SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 418 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 418

Single answerApply AI Observability features for Gen AI application security

A security engineer is reviewing a Cortex AI chatbot deployed in Snowflake for internal employees. The application uses SQL functions to invoke an LLM and must meet two requirements: (1) security teams need visibility into prompts and model responses to investigate prompt injection or data leakage patterns, and (2) developers want to monitor quality and safety issues over time without building custom logging pipelines outside Snowflake. Which Snowflake capability best addresses both requirements?

  1. A

    Enable AI Observability for the Gen AI workload so prompts, responses, and evaluation signals can be monitored within Snowflake

  2. B

    Create a masking policy on the prompt column and rely on QUERY_HISTORY to capture all model inputs, outputs, and safety metrics

  3. C

    Use network policies and Tri-Secret Secure to inspect prompt content and score model responses for toxicity

  4. D

    Configure object tags on the application schema so Snowflake automatically evaluates hallucination, groundedness, and prompt injection attempts

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use AI Observability because the scenario explicitly requires security visibility into Gen AI interactions and ongoing monitoring of quality and safety signals inside Snowflake. For Security Engineer candidates, the key distinction is that traditional controls such as masking policies, query history, tags, encryption, and network restrictions remain important, but they do not provide specialized monitoring of LLM prompts and responses. AI Observability is the Snowflake capability designed for this Gen AI use case: helping teams monitor behavior, investigate issues such as prompt injection or data leakage, and assess application performance and safety without depending on ad hoc external logging. In practice, this supports secure operation of Cortex AI and other Gen AI applications by complementing core Snowflake governance and access controls rather than replacing them.

  • A. Correct.

    Correct. AI Observability is intended to provide visibility into Gen AI application behavior in Snowflake, including monitoring prompts and responses and surfacing evaluation-oriented signals that help teams assess quality, safety, and operational issues over time. This aligns with the scenario's need for security investigation into prompt injection or data leakage patterns and for ongoing monitoring without requiring a separate external logging solution.

  • B. Incorrect.

    Incorrect. Masking policies can protect sensitive data in columns, and QUERY_HISTORY helps with SQL statement auditing, but QUERY_HISTORY is not a purpose-built Gen AI observability framework for capturing and evaluating model interactions. It does not replace AI Observability for prompt/response monitoring and safety or quality analysis. This option reflects a common misconception that standard SQL auditing alone is sufficient for Gen AI security monitoring.

  • C. Incorrect.

    Incorrect. Network policies restrict where users can connect from, and Tri-Secret Secure strengthens encryption key control. Neither capability inspects prompt content nor evaluates model outputs for risks such as toxicity, hallucination, or prompt injection. This distractor mixes valid Snowflake security features with functionality they do not provide.

  • D. Incorrect.

    Incorrect. Tags are useful for classification, governance, and policy management workflows, but applying tags to schemas does not cause Snowflake to automatically analyze LLM interactions for groundedness, hallucination, or prompt injection. This option is plausible because tags are often used in governance programs, but they are not an AI runtime observability or evaluation mechanism.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam