SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 54 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 54

Single answerDesign and manage leaked password and malicious IP protections

A security engineer at a global company needs to harden Snowflake authentication for hundreds of human users who connect from many networks, including employee home offices. Leadership wants to reduce the risk of account compromise from reused credentials and known hostile sources without maintaining large network allowlists that would block legitimate remote users. Which configuration best meets these requirements?

  1. A

    Create an authentication policy that enables leaked password protection and malicious IP protection, then assign it to the affected users or at the account level as appropriate.

  2. B

    Create a network policy that only allows corporate office IP ranges and rely on password complexity requirements to reduce credential compromise.

  3. C

    Enable MFA enrollment for all users and disable password authentication entirely for every login scenario, including service users and external integrations.

  4. D

    Rotate all user passwords weekly and create a password policy with a longer minimum length, because Snowflake password policies automatically block leaked passwords and malicious source IPs.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use an authentication policy with leaked password protection and malicious IP protection enabled. This directly addresses both risks in the scenario: credential reuse from known breaches and login attempts originating from suspicious or known-malicious IP addresses. It also avoids the operational burden and user friction of maintaining restrictive network allowlists for a distributed workforce.

In Snowflake, password policies and network policies serve different purposes. Password policies govern items such as password length, history, and lockout-related settings; they do not provide breach-intelligence-based leaked password detection or malicious IP screening. Network policies evaluate allowed and blocked IP ranges, but they are static controls and can be a poor fit for large remote populations. Authentication policies are the correct mechanism for managing modern sign-in protections such as leaked password and malicious IP controls.

This aligns with Snowflake security best practices: use layered authentication controls, apply policies at the appropriate scope, and prefer controls that reduce risk without unnecessarily disrupting legitimate user access. Candidates should know not only what each policy type does, but also when to choose authentication policies over password or network policies for real-world security outcomes.

  • A. Correct.

    Correct. Snowflake authentication policies are the control used to configure protections such as leaked password protection and malicious IP protection. This is the most suitable solution when the company wants adaptive protections against compromised credentials and risky source IPs without depending on static IP allowlists. Authentication policies can be applied at the account or user level, allowing targeted rollout for human users.

  • B. Incorrect.

    Incorrect. A network policy restricts access based on IP addresses, which is useful in some cases, but it does not address leaked passwords. In this scenario, employees connect from many locations, so a strict office-only allowlist would likely block legitimate access. This option also relies on password complexity, which does not detect whether a password has already been exposed in a breach or whether a login is coming from a known malicious IP.

  • C. Incorrect.

    Incorrect. MFA is an important security control, but this option overreaches and does not align with the requirement. Snowflake supports different authentication patterns, and disabling password authentication for every scenario is not a practical or necessary response. Also, MFA alone does not specifically provide the built-in leaked password and malicious IP protections asked for in the scenario.

  • D. Incorrect.

    Incorrect. Frequent password rotation and stronger password requirements may improve hygiene, but Snowflake password policies do not provide leaked password protection or malicious IP detection. This option reflects a common misconception that password policy settings cover breach intelligence and threat-source screening. Those protections are managed through authentication policies, not password policies.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam