SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 344 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 344

Single answerTriage incoming alerts

A Snowflake Security Engineer receives an alert from a SIEM indicating that a service account executed multiple high-cost queries against sensitive finance tables outside its normal schedule. The engineer must quickly determine whether the activity is suspicious or part of an expected process before escalating. Which action should the engineer take FIRST to triage the alert most effectively?

  1. A

    Query ACCOUNT_USAGE views such as QUERY_HISTORY and ACCESS_HISTORY to validate what statements were run, which objects were accessed, and the client, user, and role context of the activity

  2. B

    Immediately rotate the service account credentials and revoke all of its roles to contain the event before gathering any additional evidence

  3. C

    Open a Snowflake support case and request that Snowflake confirm whether the queries were malicious

  4. D

    Drop the service account and recreate it with a new default role so future alerts are easier to investigate

Show answer and explanation

Correct answer: A

Explanation

Effective triage of incoming alerts in Snowflake begins with evidence-driven validation, not immediate disruption. For a suspicious query alert, the engineer should first inspect Snowflake's monitoring and governance metadata to answer key questions: What SQL actually ran? Which objects were accessed? Under which user and role? From what client or integration? Did the timing and pattern match a scheduled ETL or other known process? Snowflake documentation describes QUERY_HISTORY in ACCOUNT_USAGE and INFORMATION_SCHEMA for query execution details, and ACCESS_HISTORY for object-level access analysis. These sources are central to distinguishing true positives from benign operational activity. Only after establishing context and potential impact should the engineer decide whether containment actions such as revoking privileges, disabling users, rotating secrets, or escalating incident response are warranted.

  • A. Correct.

    Correct. The first step in triaging an incoming alert is to validate the event with authoritative telemetry. In Snowflake, ACCOUNT_USAGE views such as QUERY_HISTORY can show when the queries ran, who ran them, what warehouse was used, and other execution details. ACCESS_HISTORY can help determine which objects were actually accessed and whether the sensitive finance tables were referenced directly or indirectly. Reviewing user, role, client, and timing context helps distinguish expected automation from suspicious misuse before taking disruptive action.

  • B. Incorrect.

    Incorrect. Immediate containment may be appropriate after evidence confirms active compromise or unacceptable risk, but it is not the best first triage step here. Prematurely rotating credentials or revoking roles can disrupt legitimate production workloads and may destroy useful investigative context about the current session or process pattern. Triage should start by validating the alert and assessing impact using available Snowflake logs and metadata.

  • C. Incorrect.

    Incorrect. Snowflake Support does not perform incident triage on behalf of the customer to determine whether a given query pattern is malicious. The customer's security team should first inspect Snowflake telemetry and internal change records to assess whether the activity aligns with expected jobs, orchestration tools, or role usage. Support may be useful later for platform-specific issues, but not as the initial triage action.

  • D. Incorrect.

    Incorrect. Deleting and recreating the account is a drastic remediation step, not an initial triage action. It also risks unnecessary outage and loss of continuity in the investigation. Effective alert triage focuses first on evidence collection, scope determination, and validation of whether the activity deviates from approved service account behavior.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam