SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 36 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 36

Single answerExternally-managed MFA

A security engineer is configuring Snowflake for a workforce that authenticates through an external identity provider (IdP) using SAML 2.0. The company requires MFA to be enforced by the IdP for all interactive user logins, and wants to avoid managing separate MFA enrollment inside Snowflake. During testing, users who sign in through the IdP can access Snowflake successfully, but the engineer wants to ensure the MFA requirement is enforced in a way that aligns with Snowflake best practices for externally-managed MFA. Which action should the engineer take?

  1. A

    Configure the security integration for the SAML IdP with MFA-related settings so Snowflake can verify the IdP performed MFA during authentication.

  2. B

    Enable Snowflake-native MFA for all federated users in addition to the IdP MFA policy so that Snowflake can enforce a second MFA challenge after SSO completes.

  3. C

    Set a network policy on the Snowflake account, because network policies are the required control Snowflake uses to detect whether MFA occurred at the IdP.

  4. D

    Create a session policy that limits session duration, because session policies are the primary mechanism Snowflake uses to confirm externally-managed MFA was completed.

Show answer and explanation

Correct answer: A

Explanation

In Snowflake, externally-managed MFA is used with federated authentication so that the external IdP, not Snowflake, performs the MFA challenge. To make this effective, the SAML federation configuration must be set up so Snowflake can trust and validate the authentication context provided by the IdP indicating that MFA occurred. This is the core implementation pattern for externally-managed MFA. Snowflake-native MFA is a separate feature and is generally not the right answer when the goal is to centralize MFA at the IdP and avoid duplicate enrollment. Network policies and session policies are valuable security controls, but they do not serve as evidence that MFA was completed. This aligns with Snowflake guidance on federated authentication, security integrations, and externally-managed MFA using an external identity provider.

  • A. Correct.

    Correct. For externally-managed MFA, Snowflake relies on the external IdP to perform MFA and to communicate the authentication context in the SAML assertion. The Snowflake security integration for federated authentication must be configured to expect and validate the MFA-related authentication context from the IdP. This aligns with the intended model for externally-managed MFA: the IdP is the MFA authority, while Snowflake trusts the federated assertion when properly configured.

  • B. Incorrect.

    Incorrect. Snowflake-native MFA and externally-managed MFA are different approaches. If the organization wants the IdP to enforce MFA and does not want separate MFA enrollment inside Snowflake, enabling Snowflake-native MFA for those federated users is not the best fit. It can also create unnecessary complexity and does not reflect the standard externally-managed MFA design.

  • C. Incorrect.

    Incorrect. Network policies restrict access based on IP addresses or related network conditions, but they do not indicate whether an IdP performed MFA. They are useful for reducing attack surface, not for validating MFA claims in SAML federation. This option reflects a common misconception that any access control at login can substitute for MFA verification.

  • D. Incorrect.

    Incorrect. Session policies help govern session behavior such as idle timeouts or session duration, but they do not validate whether MFA occurred at the external IdP. They are complementary hardening controls, not the mechanism for externally-managed MFA enforcement.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam