CertSafari
    Snowflake SnowPro Advanced: Security Engineer (SEA-C01)· Lessons

    Domain 3 · Lesson 14/21

    Automating Compliance Audits and Using Snowflake Trust Center Evidence

    Design and manage data compliance policies.

    8 min read
    6% of exam
    9 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Automate recurring compliance checks with Snowflake alerts built on Account Usage data
    • Generate a Trust Center account posture report as dated audit evidence
    • Name Snowflake's security certifications and explain how to obtain compliance reports through the Snowflake Compliance Center

    1.Defining and automating audit checks

    The exam guide asks you to define, enable and automate audit policies. None of the available Snowflake documentation describes an object called an 'audit policy'. In practice, an audit policy is a combination of three things: a rule saying what must be watched, a data source that records it, and a scheduled check that raises an alarm. Snowflake supplies each part separately.

    The data source is Account Usage, especially ACCESS_HISTORY. Know its limits before relying on it. Records in the Account Usage QUERY_HISTORY view are not always copied into ACCESS_HISTORY, because the structure of the SQL statement decides whether an entry is written. A related detail: connectors such as the Python connector or the SQL API can submit several statements in one request and return only a single parent ID. To audit each statement in that request, filter on parent_query_id:

    Listing the individual statements behind a multi-statement request in ACCESS_HISTORYsql
    SELECT query_id, parent_query_id, direct_objects_accessed FROM snowflake.account_usage.access_history WHERE parent_query_id = 6789;

    The scheduled check is a Snowflake alert. An alert is a schema-level object with three parts: a condition that triggers it, an action to take when the condition is met (for example, send an email notification or capture some data in a table), and a schedule for evaluating the condition, such as every 24 hours or every Sunday at midnight. Snowflake's own examples include being notified when your data fails to comply with a business rule you have set up. A compliance rule, such as 'nobody outside the payments role writes to the card table', fits that pattern. The condition queries Account Usage, and the action emails the security team.

    For misconfigurations, the Trust Center provides a second, prebuilt layer. Its scanners check the account against built-in recommendations, and you can configure proactive notifications so that problems reach you without anyone having to look.

    Checkpoint 1 of 5· Check yourself

    Which three parts must you define when you create a Snowflake alert to enforce a compliance rule?

    Checkpoint 2 of 5· Exam question

    A health insurer tags every column that holds personal email addresses with the object tag `PII_EMAIL` across 40 databases, and new tables appear weekly. To support GDPR data minimisation, only the `COMPLIANCE_OFFICER` role may see clear text. Which design needs the least ongoing maintenance?

    Sources12

    2.Trust Center account posture: compliance evidence on demand

    In Snowsight, the Trust Center checks your account against recommendations that are built into its scanners. A violation is a configuration that keeps failing a scanner's requirements over time. You can triage a violation, resolve it or reopen it, and record a justification for audit purposes. Once a violation is resolved, Snowflake stops sending email notifications about it.

    What an auditor usually wants, though, is a summary over a period. The Account posture section on the Overview tab provides it. It collects Trust Center activity for the period you choose and produces a PDF. The PDF is a self-contained, point-in-time record, which Snowflake describes as useful for compliance evidence and for management or auditor reporting. To view the section or generate the report, your role needs the SNOWFLAKE.TRUST_CENTER_VIEWER or SNOWFLAKE.TRUST_CENTER_ADMIN application role. A user with ACCOUNTADMIN must grant it first.

    Granting Trust Center viewer access through a custom rolesql
    CREATE ROLE trust_center_viewer_role;
    GRANT APPLICATION ROLE SNOWFLAKE.TRUST_CENTER_VIEWER TO ROLE trust_center_viewer_role;
    What each section of the PDF posture report gives an auditor
    Report sectionContents
    Scanner enablementHow many first-party scanners are enabled, with coverage per scanner package
    Scanner activity in periodWhich scanners ran and how many found no at-risk entities
    Configuration changesLatest enable or disable per package, plus triage activity (mute, unmute, comments)
    Violation findings activity in periodNewly opened, remediated, increased, decreased, unchanged, no active findings, muted
    Detection findings activity in periodDetections reported, and scanners that ran without detections
    Scanner statusEach scanner's description, status, last run and schedule

    The period defaults to the last 28 days, and all timestamps in the report are in UTC. The Configuration changes section is narrower than its name implies. It leaves out individual scanner enable and disable actions, schedule updates and notification-setting changes. To show who made those changes, use query history.

    Checkpoint 3 of 5· Put it in order

    Put the steps for generating a posture report in order

    1. 1.Sign in to Snowsight
    2. 2.Select Generate report
    3. 3.Select Governance & security » Trust Center
    4. 4.Select the Overview tab
    5. 5.Switch to a role with SNOWFLAKE.TRUST_CENTER_VIEWER or SNOWFLAKE.TRUST_CENTER_ADMIN
    6. 6.Choose a time period in the Account posture section

    Sources23

    3.Security certifications, compliance reports and the Snowflake Compliance Center

    Your own evidence covers your share of the controls. Snowflake's certifications cover its share. Snowflake publishes a reference list of its certifications by geographic region. The list includes CSA Star Level 1, ISO-9001:2015, ISO-27001, ISO-27017, ISO-27018, SOC 1 Type II, SOC 2 Type II, FedRAMP (Moderate and High), HITRUST CSF, PCI DSS, IRAP (Protected), C5 and others.

    Some of these produce reports you can request. A SOC 2 Type II report is an independent auditor's attestation of how Snowflake's security, availability and confidentiality controls were designed and how effectively they operated over the coverage period. SOC 1 Type II covers internal controls over financial reporting. The documentation for both points to the Snowflake Compliance Center for requesting a copy. Snowflake's ISO certificate can be downloaded from the Compliance Center. Its statement of applicability also includes control objectives from ISO 27017:2015 and ISO 27018:2019. For PCI DSS, you request the AoC.

    The term 'Trust Center' can cause confusion. In the product documentation, the Trust Center is the in-account Snowsight feature covered in the previous section. Snowflake's own certificates and attestation reports come from the Compliance Center.

    Checkpoint 4 of 5· Match them up

    Match each compliance artefact to what it is or how you get it

    Tap a term, then the definition that fits it.

    Checkpoint 5 of 5· Exam question

    A retailer keeps customer orders for EU and US residents in one table with a `REGION` column. To honour regional processing restrictions, the EU analyst team must see only EU rows and the US team only US rows, and team assignments change monthly. Which approach fits best?

    Sources45678

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Every query in QUERY_HISTORY also has a matching row in ACCESS_HISTORY, so either view gives complete data-access evidence.Why is that wrong?

      Not every statement in QUERY_HISTORY is written to ACCESS_HISTORY. The structure of the SQL statement decides whether an entry is recorded.

      Covered in Defining and automating audit checks

    2. 2.The posture report's Configuration changes section shows every Trust Center change, including who changed scanner schedules.Why is that wrong?

      That section excludes individual scanner toggles, schedule updates and notification-setting changes. Use query history to find who made them.

      Covered in Trust Center account posture: compliance evidence on demand

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “A Snowflake alert is a schema-level object that specifies:”
      ↩︎ Defining and automating audit checks
      “send an email notification, capture some data in a table”
      ↩︎ Defining and automating audit checks
      “Your data fails to comply with a particular business rule that you have set up.”
      ↩︎ Defining and automating audit checks
      “When and how often the condition should be evaluated (for example, every 24 hours or every Sunday at midnight).”
      ↩︎ Checkpoint
    2. 2.
      “You can also use the Trust Center to configure proactive notifications that help you monitor your account for security risks.”
      ↩︎ Defining and automating audit checks
      “The Trust Center evaluates each Snowflake account against recommendations that are specified in scanners.”
      ↩︎ Trust Center account posture: compliance evidence on demand
      “Resolve or reopen violations for any reason and record justification for audit needs.”
      ↩︎ Trust Center account posture: compliance evidence on demand
      “a user with the ACCOUNTADMIN role must grant the SNOWFLAKE.TRUST_CENTER_VIEWER or SNOWFLAKE.TRUST_CENTER_ADMIN application role to your role”
      ↩︎ Trust Center account posture: compliance evidence on demand
    3. 3.
      “useful for compliance evidence and for management or auditor reporting”
      ↩︎ Trust Center account posture: compliance evidence on demand
      “All timestamps in the report are shown in UTC.”
      ↩︎ Trust Center account posture: compliance evidence on demand
      “To see who made other configuration changes, review your account’s query history.”
      ↩︎ Exam trap 2
      “Scanners that ran clean during the period are reported alongside open findings”
      ↩︎ Prediction
      “On the Overview tab, in the Account posture section, select a time period from the drop-down menu.”
      ↩︎ Checkpoint
    4. 4.
      “This topic is a reference for Snowflake certifications based on geographic regions.”
      ↩︎ Security certifications, compliance reports and the Snowflake Compliance Center
    5. 5.
      “an independent auditor’s attestation of the design and operating effectiveness of the security, availability, and confidentiality controls”
      ↩︎ Security certifications, compliance reports and the Snowflake Compliance Center
      “For information about requesting a copy of the report, see the Snowflake Compliance Center.”
      ↩︎ Security certifications, compliance reports and the Snowflake Compliance Center
    6. 7.
      “The statement of applicability also includes control objectives from the ISO 27017:2015 & ISO 27018:2019 framework.”
      ↩︎ Security certifications, compliance reports and the Snowflake Compliance Center
      “Snowflake’s ISO Certificate is available for download from the Snowflake Compliance Center.”
      ↩︎ Checkpoint

    Also cited

    Ready to test yourself?

    Practise the 22 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.