catalog does not support centralized discovery of column-level sensitive data information.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use Snowflake Horizon Catalog together with Snowflake's data classification and tagging capabilities to centralize discovery of sensitive data and enrich assets with governance metadata. For security and compliance use cases, a practical pattern is: classify sensitive columns, apply tags to represent sensitivity or governance attributes, document ownership and business context in metadata, and allow governance teams to use the catalog for centralized search and review. This is far more effective than relying on external inventories or unrelated security controls such as network policies or encryption key features. Snowflake documentation and best practices emphasize combining discovery, classification, tagging, and metadata stewardship to improve governance posture, support compliance workflows, and make sensitive assets easier to find and manage.

  • A. Correct.

    Correct. This aligns with how Snowflake Horizon Catalog is used to improve governance and compliance visibility. Horizon Catalog provides centralized discovery and metadata visibility for Snowflake assets. In practice, organizations can use Snowflake's sensitive data classification capabilities to detect sensitive columns, apply tags to label and govern those data elements, and enrich objects with business metadata such as descriptions and ownership/stewardship information. This supports audit readiness, discoverability, and policy-driven governance with minimal custom development.

  • B. Incorrect.

    Incorrect. Network policies and login history address access controls and monitoring of authentication activity, not discovery of sensitive data content or cataloging of ownership and business context. An external spreadsheet also undermines centralized governance and becomes difficult to maintain. This option reflects a common misconception that perimeter controls and access logs can substitute for data discovery and catalog-based governance.

  • C. Incorrect.

    Incorrect. Tri-Secret Secure and customer-managed encryption keys are encryption and key management capabilities, not data cataloging or automated governance metadata features. They do not infer data owners, do not automatically classify all regulated fields for catalog purposes, and do not block queries by default through Horizon Catalog. This option mixes unrelated security features with governance/catalog functionality.

  • D. Incorrect.

    Incorrect. Manual tags can be useful, but the statement that Horizon Catalog does not support centralized discovery of column-level sensitive data information is false. Horizon Catalog is intended to improve discovery and understanding of Snowflake data assets, including governance metadata. Relying only on manually created tags at higher object levels would not best satisfy the requirement to quickly identify sensitive fields such as SSNs and bank account numbers.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam