What you will be able to do
- Explain which Horizon Catalog governance capabilities reduce data security risk and how they apply to every caller
- Enable and schedule Trust Center scanner packages, including CIS Benchmarks, with the correct application role
- Tell violations apart from detections and use severity and at-risk entity counts to weigh likelihood and impact
Key concept
Trust Center as the risk loop — The Trust Center checks a Snowflake account against the recommendations built into its scanners and reports any gaps as findings. Each finding is something you can measure, prioritise and act on. Risk assessment in Snowflake means turning those findings into decisions about what to fix first.
1.Horizon Catalog: the governance baseline you assess against
You can't assess risk until you know what controls are supposed to be in place. In Snowflake, that baseline is Horizon Catalog. Snowflake describes it as a catalog that lets you trust every answer with enterprise-grade governance: sensitive data protection, data quality, end-to-end lineage, AI guardrails, and AI governance. The documentation frames the problem Horizon solves in risk terms. When access controls and lineage are kept separately in different systems, sensitive data becomes difficult to track and protect as it moves between formats and platforms.
Three Horizon properties matter most to a security engineer. First, governance policies run at the query engine layer, not the application layer. That means a masking or row-access policy applies the same way to an analyst, a BI tool or an AI agent, with no separate configuration for AI workloads. Second, sensitive data classification discovers sensitive columns automatically and applies tags and policies as schemas change, so new columns don't slip through unprotected. Third, policies follow the data. Shared data products carry their tags and permissions, and masking and row-access policies are enforced across any Iceberg REST Catalog-compatible engine.
| Horizon capability | Risk it addresses |
|---|---|
| Sensitive data classification | Unprotected sensitive columns as schemas evolve |
| Data protection policies (masking, row-access) | Exposure through Iceberg REST Catalog-compatible engines outside Snowflake |
| AI Guardrails | PII and PHI leaking in agent outputs |
| End-to-end data lineage | Being unable to trace where data, or an AI answer, came from |
| Access control (RBAC, Time Travel, access history) | Being unable to review past activity and data states |
Horizon also connects governance to monitoring. Snowflake says that role-based access controls, Time Travel and access history let you review past activity and data states, and that the Trust Center continuously monitors for misconfigured roles and unprotected columns. Horizon defines the controls, and the Trust Center checks whether they are actually in place.
Checkpoint 1 of 5· Check yourself
Your team puts a masking policy on a customer table. A Cortex agent and a BI dashboard both query that table. What else must you configure so the agent's queries are masked?
Horizon policies run in the query engine, so they apply automatically to humans, BI tools and AI agents. No separate configuration is needed for AI.
“There is no separate governance configuration for AI workloads.”Source: docs.snowflake.com
Sources1
2.Scanner packages, CIS Benchmarks and who can run them
The Trust Center checks an account against the recommendations defined in its scanners, which are grouped into packages. Security Essentials is the only package on by default, and it checks a small set of basic controls: an authentication policy that requires MFA enrolment for human users who sign in with passwords; whether those users are actually enrolled; an account-level network policy that allows access only from trusted IP addresses; and an event table if a native app has event sharing turned on. The CIS Benchmarks, Threat Intelligence and AI Security packages are off until you enable them.
For compliance work, CIS Benchmarks is the package that matters. Once enabled, it runs once a day by default, and you can change that schedule. You can change the schedule of every package except Security Essentials. Be careful how you read a clean CIS result. For some benchmarks, Snowflake checks only whether a control exists, not whether it achieves its objective, so the absence of a violation doesn't guarantee the control is effective.
Access to the Trust Center comes through two application roles that ACCOUNTADMIN grants. SNOWFLAKE.TRUST_CENTER_VIEWER can view the posture overview, violations and detections. SNOWFLAKE.TRUST_CENTER_ADMIN is also needed to manage scanners, scanner packages and the lifecycle of violation findings. The documentation's own example wraps the viewer role in a custom account role:
CREATE ROLE trust_center_viewer_role;
GRANT APPLICATION ROLE SNOWFLAKE.TRUST_CENTER_VIEWER TO ROLE trust_center_viewer_role;Checkpoint 2 of 5· Put it in order
Put the steps for enabling a scanner package such as CIS Benchmarks in order
- 1.Sign in to Snowsight
- 2.In the navigation menu, select Governance & security » Trust Center
- 3.Switch to a role that has the SNOWFLAKE.TRUST_CENTER_ADMIN application role
- 4.Select the scanner package from the list, then select Enable Package
- 5.Select the Manage scanners tab
Enabling a package is a management task, so you switch to the admin application role before going to the Manage scanners tab and choosing the package.
“Switch to a role with the SNOWFLAKE.TRUST_CENTER_ADMIN application role granted to it.”Source: docs.snowflake.com
Checkpoint 3 of 5· Exam question
Which TWO statements about Trust Center findings are accurate?(Select 2)
Correct answers: B, C — Violations persist and are re-reported by their scanners until the underlying configuration is remediated; Detections are one-time events such as a suspicious login, and event-driven scanners report them within about an hour
- A. Incorrect: severity levels are low, medium, high and critical, not informational to emergency.
- B. Correct: scanners keep reporting a violation until the configuration problem is fixed.
- C. Correct: detections describe discrete events and event-driven scanners surface them quickly, typically within an hour.
- D. Incorrect: detection findings cannot be managed or viewed at organization level; that is a documented limitation.
- E. Incorrect: Snowflake reader accounts are not supported by Trust Center, so they need other controls.
- F. Incorrect: violations stay open until remediated; sending a notification does not close them.
Sources2
3.Violations, detections, and weighing likelihood against impact
Scanners produce two kinds of findings, and each tells you something different about risk. A violation is a configuration that doesn't meet a scanner's requirements. It stays in place, and scanners keep reporting it until you change the configuration to fix it. A detection is a single event at a specific time. Examples include logins from an unrecognised IP address, a large transfer of data to an external stage, a task with a high error rate, or client versions such as drivers that may have known vulnerabilities or have reached end of life.
| Aspect | Violation | Detection |
|---|---|---|
| What it represents | A configuration that persists over time | One unique event at a point in time |
| Example | Human users without MFA | Login from an unrecognized IP address |
| Can it be remediated directly? | Yes, by changing the configuration | No. Investigate it and prevent recurrence |
| Lifecycle management | Triage, resolve or reopen with a justification | Not currently supported |
To analyse a vulnerability, you need an estimate of likelihood and an estimate of impact. The Trust Center gives you the inputs but no scoring formula. For impact, the Violations tab colour-codes findings as low, medium, high or critical severity, and the Account posture section counts at-risk entities by type, such as User, Table and Procedure. The Data Security tab shows where sensitive data has been classified. For likelihood, the evidence is whether exploitation is happening, not only possible. A violation is a gap that stays open until fixed. A related detection, such as a suspicious login on an account that also has an open MFA violation, shows someone may already be using it. The documentation treats a detection as something to investigate, and if it turns out to be meaningful, you act to prevent similar events.
Checkpoint 4 of 5· Check yourself
The Trust Center reports a detection for login events from an unrecognised IP address. What is the right response?
A detection records an event that has already happened, so it can't be remediated or resolved. You investigate it and harden the account to prevent it from happening again.
“If the detection is meaningful, you can take actions to prevent similar events in the future.”Source: docs.snowflake.com
Checkpoint 5 of 5· Exam question
A security team must find service accounts that still authenticate with passwords and detect abnormal spikes in failed logins across the account. Which Trust Center scanner package should they enable?
Correct answer: C — Threat Intelligence, which evaluates user types, authentication methods and login activity for password-based users and abnormal failure rates
- A. Incorrect: the AI Security package covers AI workload configuration such as Cortex Search privileges and prompt-injection guardrails, not general login analysis.
- B. Incorrect: CIS Benchmarks checks account configuration against numbered CIS recommendations on a schedule; it does not analyze login failure rates against baselines.
- C. Correct: the Threat Intelligence package looks at user types, authentication methods, login activity and abnormal failure rates, which is exactly the password-only and failed-login signal described.
- D. Incorrect: Security Essentials checks basics such as MFA enforcement, authentication and network policies, and event tables; it does not produce per-login detections.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.If the CIS Benchmarks package reports no violation for a control, the control is working.Why is that wrong?
For some benchmarks the Trust Center only checks that a measure exists, not that it achieves its objective. A clean result proves the control is present, not that it is effective.
Covered in Scanner packages, CIS Benchmarks and who can run them
2.Every scanner package's schedule can be changed, including Security Essentials.Why is that wrong?
Security Essentials runs on a fixed schedule. CIS Benchmarks, which runs daily by default, and the other packages can be rescheduled.
Covered in Scanner packages, CIS Benchmarks and who can run them
3.Detections can be triaged and resolved in the same way as violations.Why is that wrong?
A detection is a one-time event that can't be remediated directly, and its lifecycle can't currently be managed. Only violations have a resolve and reopen lifecycle.
Covered in Violations, detections, and weighing likelihood against impact
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“trust every answer with enterprise-grade governance: sensitive data protection, data quality, end-to-end lineage, AI guardrails, and AI governance.”
↩︎ Horizon Catalog: the governance baseline you assess against“Governance policies execute at the query engine layer, not the application layer.”
↩︎ Horizon Catalog: the governance baseline you assess against“Trust Center continuously monitors for misconfigured roles and unprotected columns.”
↩︎ Horizon Catalog: the governance baseline you assess against“Shared data products carry their tags and permissions.”
↩︎ Horizon Catalog: the governance baseline you assess against“There is no separate governance configuration for AI workloads.”
↩︎ Checkpoint - 2.
“You have an account-level network policy that allows access only from trusted IP addresses.”
↩︎ Scanner packages, CIS Benchmarks and who can run them“This scanner package runs once a day by default, but you can change the schedule.”
↩︎ Scanner packages, CIS Benchmarks and who can run them“You can also create a separate, administrator-level role to manage violations and scanners by using the Violations and Manage scanners tabs.”
↩︎ Scanner packages, CIS Benchmarks and who can run them“A graph of scanner violations over time, color-coded by low, medium, high, and critical severity.”
↩︎ Violations, detections, and weighing likelihood against impact“Scanners continue to report on violations unless you change the configuration to remediate the violations.”
↩︎ Violations, detections, and weighing likelihood against impact“Some client versions (for example, drivers) currently in use may have known vulnerabilities or have reached their end-of-life status.”
↩︎ Violations, detections, and weighing likelihood against impact“You can use the Trust Center to evaluate, monitor, and reduce potential security risks in your Snowflake accounts.”
↩︎ Key concept“the absence of a violation does not guarantee that the security measure is implemented in an effective manner”
↩︎ Exam trap 1“A detection occurs one time and represents a unique event.”
↩︎ Exam trap 3“Scanner packages are deactivated by default, except for the Security Essentials scanner package.”
↩︎ Prediction“If the detection is meaningful, you can take actions to prevent similar events in the future.”
↩︎ Checkpoint - 3.
“broken out by entity type such as User, Table, and Procedure.”
↩︎ Violations, detections, and weighing likelihood against impact“You can change the schedule for all scanner packages, except the Security Essentials scanner package.”
↩︎ Exam trap 2“Switch to a role with the SNOWFLAKE.TRUST_CENTER_ADMIN application role granted to it.”
↩︎ Checkpoint