SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 419 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 419

Single answerApply AI Observability features for Gen AI application security

A security engineer is reviewing a Cortex AI chatbot application that answers employee questions using retrieval-augmented generation (RAG) over internal Snowflake data. The company wants to detect unsafe prompts and model responses, monitor usage patterns, and investigate potentially risky interactions without manually inspecting every request. Which approach best applies Snowflake AI Observability capabilities to improve the security posture of this Gen AI application?

  1. A

    Enable AI Observability for the Gen AI workload so prompt/response traces and evaluation signals can be monitored, then use the resulting telemetry to investigate problematic interactions and identify security risks.

  2. B

    Rely on Dynamic Data Masking alone because masked source data guarantees that prompts and responses cannot contain unsafe or policy-violating content.

  3. C

    Use network policies and Tri-Secret Secure as the primary method for detecting prompt injection and harmful model output in the chatbot.

  4. D

    Create a resource monitor on the virtual warehouse because warehouse credit limits are designed to classify unsafe prompts and flag high-risk responses.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use AI Observability because the scenario is specifically about applying observability features to a Gen AI application for security monitoring and investigation. In Snowflake, traditional controls such as masking policies, network policies, encryption features, and resource monitors remain valuable, but they solve different problems: data access protection, perimeter restriction, key management, and cost governance. They do not replace application-level visibility into LLM interactions. For Gen AI security, the practical goal is to capture and review telemetry about prompts, responses, traces, and evaluation outcomes so teams can detect unsafe behavior, investigate incidents, and tune controls. This aligns with Snowflake guidance to use observability for monitoring AI/LLM application behavior, while continuing to apply core Snowflake security features such as RBAC, masking, and governance to protect underlying data.

  • A. Correct.

    Correct. AI Observability is the Snowflake capability intended to provide visibility into Gen AI application behavior, including traces and evaluation-oriented telemetry for prompts, responses, and related activity. In a security scenario, this supports monitoring for unsafe interactions, investigating suspicious outputs, and identifying risk patterns in LLM-powered applications. This is the most direct application of AI Observability to Gen AI security.

  • B. Incorrect.

    Incorrect. Dynamic Data Masking helps protect sensitive data returned from tables and views based on policy, but it does not by itself evaluate whether user prompts are malicious, whether a model response is unsafe, or whether a RAG workflow is being abused. It is an important control for data protection, but it is not an observability or AI safety monitoring feature.

  • C. Incorrect.

    Incorrect. Network policies and Tri-Secret Secure address different security concerns. Network policies restrict where users can connect from, and Tri-Secret Secure strengthens encryption key control. Neither feature inspects LLM prompts/responses or provides Gen AI observability for prompt injection, unsafe completion detection, or response investigation.

  • D. Incorrect.

    Incorrect. Resource monitors help control credit consumption for warehouses and can notify or suspend usage when spending thresholds are reached. They are useful for cost governance, but they do not analyze prompt content, classify responses, or provide observability into Gen AI application security events.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam