SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 391 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 391

Single answerUnderstand the lifecycle management of services and their security implications

A security engineer at a financial services company is reviewing how application access is managed for Snowflake Native Apps and other service-based integrations in a production account. The company policy requires that any capability granted to a service or app must be explicitly approved, monitored throughout its use, and fully removed when the service is retired. During an audit, the engineer discovers that a previously approved service still has access to account resources even though the business owner says it is no longer in use. Which action BEST aligns with secure lifecycle management of services in Snowflake?

  1. A

    Suspend the virtual warehouse used by the service so it can no longer process requests, and leave the service privileges in place in case the business needs it again later.

  2. B

    Revoke the service or application's granted privileges and remove its access to shared objects or integrations as part of decommissioning, rather than relying only on operational shutdown.

  3. C

    Rotate the passwords of users who administer the service, because administrator credential rotation automatically invalidates the service's existing access to Snowflake objects.

  4. D

    Transfer ownership of the service-related objects to SECURITYADMIN so that the service can no longer use them, while keeping all existing grants unchanged.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to explicitly revoke the service or application's access as part of retirement. In Snowflake, secure lifecycle management is not limited to provisioning and monitoring; it also includes proper deprovisioning. A service, app, or integration that is no longer needed should have its privileges, object access, and any related approved capabilities removed. Operational actions such as suspending warehouses or changing administrator credentials do not replace authorization cleanup. This aligns with Snowflake security best practices around least privilege, controlled grant management, and periodic review of access for integrations and applications. Candidates should recognize that the security implication of poor service lifecycle management is lingering access after business use has ended, which increases risk during audits and incident response.

  • A. Incorrect.

    Incorrect. Suspending a warehouse only stops compute from running on that warehouse; it does not remove the underlying privileges or trust relationships that allow a service or app to access objects. From a lifecycle security perspective, unused access should be explicitly deprovisioned, not merely made temporarily inactive.

  • B. Correct.

    Correct. Secure lifecycle management requires explicit decommissioning of service access. When a service, app, or integration is no longer needed, its grants and access paths should be removed so the principle of least privilege continues to be enforced. This includes revoking privileges on objects and removing access mechanisms associated with the service or application, rather than assuming inactivity is sufficient.

  • C. Incorrect.

    Incorrect. Rotating administrator credentials is a useful operational control, but it does not inherently revoke privileges previously granted to a service, application, or integration. The misconception is confusing admin authentication hygiene with authorization cleanup. Lifecycle management requires removing the service's own access, not just changing human administrator credentials.

  • D. Incorrect.

    Incorrect. Ownership transfer changes administrative control over objects, but existing grants can remain effective unless they are explicitly revoked. A candidate might choose this because ownership is a powerful Snowflake concept, but ownership changes alone do not satisfy decommissioning requirements for service access.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam