SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 417 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 417

Single answerUse Cortex AI for data security:

A financial services company stores customer support transcripts, loan documents, and free-form case notes in Snowflake. The security team wants to use Snowflake Cortex AI to help identify sensitive information embedded in unstructured text so they can prioritize downstream masking and review workflows. They also need to minimize data movement and keep analysis inside Snowflake. Which approach BEST meets these requirements?

  1. A

    Use a Cortex AI function to analyze the text directly in Snowflake and classify or extract sensitive content from the unstructured fields, then use the results to drive security workflows.

  2. B

    Export the unstructured text to an external LLM provider, classify sensitive data there, and write the labels back to Snowflake because Cortex AI only works with structured columns.

  3. C

    Convert all unstructured text into masking policies first, then call Cortex AI only after dynamic data masking has been applied to determine whether the original data was sensitive.

  4. D

    Use network policies and Tri-Secret Secure to detect sensitive entities in the text because these controls are designed to inspect document content stored in Snowflake.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use Cortex AI directly within Snowflake to analyze unstructured text for sensitive content. This matches the scenario's two key constraints: keeping processing inside Snowflake and reducing data movement. In practice, Cortex AI can be used to classify, extract, or otherwise analyze text from transcripts, documents, and notes, and those outputs can support security workflows such as prioritizing review, assigning tags, or informing masking and governance decisions. The distractors reflect common misconceptions: that AI-based content analysis requires exporting data externally, that masking must happen before detection, or that infrastructure security features such as network policies and Tri-Secret Secure perform content inspection. Snowflake best practices generally favor in-platform processing where possible to reduce operational complexity and exposure, and Cortex AI is intended to enable AI use cases directly on Snowflake data.

  • A. Correct.

    Correct. Snowflake Cortex AI is designed to let customers use AI capabilities directly within Snowflake on data already stored there, including text-based content. For a security use case involving unstructured transcripts, documents, and notes, using Cortex AI functions to classify, summarize, or extract relevant information from text inside Snowflake aligns with the requirements to minimize data movement and keep processing in-platform. The extracted labels or classifications can then feed governance and review processes such as tagging, manual triage, or downstream masking decisions.

  • B. Incorrect.

    Incorrect. This option conflicts with the stated requirement to minimize data movement and keep analysis inside Snowflake. It also reflects a misconception that Cortex AI is limited to structured data. Cortex AI is specifically useful for text-based AI tasks on data in Snowflake, including unstructured or semi-structured content that can be processed as text.

  • C. Incorrect.

    Incorrect. Masking policies do not convert text into a format that makes Cortex AI analysis possible, and applying masking first would often reduce the model's ability to identify the original sensitive content. In practice, organizations typically identify or classify sensitive information first, then use those results to inform controls such as masking, tagging, or remediation.

  • D. Incorrect.

    Incorrect. Network policies and Tri-Secret Secure are important security controls, but they do not inspect document content to identify sensitive entities such as PII in text. Network policies restrict network access, and Tri-Secret Secure strengthens key management. Neither is a content analysis capability for unstructured data.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam