Courseiva

CCNA Accounts And Security Questions

34 questions · Accounts And Security topic · All types, answers revealed

1
MCQmedium

A Snowflake architect is designing a solution where external users need to access specific data in a Snowflake database without having Snowflake accounts. They want to provide read-only access to a few tables and ensure that the external users cannot see any other data. Which Snowflake feature should they use?

A.Secure Data Sharing
B.External Tables
C.Materialized Views
D.Snowflake Reader Accounts
AnswerD

Reader Accounts are a feature of Secure Data Sharing that allow providers to create accounts for consumers who do not have Snowflake accounts. The provider manages the reader account and can grant read-only access to specific shares. This enables external users to query shared data without needing their own Snowflake account.

Why this answer

Reader Accounts are designed for sharing data with consumers who do not have Snowflake accounts. The provider creates and manages the reader account, and can grant access to specific shares, ensuring read-only access to the desired tables. This meets the requirement for external users to access data without having their own Snowflake accounts.

Exam trap

The trap here is confusing Secure Data Sharing with Reader Accounts; Secure Data Sharing requires the consumer to have a Snowflake account, while Reader Accounts are for those without.

2
MCQhard

Which of the following describes the correct behavior of a Masking Policy applied to a column that is also referenced in a Row Access Policy?

A.The Masking Policy is evaluated first.
B.The Row Access Policy is evaluated first.
C.Only the Masking Policy is applied.
D.Only the Row Access Policy is applied.
AnswerB

Snowflake evaluates the Row Access Policy first to determine the rows that the user is permitted to see. Once the result set is filtered at the row level, the Masking Policies are applied to the columns to ensure that sensitive data is appropriately obfuscated for the current user's session.

Why this answer

Snowflake enforces policies in a specific sequence. When both Row Access and Masking Policies are present, the Row Access Policy is evaluated first to determine the visible rows, and then the Masking Policy is applied to the visible data. This ensures that the security constraints are applied logically and cumulatively.

This behavior is crucial for preventing information leakage, ensuring that users cannot bypass row-level filters by using column-level masking logic or vice versa, providing a consistent security model.

Exam trap

Candidates often assume the masking policy applies first to hide data before row access evaluation, failing to realize Snowflake evaluates the row access policy first to determine which rows are visible.

3
MCQeasy

A company wants to allow their data analysts to query data in a specific database but prevent them from viewing the underlying table definitions. Which Snowflake feature should the architect recommend?

A.Object tagging
B.Column-level security
C.Secure views
D.Row access policies
AnswerC

Secure views are designed to hide the view definition and the underlying query logic from users who do not have the necessary privileges. When a user queries a secure view, they can access the data but cannot see the view's SQL definition or the base tables. This directly meets the requirement of allowing queries while preventing viewing of table definitions, as the view abstracts the underlying schema.

Why this answer

Secure views hide both the view definition and the underlying table definitions from users who do not have the necessary privileges. When analysts query a secure view, they can retrieve data without seeing the SQL or the base tables. This makes secure views the appropriate feature to meet the requirement of querying data while preventing viewing of table definitions.

Exam trap

The trap here is confusing data filtering features like row access policies or masking with the ability to hide object definitions, which is specific to secure views.

4
MCQeasy

A startup is preparing for its first SOC 2 audit. The auditor asks how the company prevents a compromised employee credential from being used from an unknown location while still allowing legitimate travel. The architect has already created a network policy listing the corporate ranges. What should the architect do to apply this control account-wide?

A.Assign the network policy to each user individually using ALTER USER ... SET NETWORK_POLICY so that only named users are restricted.
B.Create a share that exposes the network policy to the account and grant it to PUBLIC so all roles inherit the restriction.
C.Enable the account parameter REQUIRE_NETWORK_POLICY and rely on Snowflake to block sessions that lack a matching policy.
D.Set the network policy as the account-level policy using ALTER ACCOUNT SET NETWORK_POLICY so it applies to all users by default.
AnswerD

An account-level network policy applies to every user unless a user-level policy overrides it. Setting it with ALTER ACCOUNT establishes the default allowlist of corporate ranges, blocking access from unknown locations. This gives the account-wide control the auditor expects while still permitting targeted overrides where justified.

Why this answer

Applying a network policy at the account level makes it the default for all users, restricting connections to the listed corporate ranges and blocking unknown locations. User-level policies can still override it for specific cases such as traveling executives. Per-user assignment, sharing, or invented parameters do not deliver the account-wide default control the auditor is asking about.

Exam trap

The trap here is thinking network policies must be granted or shared, when they are simply attached at the account, user, or role level.

5
MCQhard

A healthcare organization uses Snowflake to store sensitive patient data. They need to implement column-level security that allows users with the role 'DOCTOR' to see full patient IDs, while users with the role 'RESEARCHER' should see only the last four digits. The organization wants a centralized, reusable solution that can be applied to multiple columns across different tables. Which Snowflake feature should the architect use?

A.Row Access Policies that limit which rows are visible based on the user's role.
B.Dynamic Data Masking with a masking policy that checks the current role and applies the appropriate masking.
C.Object Tagging with a tag that indicates the sensitivity level, combined with a policy that enforces access.
D.Secure Views that filter the data based on the current role.
AnswerB

Dynamic Data Masking uses masking policies that can be attached to columns. The policy can evaluate the current role and conditionally mask the data. By creating a policy that returns the full value for the DOCTOR role and a masked value for others, the organization achieves column-level security. Masking policies are centralized and can be reused across multiple columns, satisfying the requirement for a reusable solution.

Why this answer

Dynamic Data Masking with a masking policy is the correct feature because it allows column-level masking based on the current role. The policy can be written to show full data to the DOCTOR role and masked data to others. Masking policies are centralized and can be applied to multiple columns, making them reusable.

Secure views, row access policies, and object tagging do not provide the required dynamic column-level masking.

Exam trap

The trap here is confusing column-level masking with row-level security or metadata tagging, when the requirement is specifically for dynamic masking of column values based on role.

6
MCQeasy

A data architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that users from one tenant cannot access data from another tenant, even if they have the same role name. Which Snowflake feature should the architect use to isolate access?

A.Network policies
B.Separate accounts per tenant
C.Database roles
D.Secure views
AnswerB

Using separate Snowflake accounts for each tenant provides the strongest isolation because accounts are completely independent. There is no shared metadata or access control, so users in one account cannot access data in another. This is a common pattern for multi-tenant architectures requiring strict isolation.

Why this answer

For strict multi-tenant isolation, using separate Snowflake accounts per tenant is the most robust approach. Each account is a separate security and management domain, ensuring that users, roles, and data are completely isolated. This prevents any possibility of cross-tenant access through shared roles or objects.

Exam trap

The trap here is assuming that database roles or secure views alone can provide complete tenant isolation, when they only provide fine-grained access control within a shared account.

7
Multi-Selecthard

Which THREE of the following are valid methods for securing data in transit for connections to Snowflake?

Select 3 answers
A.Enforcing TLS 1.2+ for all client drivers.
B.Using Snowflake Private Link for private connectivity.
C.Implementing client-side data encryption with PGP.
D.Restricting access to approved IP addresses via Network Policies.
E.Enabling the Snowflake data sharing feature.
AnswersA, B, D

Snowflake requires TLS 1.2 for all encrypted communications. Ensuring that client drivers, connectors, and applications are configured to support this protocol is essential. It provides the necessary cryptographic handshake to verify the server's identity and ensure that the traffic between the client and Snowflake remains encrypted and tamper-proof throughout the transit.

Why this answer

Snowflake enforces TLS 1.2 or higher for all client connections. Securing data in transit is a non-negotiable requirement for compliance (e.g., HIPAA, SOC2). Architects must ensure that the client software and drivers are configured to use secure protocols, that private connectivity is utilized for sensitive environments, and that connections are validated against trusted sources, thereby mitigating the risk of man-in-the-middle attacks and data interception during transit.

Exam trap

Candidates often select incorrect options like 'Data Encryption at Rest' when the question specifically asks for 'data in transit'. They fail to distinguish between encryption methods for stored data versus network communication protocols.

8
MCQmedium

When designing a role hierarchy, what is the primary benefit of granting one role to another role instead of directly to users?

A.It increases query performance.
B.It enables automatic data encryption.
C.It simplifies privilege management through inheritance.
D.It bypasses the need for MFA.
AnswerC

Role inheritance allows privileges to flow from child roles to parent roles. This structure makes it much easier to manage complex access requirements, as you can define granular roles for specific tasks and bundle them into broader functional roles, drastically reducing the number of individual grants required per user.

Why this answer

Role inheritance simplifies privilege management by allowing an architect to create a logical hierarchy. When a parent role inherits a child role, it automatically gains all the child's privileges. This reduces administrative overhead, as permission changes only need to be made once at the child level to propagate upwards.

It also improves visibility and auditability, allowing for a clearer mapping between job functions and the access required to perform those functions efficiently across the organization.

Exam trap

Candidates think granting roles directly to individual users improves isolation, completely missing the administrative scaling benefits of role inheritance.

9
MCQmedium

A security team is designing a Snowflake deployment where they need to centrally manage user access to a set of databases across multiple accounts in an organization. They want to define a set of privileges once and grant them to roles in each account without recreating the roles in every account. Which Snowflake feature should they use?

A.Organization roles
B.Account roles
C.Application roles
D.Database roles
AnswerA

Organization roles are designed for cross-account access management within a Snowflake organization. They allow you to define a role once at the organization level and grant it to accounts, enabling centralized privilege management. This matches the requirement to manage access across multiple accounts without recreating roles.

Why this answer

Organization roles allow centralized management of privileges across multiple accounts within a Snowflake organization. They are defined once and can be granted to accounts, eliminating the need to recreate roles in each account. This provides a scalable and consistent way to manage access, which is exactly what the security team needs.

Exam trap

The trap here is confusing database roles or account roles with organization roles, as all are role types but only organization roles operate across accounts.

10
MCQmedium

Refer to the exhibit. An administrator has executed a 'SHOW GRANTS TO ROLE ANALYST_ROLE' command. Based on the output, what is the significance of the 'grant_option' value for the 'SELECT' privilege on the 'SALES_DATA' table?

A.The ANALYST_ROLE can grant the SELECT privilege on the SALES_DATA table to other roles in the account.
B.The ANALYST_ROLE is a managed access role and cannot modify any privileges on the SALES_DATA table.
C.The SELECT privilege is automatically granted to any role that is a child of the ANALYST_ROLE.
D.The ANALYST_ROLE can only grant the SELECT privilege if they also have the OWNERSHIP privilege on the table.
AnswerA

When the 'grant_option' is set to 'true', it indicates that the privilege was granted using the 'WITH GRANT OPTION' clause. This allows any user active in the `ANALYST_ROLE` to grant that same SELECT privilege to other roles, effectively delegating administrative control over that specific object's access.

Why this answer

The 'grant_option' in Snowflake access control determines if a grantee has the authority to pass privileges to other roles. Understanding this output is crucial for architects to audit security and ensure that the principle of least privilege is maintained, as the ability to further delegate access can lead to unauthorized permission expansion if not strictly controlled.

Exam trap

Candidates frequently mistake 'grant_option' for general administrative rights, failing to realize it specifically authorizes the grantee to delegate that exact privilege to other roles in the system.

11
MCQmedium

Which object type should an architect use to manage granular access permissions to a specific schema within a database?

A.User
B.Role
C.Warehouse
D.Integration
AnswerB

Roles are the fundamental unit of access control in Snowflake. They act as containers for privileges, which can then be granted to users. By creating custom roles for specific schemas, an architect can effectively group permissions and grant them to the appropriate users in a manageable and auditable way.

Why this answer

Role-Based Access Control (RBAC) in Snowflake relies on roles to manage privileges. By assigning specific privileges like USAGE or SELECT to a role, and then granting that role to users or other roles, the architect implements the principle of least privilege. This hierarchy allows for scalable management of security, ensuring that users only have the access they need to perform their jobs while maintaining auditability for compliance and security monitoring purposes across the entire organization.

Exam trap

Candidates often choose 'User' or 'Account' instead of 'Role'. They mistakenly think permissions are assigned directly to users, ignoring Snowflake's best practice of assigning all privileges to roles for easier maintenance.

12
Multi-Selectmedium

A security architect is designing a Snowflake environment for a company with strict data governance requirements. They need to implement column-level security to mask sensitive data based on the user's role and also track which columns are being accessed by which users. Which two Snowflake features should the architect use to achieve these goals? (Choose two.)

Select 2 answers
A.Dynamic Data Masking
B.Secure Views
C.Object Tagging
D.Row Access Policies
E.Access History
AnswersA, E

Dynamic Data Masking allows you to apply masking policies to columns so that users see masked values unless they have the appropriate role. This directly addresses the requirement to mask sensitive data based on role. Masking policies are evaluated at query time and can reference CURRENT_ROLE(), making them ideal for column-level security.

Why this answer

The requirements are to mask sensitive data based on role and to track column access. Dynamic Data Masking provides column-level masking based on the user's role, satisfying the first requirement. Access History records which columns are accessed by which queries and users, satisfying the second requirement.

Row Access Policies filter rows, Object Tagging is for classification, and Secure Views do not provide the needed masking or auditing.

Exam trap

The trap here is confusing row-level security with column-level security and assuming that Object Tagging or Secure Views can provide access tracking.

13
MCQhard

Which security integration type should an architect use to allow a third-party BI tool to access Snowflake without storing the user's credentials in the tool?

A.SAML2 Security Integration.
B.External OAuth Security Integration.
C.SCIM Security Integration.
D.API Authentication Integration.
AnswerB

External OAuth allows Snowflake to validate tokens issued by an external authorization server like Okta or PingFederate. This enables the BI tool to present a token that Snowflake trusts, allowing the tool to execute queries as the authorized user without the need for password storage.

Why this answer

OAuth is the industry-standard protocol for delegated authorization, allowing third-party applications to access Snowflake on behalf of a user. By using OAuth, the BI tool never sees the user's password; instead, it receives a secure token that grants specific, time-limited access to the Snowflake environment.

Exam trap

Candidates often confuse internal and external OAuth. They fail to identify that third-party tools require External OAuth to delegate access without storing user credentials.

14
MCQhard

An architect is designing a security model where a specific service account should only have access to perform SELECT operations on tables within a specific schema. How should this be implemented to adhere to the principle of least privilege?

A.Grant the SECURITYADMIN role to the service account.
B.Create a custom role, grant USAGE on database and schema, then grant SELECT on all tables.
C.Assign the ACCOUNTADMIN role to the service account.
D.Grant SELECT on the whole database to the PUBLIC role.
AnswerB

This approach isolates the service account's permissions to only the necessary operations (SELECT) within the required scope (Database/Schema). By avoiding the use of powerful predefined roles, the architect ensures that the service account remains restricted, minimizing the blast radius if the service account's credentials were to be inadvertently exposed.

Why this answer

Implementing least privilege requires defining specific roles with limited scope. The best approach is to create a custom role, grant USAGE on the database and schema, and grant SELECT on the tables. This prevents the service account from performing DDL or DML operations, limiting the impact of a compromised account.

This granular control is essential for preventing lateral movement and ensuring data integrity in production pipelines.

Exam trap

Candidates often forget the USAGE privilege on the parent database and schema. They think granting SELECT on the table is sufficient, but the query will fail without the prerequisite USAGE permissions on containers.

15
MCQhard

Which feature is essential for ensuring that queries on PII (Personally Identifiable Information) columns are masked from unauthorized users?

A.Row-Level Security (RLS).
B.Dynamic Data Masking (DDM).
C.Data Encryption at Rest.
D.Object Tagging.
AnswerB

Dynamic Data Masking is specifically designed to redact or obfuscate sensitive data at query time based on the active role of the user. This is the optimal way to handle PII as it ensures data integrity while allowing for functional access to the rest of the table's data, meeting compliance standards for data security.

Why this answer

Dynamic Data Masking is the correct feature for protecting sensitive data like PII. It allows an architect to apply a policy to a table column that masks the data based on the user's role. This ensures that unauthorized users see masked, non-sensitive versions of the data, while authorized users see the original raw values, providing a robust solution for compliance and data protection without duplicating data or creating complex views.

Exam trap

Candidates suggest creating restricted views or separate physical tables, which violates the requirement for dynamic, policy-driven column protection.

16
MCQmedium

A financial organization needs to ensure that only connections originating from their corporate VPN IP range can access their Snowflake account. Which feature should the architect implement?

A.Enable MFA for all users.
B.Configure SCIM provisioning.
C.Apply a Network Policy at the account level.
D.Implement OAuth security integration.
AnswerC

Network Policies at the account level are the standard way to enforce IP allowlists and blocklists globally. By applying the policy to the account, Snowflake inspects the source IP of every incoming request against the defined CIDR blocks, ensuring that only traffic from the VPN is permitted.

Why this answer

Network Policies provide the primary mechanism for controlling access based on IP addresses. By defining an allowed list of CIDR blocks, the architect creates a perimeter defense that prevents unauthorized access from public networks. This is crucial for compliance in highly regulated industries, ensuring that data exposure risks are mitigated by restricting the attack surface to trusted network locations only, effectively blocking any connection attempts outside the defined enterprise perimeter.

Exam trap

Candidates often suggest object-level security or user-level settings. They fail to recognize that network-based access restrictions must be applied at the account level via Network Policies.

17
MCQmedium

An architect needs to audit all queries executed by users in the last 30 days. Which approach is most efficient?

A.Query the INFORMATION_SCHEMA.QUERY_HISTORY view.
B.Query the SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY view.
C.Enable query logging in the user profile.
D.Use the GET_QUERY_HISTORY() function.
AnswerB

The ACCOUNT_USAGE.QUERY_HISTORY view contains query metadata for up to 365 days, making it the correct choice for a 30-day lookback requirement. It is designed for audit and analysis purposes, providing a centralized and consistent view of all query activity across the account without requiring the maintenance of custom logging solutions.

Why this answer

The SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY view is the standard interface for auditing executed queries. It provides a comprehensive historical record of all SQL commands, their execution times, and the users who ran them. This is the most efficient and scalable method for auditing compared to manual logs or local metadata, as it is maintained and optimized by Snowflake, ensuring minimal impact on production query performance.

Exam trap

Candidates frequently mistake INFORMATION_SCHEMA for ACCOUNT_USAGE views, forgetting that INFORMATION_SCHEMA only retains query history for the last 7 days.

18
MCQmedium

A Snowflake architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that tenant administrators can manage roles and users within their own database but cannot affect other tenants. Which Snowflake feature should be used to achieve this isolation?

A.Network policies
B.Resource monitors
C.Account roles
D.Database roles
AnswerD

Database roles allow you to define roles within a specific database, enabling granular access control. A tenant administrator can be granted a database role with privileges to manage objects within that database, without having account-level privileges. This provides isolation because database roles are scoped to the database and cannot affect other databases or account-level objects.

Why this answer

Database roles are scoped to a specific database and allow for granular privilege management within that database. By granting a tenant administrator a database role with the ability to create and manage other database roles, you enable them to manage access within their database without affecting other databases. Account roles are too broad and would not provide the needed isolation.

Exam trap

The trap here is confusing account-level roles with database-scoped roles; account roles grant privileges across the account, not just within a single database.

19
MCQhard

A financial services firm uses Snowflake with Tri-Secret Secure. They have integrated AWS KMS with Snowflake and manage their own key. During a security audit, the auditor asks how Snowflake ensures that data cannot be decrypted if the customer revokes access to their key. Which statement accurately describes the behavior?

A.Revoking the key only prevents new data from being encrypted, but existing data remains accessible.
B.Snowflake stores a copy of the customer's key in an encrypted vault to ensure availability.
C.If the customer revokes the key, Snowflake immediately loses the ability to decrypt data, and data becomes inaccessible.
D.Snowflake can still decrypt data using its internal key, but the customer's key is required for auditing.
AnswerC

In Tri-Secret Secure, Snowflake combines a Snowflake-managed key with a customer-managed key. If the customer revokes access to their key in the KMS, Snowflake cannot retrieve it, and thus cannot decrypt the data. This provides an effective kill switch, ensuring data is inaccessible without the customer's key.

Why this answer

Tri-Secret Secure uses a composite master key consisting of a Snowflake-managed key and a customer-managed key. If the customer revokes access to their key, Snowflake cannot reconstruct the composite key, making data undecryptable. This provides a strong security control where the customer retains ultimate control over data access.

Other options incorrectly suggest Snowflake retains a copy or can bypass the customer key.

Exam trap

The trap here is thinking Snowflake keeps a backup of the customer key or can decrypt without it, which contradicts the zero-trust model of Tri-Secret Secure.

20
MCQhard

A security architect is configuring access control for a Snowflake environment. They need to ensure that a service account used by an ETL tool can only access specific tables in a schema and cannot create or drop any objects. The ETL tool connects using key-pair authentication. Which set of privileges should be granted to the service account's role to adhere to the principle of least privilege?

A.Grant USAGE on the database and schema, and CREATE TABLE on the schema.
B.Grant USAGE on the database and schema, and SELECT on all tables in the schema.
C.Grant USAGE on the database and schema, and ALL PRIVILEGES on the specific tables.
D.Grant USAGE on the database and schema, and SELECT on the specific tables.
AnswerD

Granting USAGE on the database and schema allows the role to see and use these objects, while SELECT on the specific tables provides read access only. This follows least privilege because it does not allow any object creation or modification, and restricts access to only the required tables.

Why this answer

The principle of least privilege requires granting only the privileges necessary to perform the required tasks. The ETL tool needs to read specific tables, so USAGE on the database and schema plus SELECT on those tables is sufficient. This avoids unnecessary privileges like object creation or data modification.

Exam trap

The trap here is assuming that ALL PRIVILEGES on tables or SELECT on all tables in the schema is acceptable, when it grants more access than needed.

21
MCQhard

An architect is tasked with auditing all failed login attempts for a security investigation. Which view should be queried?

A.QUERY_HISTORY
B.ACCESS_HISTORY
C.LOGIN_HISTORY
D.SESSIONS
AnswerC

LOGIN_HISTORY is the authoritative source for tracking authentication activity. It contains columns for the event status, including failures, the user attempting to log in, and the source IP, which are critical data points for performing a thorough security audit regarding unauthorized access attempts or credential testing.

Why this answer

The ACCOUNT_USAGE schema provides historical metadata about account activity. Specifically, the LOGIN_HISTORY view records all login attempts, including successes and failures, the client used, and the source IP address. Querying this view is essential for security architects to identify brute-force attacks or anomalous behavior, allowing them to take proactive measures such as updating network policies or flagging compromised accounts, thereby maintaining the overall integrity and security posture of the Snowflake environment.

Exam trap

Candidates often choose QUERY_HISTORY or ACCESS_HISTORY instead of LOGIN_HISTORY when specifically looking for failed authentication attempts.

22
MCQhard

Refer to the exhibit. Based on the security integration definition provided, what is the primary purpose of the 'token_user_field' parameter in this specific configuration?

A.It specifies the Snowflake role that the user will be assigned when they connect via the OAuth provider.
B.It defines the field in the OAuth token that Snowflake uses to match against the login_name of a Snowflake user.
C.It identifies the public key used to verify the digital signature of the incoming OAuth access token.
D.It determines the audience for which the token was issued to prevent token substitution attacks.
AnswerB

The `token_user_field` parameter identifies the claim within the JWT, such as 'upn' or 'email', that Snowflake will extract to find a matching user record. If the value in this field does not match a user's `login_name` in Snowflake, the authentication attempt will fail because the identity cannot be resolved.

Why this answer

External OAuth allows third-party identity providers like Azure AD to authorize access to Snowflake. The `token_user_field` is a critical configuration parameter that tells Snowflake which claim in the incoming JWT (JSON Web Token) should be used to identify the Snowflake user. In this exhibit, setting it to 'upn' ensures the user identity is mapped correctly from the Microsoft environment.

Exam trap

Candidates often confuse the 'token_user_field' with the 'issuer' or 'client_id', failing to understand that this field specifically maps the identity provider's claim to the Snowflake login_name.

23
MCQmedium

A healthcare company stores PHI in a Snowflake database and must ensure that only authorized roles can decrypt the data at rest. They want an additional layer of protection so that even Snowflake cannot access the data without a customer-held key. Which Snowflake feature should the architect implement?

A.Network policies with private connectivity
B.Column-level security with masking policies
C.Client-side encryption with Snowflake's ENCRYPT function
D.Tri-Secret Secure
AnswerD

Tri-Secret Secure combines a customer-managed key in a cloud KMS with Snowflake's internal key, creating a composite master key. This ensures that data cannot be decrypted without the customer's key, satisfying the requirement that even Snowflake cannot access data without customer consent. It is the correct choice for an additional layer of protection for data at rest.

Why this answer

Tri-Secret Secure is designed to give customers control over a key that is part of the encryption hierarchy. By combining a customer-managed key with Snowflake's key, it ensures that data cannot be decrypted without the customer's key, providing an extra layer of protection. This directly addresses the need for customer-controlled encryption at rest.

Exam trap

The trap here is confusing access control features like masking policies with encryption key management features.

24
Multi-Selectmedium

Which TWO of the following statements correctly describe the behavior of Key Pair Authentication in Snowflake?

Select 2 answers
A.The private key is stored in the Snowflake user object.
B.The public key must be associated with the user profile.
C.Key pair authentication is only supported for the ACCOUNTADMIN role.
D.Key rotation involves updating the public key in the Snowflake user object.
E.Snowflake manages the generation of the private key.
AnswersB, D

To enable key pair authentication, the public key must be converted to a specific format and associated with the Snowflake user via an ALTER USER command. Snowflake uses this stored public key to verify the signature generated by the client's private key during the authentication sequence, confirming the user's identity.

Why this answer

Key Pair Authentication replaces traditional password authentication with a cryptographic approach using a private key stored locally and a public key registered in Snowflake. This is essential for automated services and programmatic access where hardcoded passwords pose security risks. By rotating keys and managing the public key in the user object, security architects can implement high-assurance machine-to-machine authentication protocols that eliminate the risks of credential leakage.

Exam trap

Candidates often assume that Key Pair Authentication requires a certificate authority or that the private key must be uploaded to Snowflake. They fail to understand that only the public key is registered in Snowflake.

25
MCQmedium

Refer to the exhibit. An architect attempts to connect to Snowflake from 10.0.0.5. Based on the configuration, what will happen?

A.The connection is successful.
B.The connection is rejected.
C.The connection depends on the user's role.
D.The connection is deferred to the secondary policy.
AnswerB

The connection is rejected because 10.0.0.5 falls within the blocked 10.0.0.0/8 CIDR range. In Snowflake network policy evaluation logic, an explicit block always overrides an allow entry, providing a definitive security posture that prevents unauthorized access from specific network segments, even if misconfigurations exist elsewhere in the policy.

Why this answer

Snowflake evaluates network policies by checking the blocked list first, then the allowed list. Because the IP 10.0.0.5 falls within the 10.0.0.0/8 range defined in the blocked_ip_list, the connection request is rejected immediately. Even if the IP were also in an allowed range, the explicit block takes precedence, ensuring that known malicious or restricted subnets are denied access regardless of other configuration settings within the specific network policy applied to the account.

Exam trap

Many candidates assume that an allowed IP range overrides a blocked list entry, forgetting that Snowflake evaluates blocked lists first.

26
MCQmedium

A global enterprise is consolidating multiple Snowflake accounts into a single Organization to optimize billing and data sharing. They need to move a large production database from an account in 'aws_us_east_1' to an account in 'azure_west_us'. What is the most efficient architectural approach to achieve this while maintaining data consistency?

A.Unload data to a cross-region S3 bucket and use the COPY INTO command to load it into the Azure account.
B.Use Snowflake Data Sharing to share the database from the AWS account to the Azure account directly.
C.Enable database replication between the source AWS account and the target Azure account within the Organization.
D.Create a Clone of the database and use the Snowflake CLI to push the metadata to the Azure account.
AnswerC

Database replication allows for the asynchronous synchronization of databases across different regions and cloud providers within a Snowflake Organization. This feature provides a robust way to migrate data while preserving object metadata and ensuring that the target account remains consistent with the primary source database without complex manual intervention.

Why this answer

Consolidating multiple Snowflake accounts into a single Organization requires a strategy for moving data across regions. Snowflake's cross-region database replication is the primary mechanism for this, as it handles the underlying cloud provider differences and ensures data integrity through asynchronous synchronization. This architectural approach minimizes downtime and prevents the complexities of manual export/import processes while maintaining a single source of truth.

Exam trap

Candidates frequently suggest manual data unloading and loading via S3/Blob storage, ignoring the architectural efficiency of built-in database replication which handles cross-region synchronization automatically.

27
Multi-Selectmedium

An architect is configuring key-pair authentication for a service account used by an automated ETL process. They need to ensure the private key is stored securely and the public key is assigned to the user. Which two actions should be performed? (Choose two.)

Select 2 answers
A.Assign the public key to the Snowflake user using ALTER USER ... SET RSA_PUBLIC_KEY.
B.Generate a PEM private key and store it in a secure vault accessible only to the ETL service.
C.Enable multi-factor authentication for the service account to add an extra layer of security.
D.Set the user's RSA_PUBLIC_KEY_FP parameter to the fingerprint of the private key.
E.Configure the ETL service to use the private key passphrase in the connection string.
AnswersA, B

The public key corresponding to the private key must be assigned to the Snowflake user. This is done with ALTER USER <username> SET RSA_PUBLIC_KEY='<public_key>'. Snowflake uses this public key to verify the signature created with the private key. Without this step, the user cannot authenticate using key-pair, as Snowflake has no knowledge of the public key to validate the signature.

Why this answer

For key-pair authentication, the private key must be securely stored and the corresponding public key assigned to the Snowflake user. The private key is used by the client to sign authentication requests, and Snowflake verifies the signature using the public key. Storing the private key in a vault and setting the public key via ALTER USER are the essential steps to enable this authentication method securely.

Exam trap

The trap here is confusing the public key fingerprint parameter with the actual public key assignment, or assuming MFA is required for service accounts.

28
MCQmedium

A security architect at a financial services company needs to ensure that all data stored in Snowflake is encrypted with keys that the company controls and can revoke at any time. They have already enabled Tri-Secret Secure. Which additional configuration is required to meet this requirement?

A.Create a custom role with the MANAGE ENCRYPTION KEYS privilege and assign it to the security team.
B.Set up a network policy that restricts access to the Snowflake account to only the company's IP ranges.
C.Configure the account to use a customer-managed key (CMK) stored in a supported cloud KMS.
D.Enable periodic rekeying of the Snowflake-managed key through the ACCOUNTADMIN role.
AnswerC

Tri-Secret Secure combines a Snowflake-managed key with a customer-managed key (CMK) that you create and control in your cloud provider's KMS (AWS KMS, Azure Key Vault, or GCP KMS). By configuring the CMK, the company retains control over the key and can revoke access by disabling or deleting the CMK, which renders the data inaccessible. This is exactly what the scenario requires.

Why this answer

Tri-Secret Secure requires a customer-managed key (CMK) in a supported cloud KMS to give the customer control over encryption keys. By configuring the CMK, the company can revoke access by disabling the key. The other options do not provide key control: rekeying is automatic and not customer-controlled, network policies are unrelated to encryption, and there is no Snowflake privilege to manage encryption keys directly.

Exam trap

The trap here is assuming that enabling Tri-Secret Secure alone provides customer-controlled keys, when in fact it must be paired with a customer-managed key in the cloud KMS.

29
MCQhard

An organization wants to centralize user management by integrating Snowflake with their corporate Okta instance using SCIM. Which architectural component facilitates the synchronization of user metadata between Okta and Snowflake?

A.Snowflake Data Share.
B.Snowflake SCIM provisioning integration.
C.External OAuth security integration.
D.Snowflake Native App.
AnswerB

The SCIM provisioning integration acts as the bridge between the identity provider and Snowflake. It exposes a REST API endpoint that Okta calls to push user and group changes, ensuring that identity information remains synchronized without requiring manual intervention by the Snowflake administrator for each new joiner or leaver.

Why this answer

SCIM (System for Cross-domain Identity Management) is an open standard that allows for the automation of user provisioning. By using the Snowflake SCIM integration, the architect ensures that user additions, updates, and deletions in Okta are automatically reflected in Snowflake. This eliminates manual administrative overhead and reduces the risk of orphaned accounts or stale permissions, which are common security vulnerabilities in large organizations where employee turnover is high and manual tracking is prone to errors.

Exam trap

Test-takers frequently confuse manual user creation scripts or OAuth configurations with SCIM when asked about automated user metadata synchronization.

30
MCQhard

Which TWO of the following are true regarding the use of Snowflake Data Shares for security purposes?

A.Data shares allow consumers to write back to the source.
B.Data shares eliminate the need for data duplication.
C.Data shares automatically copy data to the consumer.
D.The provider can revoke access at any time.
E.Shares require public internet access.
AnswerB, D

Sharing data via Snowflake's secure sharing mechanism means the consumer accesses the provider's data directly in the provider's account. This avoids creating copies of sensitive data, which is a major security improvement over traditional methods like SFTP or cloud storage dumps that increase the organization's data attack surface.

Why this answer

Data Shares provide a secure way to share data without copying it. The provider account retains full control over the data objects, and the consumer account gets read-only access. This architecture is inherently more secure than traditional ETL-based data transfer methods because it eliminates the movement of data, reduces the risk of data leakage during transit, and ensures that the consumer is always querying the most up-to-date version of the data provided by the source.

Exam trap

Test-takers often assume data sharing copies data into the consumer's storage, missing the zero-copy architecture of Snowflake secure shares.

31
MCQhard

A financial institution uses Snowflake with Tri-Secret Secure backed by a customer-managed key in AWS KMS. The security team wants to rotate the customer-managed key without causing downtime or requiring re-encryption of all data. What is the correct procedure?

A.Create a new customer-managed key in AWS KMS, update the Snowflake account to use the new key, and Snowflake will automatically re-encrypt all data in the background.
B.Disable Tri-Secret Secure, rotate the key, and then re-enable Tri-Secret Secure; this will automatically re-wrap all data encryption keys with the new key.
C.Manually re-encrypt all data by running ALTER ACCOUNT SET ENCRYPTION_KEY, which triggers a full re-encryption process.
D.Rotate the customer-managed key by creating a new key version in AWS KMS; Snowflake will automatically use the new version for new data and continue to decrypt old data using the old version.
AnswerD

AWS KMS supports key rotation by creating new key versions under the same customer-managed key. Snowflake Tri-Secret Secure uses the KMS key to wrap the Snowflake-managed key. When a new key version is created, Snowflake can use it for new wrapping operations while still decrypting existing wrapped keys with the old version, as KMS retains all versions. This enables seamless rotation without downtime or re-encryption of data.

Why this answer

Tri-Secret Secure uses a customer-managed key in AWS KMS to add an extra layer of encryption. Key rotation in KMS is achieved by creating a new key version. Snowflake can use the new version for new data while still decrypting old data with previous versions, because KMS retains all versions.

This allows seamless rotation without downtime or data re-encryption. The other options involve incorrect commands or unnecessary re-encryption.

Exam trap

The trap here is thinking that rotating the customer-managed key requires re-encrypting all data or that Snowflake automatically re-encrypts everything when the key changes.

32
MCQeasy

A Snowflake architect is using the Data Exchange to share data with a partner who does not have a Snowflake account. What is the most appropriate feature to use?

A.Direct Data Sharing to the partner's corporate email address.
B.The creation of a Managed (Reader) Account for the partner.
C.FTP export to the partner's secure external storage bucket.
D.Granting the partner access via a temporary security token.
AnswerB

Managed accounts are specifically designed for this scenario, allowing the provider to create a dedicated Snowflake environment for the consumer. The provider manages the account and pays for the compute resources used by the partner, making it an ideal solution for sharing data with external entities.

Why this answer

Managed accounts, also known as reader accounts, allow Snowflake customers to share data with parties who do not have their own Snowflake subscription. This feature enables the provider to bear the cost of the consumer's queries, facilitating easy and secure data collaboration without requiring the partner to manage an account.

Exam trap

Candidates often suggest creating a standard user account or a share, forgetting that external partners without existing Snowflake accounts require the specific provisioning of a Reader Account.

33
MCQhard

What is the primary benefit of implementing Snowflake Tri-Secret Secure?

A.It automatically rotates data encryption keys every 24 hours.
B.It enables the use of three different identity providers for authentication.
C.It allows customers to have total control over data access by managing one of the master keys.
D.It provides a three-way handshake for all data transfers via Snowpipe.
AnswerC

By integrating a customer-managed key from AWS KMS, Azure Key Vault, or Google Cloud KMS, the customer gains the ability to effectively 'kill' access to their Snowflake data. If the customer disables their key, Snowflake can no longer decrypt the data, providing a high level of sovereignty.

Why this answer

Tri-Secret Secure is an advanced security feature that combines a customer-managed key with Snowflake-managed keys to encrypt data. This provides an additional layer of control, as it allows the customer to revoke access to their data by disabling their key in their own cloud provider's Key Management Service.

Exam trap

Candidates often confuse Tri-Secret Secure with standard encryption-at-rest. They miss the key point that it provides external control via the customer's own cloud Key Management Service.

34
MCQmedium

An organization has a Network Policy applied at the Account level to restrict IP ranges. A specific user requires access from a home office IP not in the account range. How should the architect configure this while maintaining the strictest security posture?

A.Modify the existing account-level network policy to include the user's home IP address.
B.Create a new role for the user and attach the network policy to that specific role.
C.Create a user-level network policy and assign it directly to that specific user account.
D.Disable the account-level network policy and rely solely on multi-factor authentication for security.
AnswerC

User-level network policies take precedence over account-level policies, allowing architects to define exceptions for specific identities. By creating a policy that includes the unique IP and assigning it directly to the user, the architect ensures that only that specific identity can bypass the broader organizational restrictions.

Why this answer

Snowflake evaluates network policies at the most granular level first, starting with the user, then the account. Applying a specific policy to the individual user overrides the account-level restrictions without opening access for the entire organization. This hierarchy allows for precise control over entry points while maintaining a broad security baseline for all other platform participants.

Exam trap

Candidates incorrectly assume account-level network policies can be bypassed via exceptions or that they must alter the main company-wide IP range.

Ready to test yourself?

Try a timed practice session using only Accounts And Security questions.