What you will be able to do
- Automate recurring compliance checks with Snowflake alerts built on Account Usage data
- Generate a Trust Center account posture report as dated audit evidence
- Name Snowflake's security certifications and explain how to obtain compliance reports through the Snowflake Compliance Center
1.Defining and automating audit checks
The exam guide asks you to define, enable and automate audit policies. None of the available Snowflake documentation describes an object called an 'audit policy'. In practice, an audit policy is a combination of three things: a rule saying what must be watched, a data source that records it, and a scheduled check that raises an alarm. Snowflake supplies each part separately.
The data source is Account Usage, especially ACCESS_HISTORY. Know its limits before relying on it. Records in the Account Usage QUERY_HISTORY view are not always copied into ACCESS_HISTORY, because the structure of the SQL statement decides whether an entry is written. A related detail: connectors such as the Python connector or the SQL API can submit several statements in one request and return only a single parent ID. To audit each statement in that request, filter on parent_query_id:
SELECT query_id, parent_query_id, direct_objects_accessed FROM snowflake.account_usage.access_history WHERE parent_query_id = 6789;The scheduled check is a Snowflake alert. An alert is a schema-level object with three parts: a condition that triggers it, an action to take when the condition is met (for example, send an email notification or capture some data in a table), and a schedule for evaluating the condition, such as every 24 hours or every Sunday at midnight. Snowflake's own examples include being notified when your data fails to comply with a business rule you have set up. A compliance rule, such as 'nobody outside the payments role writes to the card table', fits that pattern. The condition queries Account Usage, and the action emails the security team.
For misconfigurations, the Trust Center provides a second, prebuilt layer. Its scanners check the account against built-in recommendations, and you can configure proactive notifications so that problems reach you without anyone having to look.
Checkpoint 1 of 5· Check yourself
Which three parts must you define when you create a Snowflake alert to enforce a compliance rule?
An alert is a schema-level object that specifies the triggering condition, the action to take, and the evaluation schedule.
“When and how often the condition should be evaluated (for example, every 24 hours or every Sunday at midnight).”Source: docs.snowflake.com
Checkpoint 2 of 5· Exam question
A health insurer tags every column that holds personal email addresses with the object tag `PII_EMAIL` across 40 databases, and new tables appear weekly. To support GDPR data minimisation, only the `COMPLIANCE_OFFICER` role may see clear text. Which design needs the least ongoing maintenance?
Correct answer: A — Create a masking policy that tests `IS_ROLE_IN_SESSION('COMPLIANCE_OFFICER')` and set it on the `PII_EMAIL` tag so tagged columns inherit it
- A. Correct. A tag-based masking policy is applied automatically to every column that carries the tag, including columns tagged on tables created later, so no per-column work is needed.
- B. Incorrect. A scheduled procedure can eventually achieve the same result, but it leaves a gap between tagging and protection and needs constant upkeep and failure handling.
- C. Incorrect. Secure views must be built and kept in sync for every table, and the underlying tables stay exposed to anyone granted access to them.
- D. Incorrect. Row access policies cannot be assigned to tags and filter rows rather than masking column values, so this does not satisfy the requirement.
2.Trust Center account posture: compliance evidence on demand
In Snowsight, the Trust Center checks your account against recommendations that are built into its scanners. A violation is a configuration that keeps failing a scanner's requirements over time. You can triage a violation, resolve it or reopen it, and record a justification for audit purposes. Once a violation is resolved, Snowflake stops sending email notifications about it.
What an auditor usually wants, though, is a summary over a period. The Account posture section on the Overview tab provides it. It collects Trust Center activity for the period you choose and produces a PDF. The PDF is a self-contained, point-in-time record, which Snowflake describes as useful for compliance evidence and for management or auditor reporting. To view the section or generate the report, your role needs the SNOWFLAKE.TRUST_CENTER_VIEWER or SNOWFLAKE.TRUST_CENTER_ADMIN application role. A user with ACCOUNTADMIN must grant it first.
CREATE ROLE trust_center_viewer_role;
GRANT APPLICATION ROLE SNOWFLAKE.TRUST_CENTER_VIEWER TO ROLE trust_center_viewer_role;| Report section | Contents |
|---|---|
| Scanner enablement | How many first-party scanners are enabled, with coverage per scanner package |
| Scanner activity in period | Which scanners ran and how many found no at-risk entities |
| Configuration changes | Latest enable or disable per package, plus triage activity (mute, unmute, comments) |
| Violation findings activity in period | Newly opened, remediated, increased, decreased, unchanged, no active findings, muted |
| Detection findings activity in period | Detections reported, and scanners that ran without detections |
| Scanner status | Each scanner's description, status, last run and schedule |
The period defaults to the last 28 days, and all timestamps in the report are in UTC. The Configuration changes section is narrower than its name implies. It leaves out individual scanner enable and disable actions, schedule updates and notification-setting changes. To show who made those changes, use query history.
Checkpoint 3 of 5· Put it in order
Put the steps for generating a posture report in order
- 1.Sign in to Snowsight
- 2.Select Generate report
- 3.Select Governance & security » Trust Center
- 4.Select the Overview tab
- 5.Switch to a role with SNOWFLAKE.TRUST_CENTER_VIEWER or SNOWFLAKE.TRUST_CENTER_ADMIN
- 6.Choose a time period in the Account posture section
The documented procedure opens the Overview tab with a suitable role, then selects a period in Account posture and generates the PDF.
“On the Overview tab, in the Account posture section, select a time period from the drop-down menu.”Source: docs.snowflake.com
3.Security certifications, compliance reports and the Snowflake Compliance Center
Your own evidence covers your share of the controls. Snowflake's certifications cover its share. Snowflake publishes a reference list of its certifications by geographic region. The list includes CSA Star Level 1, ISO-9001:2015, ISO-27001, ISO-27017, ISO-27018, SOC 1 Type II, SOC 2 Type II, FedRAMP (Moderate and High), HITRUST CSF, PCI DSS, IRAP (Protected), C5 and others.
Some of these produce reports you can request. A SOC 2 Type II report is an independent auditor's attestation of how Snowflake's security, availability and confidentiality controls were designed and how effectively they operated over the coverage period. SOC 1 Type II covers internal controls over financial reporting. The documentation for both points to the Snowflake Compliance Center for requesting a copy. Snowflake's ISO certificate can be downloaded from the Compliance Center. Its statement of applicability also includes control objectives from ISO 27017:2015 and ISO 27018:2019. For PCI DSS, you request the AoC.
The term 'Trust Center' can cause confusion. In the product documentation, the Trust Center is the in-account Snowsight feature covered in the previous section. Snowflake's own certificates and attestation reports come from the Compliance Center.
Checkpoint 4 of 5· Match them up
Match each compliance artefact to what it is or how you get it
Tap a term, then the definition that fits it.
Each certification page describes what the report attests and points to the Compliance Center, or to a request, as the way to obtain it.
“Snowflake’s ISO Certificate is available for download from the Snowflake Compliance Center.”Source: docs.snowflake.com
Checkpoint 5 of 5· Exam question
A retailer keeps customer orders for EU and US residents in one table with a `REGION` column. To honour regional processing restrictions, the EU analyst team must see only EU rows and the US team only US rows, and team assignments change monthly. Which approach fits best?
Correct answer: A — Attach a row access policy that looks up the invoking role in a role-to-region mapping table and passes only matching `REGION` rows
- A. Correct. A row access policy driven by a mapping table filters rows per role at query time, and monthly reassignments only require updating the mapping table.
- B. Incorrect. A masking policy changes the value of one column, so the rows themselves would still be returned to the wrong team.
- C. Incorrect. Network policies decide where a connection may originate and have no effect on which rows a role can read.
- D. Incorrect. An aggregation policy forces aggregate queries over minimum group sizes but does not partition data between teams by region.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Every query in QUERY_HISTORY also has a matching row in ACCESS_HISTORY, so either view gives complete data-access evidence.Why is that wrong?
Not every statement in QUERY_HISTORY is written to ACCESS_HISTORY. The structure of the SQL statement decides whether an entry is recorded.
Covered in Defining and automating audit checks
2.The posture report's Configuration changes section shows every Trust Center change, including who changed scanner schedules.Why is that wrong?
That section excludes individual scanner toggles, schedule updates and notification-setting changes. Use query history to find who made them.
Covered in Trust Center account posture: compliance evidence on demand
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.https://docs.snowflake.com/en/user-guide/alertsOfficial docs
“A Snowflake alert is a schema-level object that specifies:”
↩︎ Defining and automating audit checks“send an email notification, capture some data in a table”
↩︎ Defining and automating audit checks“Your data fails to comply with a particular business rule that you have set up.”
↩︎ Defining and automating audit checks“When and how often the condition should be evaluated (for example, every 24 hours or every Sunday at midnight).”
↩︎ Checkpoint - 2.
“You can also use the Trust Center to configure proactive notifications that help you monitor your account for security risks.”
↩︎ Defining and automating audit checks“The Trust Center evaluates each Snowflake account against recommendations that are specified in scanners.”
↩︎ Trust Center account posture: compliance evidence on demand“Resolve or reopen violations for any reason and record justification for audit needs.”
↩︎ Trust Center account posture: compliance evidence on demand“a user with the ACCOUNTADMIN role must grant the SNOWFLAKE.TRUST_CENTER_VIEWER or SNOWFLAKE.TRUST_CENTER_ADMIN application role to your role”
↩︎ Trust Center account posture: compliance evidence on demand - 3.
“useful for compliance evidence and for management or auditor reporting”
↩︎ Trust Center account posture: compliance evidence on demand“All timestamps in the report are shown in UTC.”
↩︎ Trust Center account posture: compliance evidence on demand“To see who made other configuration changes, review your account’s query history.”
↩︎ Exam trap 2“Scanners that ran clean during the period are reported alongside open findings”
↩︎ Prediction“On the Overview tab, in the Account posture section, select a time period from the drop-down menu.”
↩︎ Checkpoint - 4.
“This topic is a reference for Snowflake certifications based on geographic regions.”
↩︎ Security certifications, compliance reports and the Snowflake Compliance Center - 5.https://docs.snowflake.com/en/user-guide/cert-soc-2Official docs
“an independent auditor’s attestation of the design and operating effectiveness of the security, availability, and confidentiality controls”
↩︎ Security certifications, compliance reports and the Snowflake Compliance Center“For information about requesting a copy of the report, see the Snowflake Compliance Center.”
↩︎ Security certifications, compliance reports and the Snowflake Compliance Center - 6.https://docs.snowflake.com/en/user-guide/cert-soc-1Official docs
“internal controls over financial reporting”
↩︎ Security certifications, compliance reports and the Snowflake Compliance Center - 7.
“The statement of applicability also includes control objectives from the ISO 27017:2015 & ISO 27018:2019 framework.”
↩︎ Security certifications, compliance reports and the Snowflake Compliance Center“Snowflake’s ISO Certificate is available for download from the Snowflake Compliance Center.”
↩︎ Checkpoint - 8.
“The AoC (Attestation of Compliance) is available upon request.”
↩︎ Security certifications, compliance reports and the Snowflake Compliance Center
Also cited
“Records in the Account Usage QUERY_HISTORY view do not always get recorded in the ACCESS_HISTORY view.”
↩︎ Exam trap 1