SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 370 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 370

Select 3Establish a chain of custody for evidence

A security engineer is responding to a suspected insider data exfiltration incident in Snowflake. The legal team has instructed the engineer to preserve evidence so it can be used in a formal investigation and potentially in court. The engineer needs to establish a defensible chain of custody for Snowflake evidence while minimizing the risk of alteration. Which actions should the engineer take?

  1. A

    Query the relevant ACCOUNT_USAGE and INFORMATION_SCHEMA views, export the results to controlled storage, record who collected them and when, and calculate hashes for the exported files.

  2. B

    Rely on screenshots of Snowsight history pages because they are easier for nontechnical reviewers to understand than exported query results.

  3. C

    Restrict evidence handling to a small set of authorized personnel, document every transfer or access event, and store the evidence in a write-protected or tightly access-controlled repository.

  4. D

    Update suspicious user objects and revoke privileges first, then collect historical evidence later from the modified environment because Snowflake retains all metadata indefinitely.

  5. E

    Use Time Travel or CLONE to preserve relevant tables as close to the incident time as possible, and document the exact timestamps, object names, and the personnel performing the preservation.

Show answer and explanation

Correct answers: A, C, E

Explanation

To establish a chain of custody for Snowflake evidence, the engineer should preserve relevant evidence promptly, document every collection and handling step, restrict access, and protect evidence integrity. In Snowflake, practical sources of evidence often include ACCOUNT_USAGE views, INFORMATION_SCHEMA views, access history where enabled, query history, login history, and preserved table states using CLONE or Time Travel where appropriate. Best practice is to export evidence to controlled storage, record timestamps, collectors, methods, and hashes, and maintain an auditable log of each transfer or access. Screenshots alone are insufficient as primary evidence because they lack completeness and strong integrity controls. It is also incorrect to assume Snowflake retains all metadata indefinitely; retention and latency vary by view and feature. Relevant Snowflake documentation includes usage views in ACCOUNT_USAGE, INFORMATION_SCHEMA, Access History, Query History, Login History, Time Travel, and CLONE behavior. These capabilities support evidence preservation, but a defensible chain of custody depends on disciplined forensic process around them.

  • A. Correct.

    Correct. A defensible chain of custody requires documenting how evidence was collected, by whom, when, and how integrity was preserved. Exporting query results from Snowflake system views such as ACCOUNT_USAGE or applicable INFORMATION_SCHEMA views can preserve relevant activity records, and hashing the exported files helps demonstrate they were not altered after collection. Controlled storage and collector logs are core forensic handling practices.

  • B. Incorrect.

    Incorrect. Screenshots may be useful as supporting material, but they are not a strong primary evidence format for forensic preservation. They are harder to validate for completeness and integrity, are less searchable, and do not by themselves establish a robust chain of custody. Exported structured records with documented handling are more defensible.

  • C. Correct.

    Correct. Chain of custody is fundamentally about maintaining documented control over evidence from collection through analysis and storage. Limiting handling to authorized personnel, logging each access or transfer, and using protected storage reduces opportunities for tampering and helps prove integrity and accountability throughout the investigation.

  • D. Incorrect.

    Incorrect. Revoking access may be necessary for containment, but the statement is flawed because it delays evidence preservation and assumes metadata is retained indefinitely, which is not true. Snowflake retention varies by source: many ACCOUNT_USAGE views have latency and finite retention periods, and operational changes can complicate reconstruction. Evidence should be preserved as early as possible, with containment and collection carefully coordinated.

  • E. Correct.

    Correct. Preserving relevant data objects using Time Travel or CLONE can be an effective way to capture the state of data near the incident window without modifying the original object. Documenting exact timestamps, object names, and the people involved strengthens the chain of custody and supports reproducibility of the preservation process.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam