Which TWO of the following are true regarding Snowflake Access History?
Trap 1: Access History only records queries executed by human users.
Access History records all data access, including those originating from internal system processes, automated scripts, and service accounts. Governance requires visibility into every access point, regardless of the initiator, to ensure that automated ETL jobs and machine learning models are compliant with data privacy policies and organizational standards.
Trap 2: Access History is automatically enabled for all accounts and cannot…
While Access History is a core feature, certain aspects of telemetry and data retention are tied to Snowflake edition capabilities and account settings. Administrators must ensure the account is properly configured to capture the desired level of detail to support enterprise-wide governance initiatives and detailed security audits.
Trap 3: Access History includes the results of all queries executed.
Access History records the metadata about the query, such as objects queried and columns accessed, not the actual result sets returned to the user. Storing result sets would be a significant security risk and would create massive data volumes, making the audit logs difficult to query or maintain.
- A
Access History is stored in the ACCOUNT_USAGE schema and is available for 365 days.
The ACCESS_HISTORY view is located in the SNOWFLAKE.ACCOUNT_USAGE schema. By default, Snowflake retains historical data in the ACCOUNT_USAGE views for one year (365 days), providing a long-term audit trail necessary for security investigations, compliance reporting, and tracking data lineage over extended organizational periods.
- B
Access History only records queries executed by human users.
Why it fails: Access History records all data access, including those originating from internal system processes, automated scripts, and service accounts. Governance requires visibility into every access point, regardless of the initiator, to ensure that automated ETL jobs and machine learning models are compliant with data privacy policies and organizational standards.
- C
Access History tracks the objects accessed, including columns, even if nested in views.
One of the primary benefits of Access History is its ability to track lineage through complex view hierarchies. It identifies the underlying base tables and columns accessed through views, allowing data engineers to map sensitive data flow across the entire Snowflake ecosystem for comprehensive audit and compliance tracking.
- D
Access History is automatically enabled for all accounts and cannot be disabled.
Why it fails: While Access History is a core feature, certain aspects of telemetry and data retention are tied to Snowflake edition capabilities and account settings. Administrators must ensure the account is properly configured to capture the desired level of detail to support enterprise-wide governance initiatives and detailed security audits.
- E
Access History includes the results of all queries executed.
Why it fails: Access History records the metadata about the query, such as objects queried and columns accessed, not the actual result sets returned to the user. Storing result sets would be a significant security risk and would create massive data volumes, making the audit logs difficult to query or maintain.