SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 34 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 34

Single answerSnowflake-managed MFA

A security engineer is preparing to enforce stronger authentication for Snowflake users who sign in through the Snowflake web interface and SnowSQL. The company does not use a federated IdP for all users, so they want Snowflake to manage the second factor directly. They also want to avoid disrupting service accounts used for automated jobs. Which approach best meets these requirements?

  1. A

    Configure a network policy to allow only corporate IP ranges; this replaces the need for MFA for interactive users while keeping service accounts unchanged.

  2. B

    Enable Snowflake-managed MFA for the account, require eligible human users to enroll a second factor for supported clients, and keep non-interactive service accounts on key-pair authentication instead of MFA.

  3. C

    Create a session policy with a short idle timeout and attach it to all users; this enforces MFA prompts for both interactive users and service accounts.

  4. D

    Require all users, including service accounts, to use Snowflake-managed MFA and store the rotating MFA codes securely in the orchestration platform.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to enable Snowflake-managed MFA for interactive users who authenticate directly to Snowflake, while excluding unattended automation from interactive MFA workflows by using key-pair authentication for service accounts. This aligns with Snowflake security best practices: MFA is a strong control for human users, but automated processes should use secure non-interactive authentication methods rather than trying to bypass or simulate MFA. Network policies and session policies are useful complementary controls, but they do not enforce a second factor. In Snowflake documentation, Snowflake-managed MFA is positioned as an account-level capability for direct Snowflake authentication in supported clients, while key-pair authentication is the recommended approach for programmatic access and service accounts.

  • A. Incorrect.

    Incorrect. Network policies restrict where connections can originate, but they do not provide a second authentication factor and do not replace MFA. This is a common misconception because IP allowlists are often part of a layered security model, but they are not an authentication control equivalent to MFA.

  • B. Correct.

    Correct. Snowflake-managed MFA is designed for interactive user authentication in supported Snowflake clients. For human users who authenticate directly to Snowflake, enabling Snowflake-managed MFA is the right approach. Service accounts used by automation should not rely on interactive MFA flows; best practice is to use non-interactive authentication such as key-pair authentication for those accounts so scheduled jobs are not disrupted.

  • C. Incorrect.

    Incorrect. Session policies control session behavior such as idle timeout and session duration, but they do not trigger or enforce MFA challenges. Someone might choose this option because session controls are security-related, but they are separate from authentication factor requirements.

  • D. Incorrect.

    Incorrect. Requiring service accounts to use MFA is operationally unsound because Snowflake-managed MFA is intended for interactive user sign-ins, not unattended automation. Attempting to capture and reuse MFA codes in an orchestration platform undermines the purpose of MFA and is not an appropriate design for service principals or batch jobs.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam