SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 84 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 84

Select 3Perform third-party vendor risk assessment

A financial services company uses Snowflake to store regulated customer data. The security team is evaluating a third-party ETL vendor that will load source files into Snowflake and perform data transformations. The vendor proposes using its own managed integration platform and asks for broad access so onboarding can be completed quickly. The company must perform a vendor risk assessment that minimizes exposure while still allowing the integration to function. Which TWO actions are the MOST appropriate to include in the assessment and onboarding decision?

  1. A

    Require the vendor integration to use a dedicated Snowflake service account with least-privilege RBAC and only the specific object privileges needed for loading and transformation tasks.

  2. B

    Approve the vendor if it can connect from a static IP range, because network restrictions alone are sufficient to address third-party access risk.

  3. C

    Evaluate whether the vendor can use Snowflake-supported secure connectivity and authentication patterns, such as key-pair authentication, storage integrations, and network policies, instead of embedding long-lived usernames and passwords in the vendor platform.

  4. D

    Grant the vendor ACCOUNTADMIN during implementation and plan to reduce privileges after go-live, since temporary elevated access lowers delivery risk.

  5. E

    Confirm the vendor has an appropriate security posture and contractual controls, such as evidence of independent security assessments and incident notification commitments, because third-party risk extends beyond technical connectivity.

Show answer and explanation

Correct answers: A, C, E

Explanation

The best answer combines technical and governance controls. For a third-party vendor in Snowflake, the organization should minimize access through a dedicated service identity and least-privilege RBAC, prefer secure authentication and integration patterns over embedded passwords, and evaluate the vendor's external security posture and contractual obligations. This approach reflects Snowflake best practices around role-based access control, limiting use of powerful roles, and securing service authentication. Relevant Snowflake documentation includes guidance on access control and RBAC, key-pair authentication for programmatic access, network policies, and storage integrations. From a vendor risk perspective, strong onboarding decisions also require non-technical due diligence such as audit evidence and incident notification requirements, because secure Snowflake configuration alone does not fully address third-party operational risk.

  • A. Correct.

    Correct. A core part of third-party vendor risk assessment in Snowflake is ensuring the vendor operates through a dedicated non-human identity with least-privilege role-based access control. The account should receive only the minimum privileges required for the integration, such as access to specific warehouses, databases, schemas, stages, or tables. This reduces blast radius if the vendor account is misused or compromised and aligns with Snowflake security best practices around RBAC and separation of duties.

  • B. Incorrect.

    Incorrect. Restricting access by source IP can help reduce exposure, but it does not by itself address third-party risk. A vendor could still have excessive privileges, weak credential management, poor internal controls, or inadequate incident response. Network restrictions are only one compensating control and should be evaluated alongside identity, privilege scope, credential handling, and vendor governance controls.

  • C. Correct.

    Correct. During vendor assessment, the company should determine whether the integration can use Snowflake-native and security-aligned mechanisms instead of weaker credential practices. Key-pair authentication is preferred for service users over passwords in many automation scenarios. Storage integrations can reduce the need to hand cloud credentials to vendors when working with external cloud storage. Network policies can further constrain where access is allowed from. This option reflects a practical review of secure architecture choices that materially reduce vendor risk.

  • D. Incorrect.

    Incorrect. Granting ACCOUNTADMIN to a third-party vendor, even temporarily, is a major risk and contradicts least-privilege principles. Excessive privileges during implementation can expose all account resources and security settings. A common misconception is that short-term elevated access is acceptable if there is pressure to deliver quickly, but this increases the likelihood and impact of mistakes or compromise. Snowflake recommends tightly controlling powerful system roles and limiting them to trusted internal administrators.

  • E. Correct.

    Correct. Third-party vendor risk assessment is not limited to Snowflake configuration. The company should also review the vendor's broader security posture, such as evidence from independent audits or assessments, security program maturity, and contractual provisions for breach notification and responsibilities. These measures help evaluate whether the vendor can be trusted with regulated data workflows and are standard components of enterprise vendor risk management.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam