SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 58 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 58

Single answerCreate, implement, and manage network and rules policies:

A financial services company wants to restrict user authentication to Snowflake so that employees can sign in only from the corporate office public IP range and from a company-managed VPN range. However, the security team must ensure that a small group of break-glass administrators can still connect from any location during an outage. The company wants the control enforced at login, with minimal ongoing manual intervention, and wants the exception to be manageable at the user level. Which approach best meets these requirements?

  1. A

    Create a network policy that allows the corporate office and VPN IP ranges, set it at the account level, and set a different user-level network policy for the break-glass administrator users that permits broader access.

  2. B

    Create a rule object listing the approved IP ranges, attach it directly to all roles used by employees, and leave administrators without any rule so they can connect from anywhere.

  3. C

    Create a password policy for all employees and a separate password policy for break-glass administrators, because password policies can enforce source IP restrictions during login.

  4. D

    Create a session policy that checks the client IP address after authentication and terminates sessions that do not originate from the corporate office or VPN ranges, while excluding administrator sessions.

Show answer and explanation

Correct answer: A

Explanation

The best solution is to use Snowflake network policies. Network policies allow administrators to define allowed and blocked IP address lists for authentication requests. Applying a restrictive network policy at the account level establishes a secure default for all users. Assigning a different network policy directly to specific break-glass administrator users provides a clean exception path without changing the broader account configuration. This design aligns with Snowflake best practices for layered, least-privilege access and exception management. In Snowflake documentation, network policies are the supported mechanism for controlling login access by client IP address, and user-level assignment can override broader account-level settings for targeted exceptions. By contrast, password policies govern password requirements, and session policies manage session behavior rather than pre-authentication source network enforcement.

  • A. Correct.

    Correct. Snowflake network policies are designed to restrict authentication based on client IP address. A network policy can be set at the account level to enforce the default restriction for all users, and a user-level network policy can be assigned to specific users to override the account-level policy for exceptions such as break-glass administrators. This matches the requirement to enforce controls at login and manage exceptions at the user level with minimal operational overhead.

  • B. Incorrect.

    Incorrect. Roles are not the attachment point for network policies or network rules in this way. Snowflake network access restrictions for login are enforced through network policies, which are associated at the account, security integration, or user level depending on the use case. Attaching an IP-based rule directly to roles would not satisfy the login restriction requirement.

  • C. Incorrect.

    Incorrect. Password policies control password characteristics and related behavior, not source IP restrictions. They cannot be used to permit or deny authentication based on network location. This option reflects a common confusion between authentication policy controls and network-based access controls.

  • D. Incorrect.

    Incorrect. Session policies govern session behavior such as idle timeout and related session settings, but they are not the primary mechanism for enforcing source IP restrictions at login. The requirement specifically states the control must be enforced during authentication, which is what network policies are intended to do.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam