SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 332 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 332

Select 3Develop, implement, and monitor risk mitigation strategies

A financial services company stores PCI-related data in Snowflake and recently discovered that several analysts were granted broad access through inherited roles. The security team must reduce the risk of future overexposure while preserving analysts' ability to work with approved datasets. They also want ongoing visibility into risky privilege changes so they can detect drift after remediation. Which TWO actions should the Security Engineer implement to best mitigate this risk?

  1. A

    Replace broad object grants with role-based access using least-privilege functional roles, and grant access to approved secure views instead of granting direct access to sensitive base tables where possible.

  2. B

    Grant analysts the SECURITYADMIN role so they can manage their own access requests without involving central administrators.

  3. C

    Use access history and account usage views to monitor privilege grants and query behavior related to sensitive objects after the new model is implemented.

  4. D

    Disable Time Travel on the database containing PCI data because historical retention increases the chance of unauthorized reads.

  5. E

    Create masking and row access policies for regulated columns and rows, and attach them to the relevant tables or views based on business need.

Show answer and explanation

Correct answers: A, C, E

Explanation

The best answer combines preventive controls with detective monitoring. Replacing broad grants with least-privilege role design and using secure views reduces the attack surface and limits unnecessary direct access to sensitive base objects. Applying masking and row access policies adds fine-grained protection for regulated columns and row subsets. Then, monitoring through Snowflake Account Usage and access history helps detect access anomalies and privilege drift over time. This aligns with Snowflake security best practices: use RBAC for least privilege, apply policy-based controls for sensitive data, and continuously monitor access and privilege changes. Relevant Snowflake documentation areas include Access Control Overview, Dynamic Data Masking, Row Access Policies, Secure Views, ACCESS_HISTORY, and ACCOUNT_USAGE views.

  • A. Correct.

    Correct. This is a core risk-mitigation strategy in Snowflake. Using least-privilege functional roles limits access to only the data and actions required for a user's job. Exposing approved secure views instead of base tables can further reduce risk by restricting visible columns and rows and by encapsulating business logic for safer consumption. This directly addresses the problem of broad inherited access.

  • B. Incorrect.

    Incorrect. SECURITYADMIN is a highly privileged system role that manages grants and roles across the account. Giving it to analysts would significantly increase risk rather than mitigate it. This option reflects a common misconception that decentralizing privilege management improves agility without increasing exposure.

  • C. Correct.

    Correct. Monitoring is required to ensure controls remain effective over time. Snowflake's ACCOUNT_USAGE and access-related views, including query and access history, can help identify who accessed sensitive data and whether grants changed unexpectedly. This supports ongoing detection of privilege drift and suspicious access patterns after remediation.

  • D. Incorrect.

    Incorrect. Disabling Time Travel is not an appropriate primary control for reducing analyst overexposure to active sensitive data. Time Travel is a data protection and recovery feature, not an access control mechanism. Unauthorized reads are governed by privileges and policies, not by whether historical versions exist.

  • E. Correct.

    Correct. Dynamic data masking and row access policies are native Snowflake controls that reduce exposure of regulated data even when users can query the object. They are appropriate compensating and preventive controls for PCI-related datasets, especially when different users need different levels of visibility. This supports both risk reduction and business continuity.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam