SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 85 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 85

Select 2Perform third-party vendor risk assessment

A financial services company uses Snowflake to store regulated customer data, including PII. The security team is evaluating a third-party ETL vendor that wants to connect to Snowflake and run scheduled data ingestion jobs. The vendor states that its platform will use a Snowflake service account with broad object privileges to simplify onboarding. The company must perform a vendor risk assessment and minimize the security impact if the vendor is compromised. Which TWO actions should the Snowflake security engineer recommend as the most appropriate controls before approving the integration?

  1. A

    Create a dedicated vendor role with least-privilege access only to the required databases, schemas, warehouses, and objects needed for the ETL jobs

  2. B

    Allow the vendor to use the ACCOUNTADMIN role temporarily during initial setup, then revoke it after the integration is stable

  3. C

    Require the vendor connection to be restricted through Snowflake network policies so only the vendor's approved egress IP addresses can authenticate

  4. D

    Share the same Snowflake user across multiple vendors so activity can be reviewed centrally in one login history trail

  5. E

    Grant OWNERSHIP on the target schema so the vendor can manage future pipeline changes without internal administrator involvement

Show answer and explanation

Correct answers: A, C

Explanation

For third-party vendor risk assessment in Snowflake, the strongest recommendations focus on reducing blast radius, improving accountability, and limiting exposure if vendor credentials or infrastructure are compromised. The best answers are to create a dedicated least-privilege role and to restrict access using network policies tied to approved vendor IP addresses. These controls align with Snowflake security best practices around role-based access control, separation of duties, and network access restrictions. In practice, a security engineer should also ensure the vendor uses a dedicated Snowflake identity, review authentication method choices, monitor LOGIN_HISTORY and QUERY_HISTORY, and periodically recertify granted privileges. Snowflake documentation consistently emphasizes least privilege for RBAC and the use of network policies to control where users can connect from. High-privilege roles such as ACCOUNTADMIN and excessive grants such as OWNERSHIP are not appropriate defaults for vendor onboarding and would represent elevated residual risk in a formal vendor assessment.

  • A. Correct.

    Correct. A dedicated role designed around least privilege is a primary control in third-party vendor risk reduction. The vendor should receive only the minimum privileges necessary for its ETL function, such as specific USAGE, SELECT, INSERT, or CREATE STAGE permissions as required, instead of broad account-level authority. This limits blast radius if the vendor account or platform is compromised and supports separation of duties and clearer auditing.

  • B. Incorrect.

    Incorrect. Allowing a third party to use ACCOUNTADMIN, even temporarily, is a significant risk and violates least-privilege principles. ACCOUNTADMIN is highly privileged and can manage security, billing-related settings, and object access across the account. A common misconception is that temporary elevation is acceptable for convenience during onboarding, but vendor risk assessments should avoid unnecessary privileged access entirely and instead use narrowly scoped administrative processes managed by internal personnel.

  • C. Correct.

    Correct. Restricting authentication with a Snowflake network policy to the vendor's known source IP ranges is an effective compensating control for third-party access. It reduces the chance that stolen credentials can be used from unauthorized locations. In a vendor risk review, validating and enforcing source network restrictions is a practical control that complements role-based least privilege.

  • D. Incorrect.

    Incorrect. Each vendor should have distinct identities for accountability, least privilege, and incident response. Sharing a single user across vendors weakens auditability, makes forensic analysis difficult, and increases the chance of credential misuse going undetected. The misconception is that centralization improves oversight, but in practice unique service principals or users provide better traceability in login and query history.

  • E. Incorrect.

    Incorrect. Granting OWNERSHIP is excessive for a vendor performing scheduled ETL unless there is a very specific and tightly governed requirement. OWNERSHIP gives full control over objects and the ability to transfer privileges, which materially increases risk. The safer approach is to grant only the object privileges required for ingestion and operational tasks, while internal administrators retain ownership and change control.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam