SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 91 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 91

Single answerCloud provider tokens

A security engineer is reviewing how a Snowflake account in AWS accesses an encrypted external stage used for loading sensitive files from Amazon S3. The current design uses a long-lived AWS IAM user access key stored outside Snowflake, and the company wants to reduce credential exposure and simplify key rotation. The engineer recommends using a Snowflake storage integration with cloud provider tokens instead. Which outcome should the engineer expect from this change?

  1. A

    Snowflake will use short-lived AWS security credentials obtained by assuming a designated IAM role, reducing the need to manage long-lived cloud keys in application code.

  2. B

    Snowflake will generate a permanent AWS access key pair inside the Snowflake account and automatically rotate it without any AWS configuration.

  3. C

    Snowflake will require all users who query the stage to authenticate directly to AWS with their own federated cloud identities before Snowflake can read S3 objects.

  4. D

    Snowflake will eliminate the need for any trust relationship in AWS because the storage integration token itself grants direct access to S3 buckets.

Show answer and explanation

Correct answer: A

Explanation

The key security benefit of using cloud provider tokens through a Snowflake storage integration is that Snowflake can obtain temporary cloud credentials instead of relying on static credentials such as long-lived AWS access keys. In AWS, this is implemented by configuring an IAM role that Snowflake is allowed to assume, commonly protected with an external ID in the trust policy. This design reduces secret sprawl, supports least-privilege access, and simplifies operational rotation compared with embedding IAM user keys in applications. Snowflake documentation for storage integrations and S3 external stages describes the AWS role assumption model, temporary credentials, and required trust relationship configuration.

  • A. Correct.

    Correct. For S3 storage integrations, Snowflake uses a cloud provider trust model in which Snowflake assumes a customer-designated AWS IAM role and obtains temporary security credentials. This avoids embedding long-lived AWS access keys in scripts or applications and aligns with security best practices for least privilege and credential rotation.

  • B. Incorrect.

    Incorrect. Snowflake does not create a permanent AWS access key pair for this purpose. Storage integrations are designed specifically to avoid reliance on long-lived static keys. AWS-side configuration is still required, including an IAM role and trust policy that allows Snowflake to assume the role.

  • C. Incorrect.

    Incorrect. End users querying Snowflake do not each need direct AWS authentication for Snowflake to access staged data through a storage integration. Snowflake accesses the cloud storage on behalf of the account using the configured integration and assumed role, not each individual user's separate AWS session.

  • D. Incorrect.

    Incorrect. A trust relationship in AWS is still required. The IAM role used by the storage integration must trust the Snowflake IAM user or principal identified during integration setup, typically constrained with an external ID. The token-based approach does not bypass AWS authorization or trust configuration.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam