SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 347 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 347

Single answerIsolate affected user accounts

A Snowflake security engineer discovers that a contractor's Snowflake user account was used from an unexpected network location and executed several queries against sensitive tables. The contractor should no longer have access while the incident is investigated, but the account's objects, ownership, and audit trail must remain intact for forensic review. Which action should the engineer take first to isolate the affected account with the least operational impact?

  1. A

    Set the user's DISABLED property to TRUE.

  2. B

    Drop the user immediately to prevent any further access.

  3. C

    Revoke all roles currently granted to the user.

  4. D

    Rotate the password and clear any MFA enrollment on the user.

Show answer and explanation

Correct answer: A

Explanation

For isolating an affected Snowflake user account during a security incident, the preferred first action is to disable the user by setting DISABLED = TRUE. This blocks authentication while preserving the user object and its associated metadata for investigation. In incident response, containment should be fast, targeted, and reversible. Dropping the user is too destructive for an initial response, and revoking roles addresses authorization rather than account access. Credential rotation may be part of remediation later, but it is not as immediate or definitive as disabling the account. This aligns with Snowflake user management practices documented for ALTER USER, including the ability to disable user access without deleting the account.

  • A. Correct.

    Correct. Setting a Snowflake user's DISABLED property to TRUE is the most direct way to prevent that user from authenticating while preserving the account, its ownership relationships, and historical activity for investigation. This is the standard containment action when isolating a suspected compromised user account. It minimizes collateral impact compared with deleting the user or making broad privilege changes that can complicate incident response.

  • B. Incorrect.

    Incorrect. Dropping the user is not the best first step for isolation during an investigation. Although it removes access, it is destructive and can complicate forensic analysis, object ownership review, and later recovery steps. Incident response best practice is to contain first in a reversible manner, then perform deeper remediation after scope and impact are understood.

  • C. Incorrect.

    Incorrect. Revoking all granted roles may reduce what the user can do after login, but it does not fully isolate the account because the user may still be able to authenticate. It also creates more administrative churn and can interfere with understanding the user's prior privilege posture during the investigation. Disabling the user is a cleaner containment step.

  • D. Incorrect.

    Incorrect. Rotating the password and clearing MFA can affect future authentication, but this is not the most reliable first containment measure. If the session is already active or the user has other valid authentication methods configured, simply changing credentials may not immediately isolate the account. Also, clearing MFA weakens authentication controls and is not a standard containment action.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam