SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 333 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 333

Select 3Develop, implement, and monitor risk mitigation strategies

A financial services company stores regulated customer data in Snowflake and recently enabled access from several new BI tools and automation accounts. During a security review, the team discovers that some service users authenticate with only passwords, several legacy users still connect without network restrictions, and security administrators lack a centralized way to detect these risky configurations over time. The security engineer must reduce the likelihood of account compromise and establish ongoing monitoring with minimal disruption to existing workloads. Which TWO actions should the engineer take?

  1. A

    Create and enforce appropriate authentication policies so password-based users must use stronger authentication controls such as MFA where supported, and apply the policies to the relevant users or account.

  2. B

    Define network policies with allowed IP ranges for legacy users and service access paths, then assign those policies at the appropriate level to restrict where connections can originate.

  3. C

    Rotate all Snowflake object encryption keys manually every week and require users to upload customer-managed keys for each database to reduce login risk.

  4. D

    Use Snowsight/SQL to monitor security-related metadata and views such as users, login history, and policy assignments, and build recurring reviews or alerts for noncompliant accounts.

  5. E

    Grant SECURITYADMIN to BI tool service accounts so they can self-remediate failed logins and avoid business disruption.

Show answer and explanation

Correct answers: A, B, D

Explanation

The best answer combines preventive controls with detective monitoring. In Snowflake, authentication policies and network policies are practical, supported controls for reducing the attack surface associated with compromised credentials. Authentication-related policy enforcement helps address weak sign-in practices, while network policies constrain where users and service accounts can connect from. To satisfy the monitoring requirement, security engineers should regularly review account metadata and usage data, including login activity and policy assignment state, using Snowsight or SQL-based processes. This approach reflects Snowflake security best practices: apply least privilege, harden authentication, restrict network origins where appropriate, and continuously monitor for drift or noncompliance. Relevant Snowflake documentation areas include Authentication Policies, Network Policies, ACCOUNT_USAGE views such as LOGIN_HISTORY, and general security best practices for user and access management.

  • A. Correct.

    Correct. Authentication policies are a core Snowflake control for reducing account-compromise risk. They allow administrators to define sign-in related requirements and restrictions for users, helping enforce stronger authentication behavior and reduce reliance on password-only access. Applying authentication controls at the proper scope is a practical mitigation strategy because it directly addresses weak login posture while limiting disruption to unaffected identities.

  • B. Correct.

    Correct. Network policies are a standard Snowflake risk mitigation mechanism for restricting client access based on IP address rules. Applying them to legacy users or service access paths reduces exposure from stolen credentials by limiting where logins can originate. This is especially effective for service accounts and known enterprise egress locations.

  • C. Incorrect.

    Incorrect. This option mixes concepts and does not address the stated risk. Snowflake manages encryption of data at rest, and weekly manual rotation of object encryption keys is not a normal control for reducing login compromise risk. Customer-managed keys are an account-level Tri-Secret Secure capability, not something uploaded per database by users. Even where customer-managed keys are used, they do not mitigate weak authentication or unrestricted network access.

  • D. Correct.

    Correct. Monitoring is required in the scenario, and Snowflake provides metadata and account usage information that can be used to review users, authentication posture, login activity, and policy coverage over time. Building recurring reviews or alerts around LOGIN_HISTORY and user/policy metadata supports continuous detection of risky configurations and aligns with a risk mitigation lifecycle of implement plus monitor.

  • E. Incorrect.

    Incorrect. Granting SECURITYADMIN to BI tool service accounts violates least-privilege principles and increases risk substantially. Service accounts should have only the privileges needed for their workload. Failed logins should be addressed through proper authentication configuration, network policy design, and operational processes, not by expanding administrative privileges.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam