What you will be able to do
- Catalog the critical assets in a Snowflake account, including sensitive data and privileged roles
- Document inbound entry points and the network policy controls that restrict them
- Document outbound exit points such as external access integrations and external stages
- Analyze data sharing configurations as a threat surface that the provider controls
Key concept
Violation versus detection — Snowflake reports threats in two forms. A violation is a misconfiguration that stays open until you change the configuration. A detection is a single event that already happened, so you investigate it instead of fixing it. A threat model needs both: the weak configurations an attacker could exploit, and evidence of the events that show someone tried.
1.Cataloging critical assets
A threat model starts with an inventory of what an attacker would want. In Snowflake that is mainly two things: sensitive data, and the identities that can reach it. The documentation states the requirement directly: you need to know where sensitive data is stored and whether it is protected. You don't have to build that inventory by hand. Sensitive data classification finds sensitive data automatically and makes it easy to apply tags and masking policies to it. Snowflake has built-in categories such as name and national identifier, and you can add custom categories for data specific to your organization. Classification is set up and reviewed in the Trust Center.
The resulting tags make the catalog usable by other controls. The Trust Center's AI Security package, for example, looks for columns tagged with system classification tags such as SNOWFLAKE.CORE.PRIVACY_CATEGORY or SNOWFLAKE.CORE.SEMANTIC_CATEGORY. It reports when agents read those columns while no masking or row access policy is in place. Untagged sensitive data is not covered by checks like this.
Privileged roles are critical assets too. ACCOUNTADMIN is the most powerful role in the system and the only one that configures account-level parameters. A compromised ACCOUNTADMIN user is therefore a high-impact threat in its own right. The Trust Center Overview tab summarizes posture: findings from current scanners, secure authentication readiness, data security, and at-risk entities over a selected period. Its scanners report two kinds of finding. Violations are persistent misconfigurations. Detections are one-time events. The rest of this lesson relies on that distinction.
Checkpoint 1 of 6· Check yourself
A security team needs an inventory of which tables hold personal data, so they can attach governance controls. Which Snowflake capability fits best?
Classification is built to find sensitive data and connect it to governance controls such as tags and masking policies. The other options deal with network access, grants, or sharing, not data discovery.
“Snowflake provides a solution that automatically discovers sensitive data and makes it easy to apply governance controls like tags and masking policies.”Source: docs.snowflake.com
2.Documenting entry points and network policies
With the assets cataloged, the next step is to list the ways in. The main inbound paths are connections to the Snowflake service and to the internal stage. Both are open by default: Snowflake accepts connections from any computer or device until a security administrator (or higher) restricts them with a network policy. Each undocumented entry point is effectively an open door.
A network policy does not list IP addresses itself. It refers to network rules, which group related identifiers, and puts them on an allowed list or a blocked list. New policies should use network rules rather than the older ALLOWED_IP_LIST and BLOCKED_IP_LIST parameters. When an identifier appears on both lists, the blocked list wins. Private connectivity rules (types AWSVPCEID and AZURELINKID) take precedence over IPV4 and IPV6 rules when a request arrives over private connectivity.
An allowed list blocks everything else of the same identifier type. You don't need to add the rest to a blocked list. A rule based on a private endpoint has no effect on requests from the public internet, though. If you want to allow only a VPC endpoint, you also need to block public IPv4 explicitly, as in this example:
CREATE NETWORK RULE block_public_access
MODE = INGRESS
TYPE = IPV4
VALUE_LIST = ('0.0.0.0/0');
CREATE NETWORK RULE allow_vpceid_access
MODE = INGRESS
TYPE = AWSVPCEID
VALUE_LIST = ('vpce-0fa383eb170331202');
CREATE NETWORK POLICY allow_vpceid_block_public_policy
ALLOWED_NETWORK_RULE_LIST = ('allow_vpceid_access')
BLOCKED_NETWORK_RULE_LIST=('block_public_access');| Activated on | Overrides | Overridden by |
|---|---|---|
| Account | Nothing (most general) | User or security integration policies |
| User | Account policies | Security integration policies |
| Security integration | Account and user policies | Nothing (most specific) |
Checkpoint 2 of 6· Put it in order
Put the steps for controlling inbound traffic with a network policy in order
- 1.Create a network policy that includes the rules in its allowed or blocked list
- 2.Activate the network policy for an account, user, or security integration
- 3.Create network rules based on their purpose and type of network identifier
Rules group the identifiers, policies reference the rules, and nothing is restricted until the policy is activated.
“Create network rules based on their purpose and type of network identifier.”Source: docs.snowflake.com
Checkpoint 3 of 6· Fill the gap
This rule is meant to restrict inbound connections to an IP range. Which MODE completes it?
CREATE NETWORK RULE allow_access_rule
MODE = ?
TYPE = IPV4
VALUE_LIST = ('192.168.1.0/24');Network policies control inbound access, so their rules use MODE = INGRESS. EGRESS is for outbound rules used by external access integrations.
Source: docs.snowflake.comSources3
3.Documenting exit points: egress and unloads
Network policies only control inbound traffic. For outbound traffic, the documentation points to external network access, so egress needs its own entry in the threat model. When a UDF or stored procedure has to reach an external endpoint, an administrator creates a network rule with MODE = EGRESS. The rule has a TYPE such as HOST_PORT or PRIVATE_HOST_PORT and lists the endpoint in VALUE_LIST. If no port is given, Snowflake uses 443. The administrator then includes the rule in an external access integration.
Each rule in the integration names one external location the code is allowed to reach. That makes the integration both the record of the exit point and the control on it. If the function is compromised, it can only reach the hosts the rules list.
Checkpoint 4 of 6· Exam question
A security team inherits an account with roughly 400 tables spread across 30 schemas and must catalog every column that holds personal data so it can be ranked as a critical asset. Nobody documented the data. Which approach builds this inventory with the least manual effort?
Correct answer: A — Attach a classification profile to the databases so `SYSTEM$CLASSIFY` runs automatically and tags detected columns with SEMANTIC_CATEGORY and PRIVACY_CATEGORY.
- A. Correct. Classification profiles automate sensitive-data detection and auto-apply the system tags, which can then be queried to build the critical-asset inventory without per-table work.
- B. Incorrect. The CIS Benchmarks scanner evaluates account configuration such as MFA and network policy settings; it does not inspect column contents or classify data.
- C. Incorrect. Name matching misses columns with unconventional names and flags harmless ones; it inspects no values, so it is not reliable classification.
- D. Incorrect. Access history records which columns were read, not what they contain, so frequently queried non-sensitive columns would be wrongly cataloged as critical.
Stages are another way data leaves the account. The Trust Center can raise a detection when a large amount of data is transferred to an external stage. Its Sensitive parameter protection scanner reports when PREVENT_UNLOAD_TO_INLINE_URL, REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_CREATION, or REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_OPERATION is changed from TRUE to FALSE. All three are TRUE by default for the best security posture, so switching one off widens an exit path.
Checkpoint 5 of 6· Check yourself
A Python UDF must call one partner API. What do you configure so that this exit point is both recorded and limited?
Outbound access from functions and procedures is defined by egress network rules in an external access integration. Network policies only govern inbound traffic.
“Each rule included in the integration specifies an external network location that the function or procedure is allowed to access.”Source: docs.snowflake.com
4.Threat-modeling data sharing configurations
Shares make data available outside the account boundary without any data movement. With Secure Data Sharing, nothing is copied or transferred between accounts. The provider creates a share, grants privileges on objects to it (either directly or through a database role), and adds consumer accounts. Shared objects are read-only for consumers.
That design affects the threat model in both directions. The risk is that grants propagate automatically: a new object added to a share, or a change to an existing one, is immediately visible to every consumer. A table granted to the wrong share is exposed straight away. The advantage is that the provider stays in control and can revoke access to a share or any object in it at any time. Reader accounts let you share with organizations that are not Snowflake customers. Each reader account belongs to the provider that created it and can consume data only from that provider. One gap to record: the Trust Center does not support reader accounts.
| Sharing option | What is offered |
|---|---|
| Listing | A share plus additional metadata as a data product to one or more accounts |
| Direct Share | Specific database objects shared directly to another account in your region |
| Data Exchange | A share offered to a group of accounts you set up and manage |
| Clean room | Shared data with control over which queries can run against it |
Checkpoint 6 of 6· Check yourself
A provider grants a new table containing customer emails to a share that already has five consumer accounts. When can those consumers query the table?
Objects added to a share become available to all consumers immediately. This is why share grants need review before they are made.
“New objects added to a share become immediately available to all consumers, providing real-time access to imported data.”Source: docs.snowflake.com
Sources6
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.A network policy on a user always overrides every other network policy.Why is that wrong?
A user-level policy overrides the account-level policy, but a policy on a security integration overrides the user-level one.
2.Once data is shared, consumers hold a copy, so revoking the share cannot contain an exposure.Why is that wrong?
Secure Data Sharing copies no data, and the provider can revoke access to a share or any object in it at any time.
Covered in Threat-modeling data sharing configurations
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“It’s critical to know where your sensitive data resides and if it’s adequately protected.”
↩︎ Cataloging critical assets“Snowflake provides a solution that automatically discovers sensitive data and makes it easy to apply governance controls like tags and masking policies.”
↩︎ Checkpoint - 2.
“The account administrator (users with the ACCOUNTADMIN system role) is the most powerful role in the system.”
↩︎ Cataloging critical assets - 3.
“By default, Snowflake allows users to connect to the service and internal stage from any computer or device.”
↩︎ Documenting entry points and network policies“you do not have to use the blocked list to explicitly block other identifiers of the same type; only the allowed identifiers have access.”
↩︎ Documenting entry points and network policies“are overridden by a network policy applied to a security integration.”
↩︎ Exam trap 1“A network policy doesn’t restrict network traffic until it is activated.”
↩︎ Prediction“Create network rules based on their purpose and type of network identifier.”
↩︎ Checkpoint - 4.https://docs.snowflake.com/en/developer-guide/external-network-access/creating-using-external-network-accessOfficial docs
“To support access to an external network, an administrator will include the rule when creating an external access integration.”
↩︎ Documenting exit points: egress and unloads“Each rule included in the integration specifies an external network location that the function or procedure is allowed to access.”
↩︎ Checkpoint - 5.
“A large amount of data was transferred to an external stage.”
↩︎ Documenting exit points: egress and unloads“A violation persists over time and represents a configuration that doesn’t conform with a scanner’s requirements.”
↩︎ Key concept - 6.
“With Secure Data Sharing, no actual data is copied or transferred between accounts.”
↩︎ Threat-modeling data sharing configurations“a reader account can only consume data from the provider account that created it.”
↩︎ Threat-modeling data sharing configurations“Access to a share (or any of the objects in a share) can be revoked at any time.”
↩︎ Exam trap 2“New objects added to a share become immediately available to all consumers, providing real-time access to imported data.”
↩︎ Checkpoint