CertSafari

    Free Snowflake SnowPro Advanced: Security Engineer (SEA-C01) Sample Questions

    35 free sample questions from our bank of 360+, covering every exam domain, with answers and detailed explanations. Updated October 2026.

    Domain 1: Account and Security

    Subdomain 1.1: Design and implement access control strategies.

    1.A user holds primary role ANALYST and has secondary roles activated with USE SECONDARY ROLES ALL, including ENGINEER which has CREATE TABLE on schema dev.work. The user runs CREATE TABLE dev.work.t (id INT) while ANALYST lacks that privilege. Which TWO statements describe the result?(Select 2)

    1. A.Secondary roles supply privileges only for SELECT statements, so DML statements such as INSERT also ignore the privileges of ENGINEER in this session.
    2. B.The statement succeeds and the table is owned by ENGINEER, because Snowflake uses the secondary role that carries the missing privilege.
    3. C.The statement succeeds and ownership is shared by ANALYST and ENGINEER, since both roles are active in the session at the same time.
    4. D.If the primary role were ENGINEER with CREATE TABLE, the new table would be owned by ENGINEER, since ownership goes to the primary role.
    5. E.The CREATE TABLE statement fails because object creation is authorized using only the primary role and not any activated secondary role.
    Show answer & explanation

    Correct answers: D, E — If the primary role were ENGINEER with CREATE TABLE, the new table would be owned by ENGINEER, since ownership goes to the primary role.; The CREATE TABLE statement fails because object creation is authorized using only the primary role and not any activated secondary role.

    • A. Secondary roles contribute privileges for SELECT, DML and other non-CREATE operations. The restriction is specific to creating objects.
    • B. Secondary roles do not authorize CREATE and never receive ownership. The statement fails with an insufficient privileges error.
    • C. Every object has exactly one owner role. Ownership is never shared among active roles.
    • D. A created object is owned by the primary role that executed the CREATE. Secondary roles never take ownership.
    • E. CREATE statements are evaluated against the primary role only. Privileges from secondary roles do not authorize object creation.

    Subdomain 1.1: Design and implement access control strategies.

    2.An operations team wants to delegate privilege administration for one business unit. They create role BU_GRANT_ADMIN and plan to grant it MANAGE GRANTS ON ACCOUNT. Which TWO statements about that privilege are accurate?(Select 2)

    1. A.SECURITYADMIN holds MANAGE GRANTS by default, so any role granted to SECURITYADMIN also inherits the ability to modify grants across the account.
    2. B.A role holding MANAGE GRANTS can grant or revoke privileges on any object in the account, regardless of who owns it, so it should be granted sparingly.
    3. C.MANAGE GRANTS also transfers object ownership automatically, so the holder becomes the owner of any object it grants privileges on.
    4. D.MANAGE GRANTS is scoped to the database where the role is defined, so BU_GRANT_ADMIN could never affect grants in other databases of the account.
    5. E.A role with MANAGE GRANTS can create users and roles without USERADMIN, because the privilege includes CREATE USER and CREATE ROLE implicitly.
    Show answer & explanation

    Correct answers: A, B — SECURITYADMIN holds MANAGE GRANTS by default, so any role granted to SECURITYADMIN also inherits the ability to modify grants across the account.; A role holding MANAGE GRANTS can grant or revoke privileges on any object in the account, regardless of who owns it, so it should be granted sparingly.

    • A. SECURITYADMIN is the system role that holds MANAGE GRANTS by default. Roles that inherit from it through the hierarchy gain the same capability.
    • B. MANAGE GRANTS lets a role grant or revoke privileges globally, as if it were the object owner. Because of this reach, it undermines scoped delegation.
    • C. Granting privileges does not change object ownership. Ownership only moves through GRANT OWNERSHIP.
    • D. MANAGE GRANTS is an account-level privilege granted ON ACCOUNT. It is not restricted to one database.
    • E. Creating users and roles needs the CREATE USER and CREATE ROLE privileges, which USERADMIN holds. MANAGE GRANTS does not include them.

    Subdomain 1.3: Implement network security controls.

    3.Which statement about evaluation order between rule types inside a network policy is accurate?

    1. A.IPV4 and IPV6 rules take precedence over private connectivity rules, so an allowed address range overrides an endpoint ID mismatch.
    2. B.Rules are evaluated in the order they were created, so the oldest rule that matches decides the outcome for the connection.
    3. C.Private connectivity rules of type `AWSVPCEID` or `AZURELINKID` take precedence over IPV4 and IPV6 rules when a connection arrives.
    4. D.All rule types are merged into one list and evaluated together, so no type of rule can take precedence over another type.
    Show answer & explanation

    Correct answer: C — Private connectivity rules of type `AWSVPCEID` or `AZURELINKID` take precedence over IPV4 and IPV6 rules when a connection arrives.

    • A. Incorrect: the precedence runs the other way.
    • B. Incorrect: creation order plays no role in the evaluation.
    • C. Correct: Snowflake documents that private connectivity rules take precedence over IP-based rules.
    • D. Incorrect: the documented behavior gives private connectivity rules priority.

    Subdomain 1.4: Manage external access integrations.

    4.A Python UDF must call https://api.vendor.example:8443/v2/score. The network rule was created with VALUE_LIST = ('api.vendor.example') and every call fails with a blocked-endpoint error. What fixes this?

    1. A.Recreate the rule with TYPE = IPV4 and list the vendor's resolved addresses, because HOST_PORT rules cannot express a non-standard port.
    2. B.Change the rule's VALUE_LIST entry to 'api.vendor.example:8443', because a HOST_PORT value without an explicit port only allows port 443.
    3. C.Set ALLOWED_PORTS = (8443) on the external access integration, since the integration rather than the rule defines which ports may be used.
    4. D.Change the rule MODE to INGRESS so that traffic returning from port 8443 on the vendor host is accepted into the Snowflake account.
    Show answer & explanation

    Correct answer: B — Change the rule's VALUE_LIST entry to 'api.vendor.example:8443', because a HOST_PORT value without an explicit port only allows port 443.

    • A. Incorrect: HOST_PORT rules do support explicit ports, and IPv4 egress rules would break whenever the vendor's addresses change.
    • B. Correct: HOST_PORT egress values default to port 443 when no port is given, so the non-standard port must be written into the value, such as 'api.vendor.example:8443'.
    • C. Incorrect: external access integrations have no ALLOWED_PORTS parameter; the host and port allowlist lives entirely in the referenced network rules.
    • D. Incorrect: INGRESS rules govern inbound connections to Snowflake and are not valid for outbound calls from handler code; response traffic needs no rule.

    Subdomain 1.4: Manage external access integrations.

    5.Marketing calls an enrichment vendor with an API key and Finance calls a bank API with OAuth. Which two design choices follow least-privilege practice?(Select 2)

    1. A.Build one shared integration listing both rules and both secrets, then grant USAGE on it to PUBLIC to simplify onboarding for teams
    2. B.Place both vendors and a wildcard domain in a single rule so new vendor hostnames never need a rule change later on
    3. C.Create a separate rule, secret and integration per vendor, granting USAGE on each only to the team role owning that use case
    4. D.Store both credentials in one GENERIC_STRING secret as JSON and share it with every function owner in either team
    5. E.List exact host:port pairs in each rule's VALUE_LIST instead of broad domains, so only approved endpoints are reachable
    Show answer & explanation

    Correct answers: C, E — Create a separate rule, secret and integration per vendor, granting USAGE on each only to the team role owning that use case; List exact host:port pairs in each rule's VALUE_LIST instead of broad domains, so only approved endpoints are reachable

    • A. Incorrect: a shared integration granted to PUBLIC lets any function reach both vendors with both credentials.
    • B. Incorrect: a combined rule with wildcard-style breadth defeats the allowlist and exceeds what was approved.
    • C. Correct: separate objects per vendor let each team's access be granted, audited and revoked independently.
    • D. Incorrect: a combined JSON secret exposes both credentials to every function that binds it.
    • E. Correct: exact host and port entries keep the allowlist minimal and tied to the vendor assessment.

    Subdomain 1.2: Configure and monitor user authentication and session management.

    6.An auditor asks for a single account-wide inventory of all programmatic access tokens, including their expiry dates, without querying each user individually. Which source should the security engineer use?

    1. A.SNOWFLAKE.ACCOUNT_USAGE.LOGIN_HISTORY filtered by FIRST_AUTHENTICATION_FACTOR, which returns every issued token and when each one expires.
    2. B.INFORMATION_SCHEMA.POLICY_REFERENCES for the authentication policy, which returns each token's name, owner and configured expiry date.
    3. C.SNOWFLAKE.ACCOUNT_USAGE.SESSIONS filtered by AUTHENTICATION_METHOD, which lists every token issued and the session each one opened.
    4. D.SNOWFLAKE.ACCOUNT_USAGE.CREDENTIALS filtered to rows whose type is PAT, which lists tokens across all users in the account.
    Show answer & explanation

    Correct answer: D — SNOWFLAKE.ACCOUNT_USAGE.CREDENTIALS filtered to rows whose type is PAT, which lists tokens across all users in the account.

    • A. Incorrect: LOGIN_HISTORY records login events, not an inventory of issued tokens or their expiry dates.
    • B. Incorrect: POLICY_REFERENCES shows where a policy is applied, not individual credential objects.
    • C. Incorrect: SESSIONS records sessions that were opened, so tokens that were never used would be missing and expiry is not stored.
    • D. Correct: the ACCOUNT_USAGE CREDENTIALS view exposes token inventory; SHOW USER PROGRAMMATIC ACCESS TOKENS is the per-user alternative.

    Subdomain 1.2: Configure and monitor user authentication and session management.

    7.When configuring a SAML2 security integration in Snowflake, which statement about the service-provider side is correct?

    1. A.The IdP posts SAML responses to the assertion consumer service URL, formed from the account URL with /fed/login appended.
    2. B.The IdP posts SAML responses to the Snowsight address, which Snowflake reads from SAML2_SP_INITIATED_LOGIN_PAGE_LABEL for each login.
    3. C.The IdP posts SAML responses to the account URL with /oauth/token-request appended, which Snowflake lists in its generated SP metadata.
    4. D.The IdP posts SAML responses to a regional Snowflake endpoint shared by all accounts, and Snowflake routes by SAML2_ISSUER value.
    Show answer & explanation

    Correct answer: A — The IdP posts SAML responses to the assertion consumer service URL, formed from the account URL with /fed/login appended.

    • A. Correct: the ACS URL is the account URL plus /fed/login, and DESCRIBE SECURITY INTEGRATION returns SP metadata including it.
    • B. Incorrect: the login page label is only display text on the Snowflake login page.
    • C. Incorrect: the token-request path belongs to Snowflake OAuth, not SAML.
    • D. Incorrect: the ACS URL is account-specific; SAML2_ISSUER identifies the IdP, not a routing key.

    Domain 2: Data Protection, Data Privacy, and Data Governance

    Subdomain 2.1: Implement data security features.

    8.Support agents should see the full `email` value only when the row's `region` column equals 'EU'; everyone else must see a masked value. A masking policy `mask_email(val STRING, region STRING)` already exists. Which statement attaches it correctly?

    1. A.ALTER TABLE customers MODIFY COLUMN email SET MASKING POLICY mask_email USING (email, region);
    2. B.ALTER TABLE customers MODIFY COLUMN email SET MASKING POLICY mask_email WITH CONDITION (region = 'EU');
    3. C.ALTER TABLE customers ADD MASKING POLICY mask_email ON (email, region);
    4. D.ALTER TABLE customers MODIFY COLUMN email SET MASKING POLICY mask_email, region SET MASKING POLICY mask_email;
    Show answer & explanation

    Correct answer: A — ALTER TABLE customers MODIFY COLUMN email SET MASKING POLICY mask_email USING (email, region);

    • A. Correct: conditional masking passes the protected column first and the additional columns after it in the USING clause, matching the policy signature.
    • B. Masking policies have no WITH CONDITION clause. The condition belongs inside the policy body, and extra columns are passed with USING.
    • C. The ADD ... ON (...) form is the syntax for row access policies. Masking policies are set on a column with SET MASKING POLICY.
    • D. A column can carry only one masking policy and the policy takes both columns as arguments. Attaching it separately to region would protect the wrong column and mismatch the signature.

    Subdomain 2.1: Implement data security features.

    9.Account data is tokenized by a third-party provider before it is loaded, and only analysts in the `PII_REVEAL` role may see detokenized `ssn` values at query time. Which design uses External Tokenization?

    1. A.Create a masking policy calling an external function through an API integration when `IS_ROLE_IN_SESSION('PII_REVEAL')`, else returning the stored token.
    2. B.Create a masking policy that decrypts with a Java UDF holding the provider's key, stored in a Snowflake secret that analysts can read.
    3. C.Create a storage integration to the provider's bucket and expose an external table so detokenized values are read from cloud storage.
    4. D.Create an External OAuth security integration with the provider so detokenized values are returned inside each analyst's session token.
    Show answer & explanation

    Correct answer: A — Create a masking policy calling an external function through an API integration when `IS_ROLE_IN_SESSION('PII_REVEAL')`, else returning the stored token.

    • A. Correct: External Tokenization pairs a masking policy with an external function, reached through an API integration, so detokenization happens at query time for authorized roles only.
    • B. Handling the provider's key inside Snowflake defeats the purpose, since the key and detokenization logic should stay with the external provider.
    • C. Storage integrations and external tables give access to files, not column-level detokenization, and external tables cannot be used this way.
    • D. External OAuth authenticates users to Snowflake. It has no role in detokenizing column values.

    Subdomain 2.2: Manage and audit Secure Data Sharing and collaborations.

    10.Which TWO statements about the privacy characteristics of `GENERATE_SYNTHETIC_DATA` are accurate?(Select 2)

    1. A.Setting `similarity_filter` to true drops output rows that are too similar to rows in the input data set
    2. B.Each output row carries a hidden lineage pointer to its source row, which auditors can resolve through `ACCESS_HISTORY`
    3. C.String columns whose unique values exceed half of the row count are redacted in the generated output rather than modeled
    4. D.The procedure adds calibrated noise with a configurable epsilon budget, giving a formal differential privacy guarantee
    5. E.The feature runs on Standard Edition accounts once the Anaconda terms have been accepted by the account administrator
    Show answer & explanation

    Correct answers: A, C — Setting `similarity_filter` to true drops output rows that are too similar to rows in the input data set; String columns whose unique values exceed half of the row count are redacted in the generated output rather than modeled

    • A. The optional similarity filter is a privacy control that removes generated rows resembling source rows too closely.
    • B. The output has no direct reference or link to any original row; it only reproduces statistical properties.
    • C. High-cardinality string columns, such as free-text identifiers, are redacted because modeling them would risk reproducing source values.
    • D. Synthetic data generation does not expose an epsilon budget; differential privacy noise is a separate feature, for example in clean rooms.
    • E. Synthetic data generation requires Enterprise Edition or higher in addition to accepting the Anaconda terms.

    Subdomain 2.4: Establish and manage data retention and data lifecycle management.

    11.A security architect proposes enabling 30-day Time Travel on a critical permanent table by running `ALTER TABLE vault.pii.customers SET DATA_RETENTION_TIME_IN_DAYS = 30`. The account runs Standard Edition. What is the outcome of this statement?

    1. A.The statement succeeds, and the extra 29 days are billed as additional Fail-safe storage that Snowflake Support can restore on request.
    2. B.The statement succeeds only if the role holds the `MANAGE GRANTS` privilege, because retention beyond 7 days is treated as a governance-level change.
    3. C.The statement is rejected because Standard Edition caps Time Travel for permanent objects at 1 day, so 30 days needs Enterprise Edition or higher.
    4. D.The statement succeeds but is silently capped at 1 day, and the table keeps reporting a retention value of 30 days in `SHOW TABLES`.
    Show answer & explanation

    Correct answer: C — The statement is rejected because Standard Edition caps Time Travel for permanent objects at 1 day, so 30 days needs Enterprise Edition or higher.

    • A. Fail-safe is fixed at 7 days and is not extended by Time Travel settings. Time Travel itself is limited on this edition, so this is not what happens.
    • B. No special privilege unlocks a longer period. The ceiling is determined by the account edition, not by the role that runs the statement.
    • C. Standard Edition supports a maximum of 1 day of Time Travel, and values up to 90 days require Enterprise Edition or higher. A value of 30 is therefore rejected.
    • D. Snowflake does not silently cap the value. An out-of-range value for the edition raises an error instead of being accepted.

    Subdomain 2.5: Configure object tagging and data classification frameworks.

    12.An auditor applied the tag `governance.tags.pii_level` at schema level on `SALES.CUSTOMERS` and asks for a list of every table and column that carries the tag, inherited ones included, across the whole account. A query against `SNOWFLAKE.ACCOUNT_USAGE.TAG_REFERENCES` returns only the schema row. Which approach produces the complete list?

    1. A.Run `SHOW TAGS IN SCHEMA SALES.CUSTOMERS` and read the object count column, since each tag listing records every downstream object that inherits the value.
    2. B.Add a `WHERE DOMAIN = 'COLUMN'` filter to the existing `TAG_REFERENCES` query so the view expands inherited assignments down to each column of every table.
    3. C.Call the `TAG_REFERENCES_WITH_LINEAGE` table function with the fully qualified tag name, which also returns objects that inherited the tag.
    4. D.Query `SNOWFLAKE.ACCOUNT_USAGE.OBJECT_DEPENDENCIES` for the schema and join the result to `TAG_REFERENCES` to rebuild the inherited tag assignments manually.
    Show answer & explanation

    Correct answer: C — Call the `TAG_REFERENCES_WITH_LINEAGE` table function with the fully qualified tag name, which also returns objects that inherited the tag.

    • A. Incorrect. SHOW TAGS lists tag definitions and does not report the objects that carry or inherit a tag value.
    • B. Incorrect. The ACCOUNT_USAGE view records direct assignments only, so filtering on the column domain still excludes columns that merely inherit the schema's tag.
    • C. Correct. The TAG_REFERENCES_WITH_LINEAGE function takes a tag name and returns every object that has the tag, including objects that only inherit it from a parent.
    • D. Incorrect. OBJECT_DEPENDENCIES describes view and reference dependencies, not the securable hierarchy, so it cannot reconstruct which columns inherit a schema-level tag.

    Subdomain 2.6: Configure and maintain data replication policies and procedures.

    13.A failover group replicates SAML2 and SCIM security integrations. Which TWO steps help ensure SSO and provisioning work seamlessly after failover to the secondary account?(Select 2)

    1. A.Test a login and a SCIM provisioning call against the secondary account in advance of any real incident.
    2. B.Disable the SAML2 integration on the primary before refresh so that the secondary copy becomes the only active one.
    3. C.Confirm the integrations appear in the target and the IdP is configured for the target account's endpoints.
    4. D.Grant REPLICATE on each security integration to the IdP service account so that it can synchronise definitions itself.
    5. E.Recreate each security integration manually in the target with CREATE SECURITY INTEGRATION so that it matches the source.
    Show answer & explanation

    Correct answers: A, C — Test a login and a SCIM provisioning call against the secondary account in advance of any real incident.; Confirm the integrations appear in the target and the IdP is configured for the target account's endpoints.

    • A. Correct: exercising authentication and provisioning in advance exposes IdP and endpoint mismatches early.
    • B. Incorrect: this disrupts primary logins and is not a requirement for replicated integrations.
    • C. Correct: the integration objects must exist in the target and the IdP must be able to reach and trust the target account.
    • D. Incorrect: REPLICATE is a group privilege and an IdP does not replicate integrations.
    • E. Incorrect: replicated integrations are managed by the group, and manual recreation causes conflicts.

    Subdomain 2.3: Restrict data exfiltration.

    14.Enforcement on stage creation is now active, but a nightly task still unloads with `COPY INTO @legacy_ext_stage`, a stage created years ago with embedded `CREDENTIALS`. Security wants those unloads to fail until the stage is moved onto a storage integration. Which setting provides this?

    1. A.Set `REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_OPERATION = TRUE` at account level so load and unload on stages lacking an integration fail
    2. B.Re-run `ALTER ACCOUNT SET REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_CREATION = TRUE`, which retroactively invalidates stages created with embedded keys
    3. C.Set `PREVENT_UNLOAD_TO_INLINE_URL = TRUE` at account level, since a stage that stores credentials behaves like an inline URL at run time
    4. D.Set `PREVENT_UNLOAD_TO_INTERNAL_STAGES = TRUE` for the task owner's user so that unloads to any stage lacking an integration are rejected
    Show answer & explanation

    Correct answer: A — Set `REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_OPERATION = TRUE` at account level so load and unload on stages lacking an integration fail

    • A. Correct. This parameter is checked when the stage is used, so pre-existing stages with embedded keys stop working for load and unload until they reference a storage integration.
    • B. The creation parameter only evaluates new CREATE STAGE statements. It never revisits stages that already exist, so the legacy stage keeps working.
    • C. A named stage is not an inline URL. The unload references the stage by name, so this parameter does not apply to the task.
    • D. This parameter concerns internal stages only. The legacy stage is external, so the unload is not affected.

    Subdomain 2.3: Restrict data exfiltration.

    15.Which statements about `PREVENT_UNLOAD_TO_INTERNAL_STAGES` are correct?(Select 3)

    1. A.It can be set on an individual user with `ALTER USER`, so that different users in the same account can be restricted differently
    2. B.It blocks `GET` downloads of files that already sit in internal stages, so staged exports can no longer be retrieved
    3. C.It blocks COPY INTO <location> that targets any internal stage, including user stages, table stages and named stages
    4. D.It blocks `PUT` uploads from client machines into internal stages, which would also prevent any file-based data loading
    5. E.It does not restrict unloads to external stages or inline URLs, which are covered by their own separate parameters
    6. F.It is evaluated only for sessions that use the ACCOUNTADMIN role, so every other role is left entirely unaffected by the setting in the account
    Show answer & explanation

    Correct answers: A, C, E — It can be set on an individual user with `ALTER USER`, so that different users in the same account can be restricted differently; It blocks COPY INTO <location> that targets any internal stage, including user stages, table stages and named stages; It does not restrict unloads to external stages or inline URLs, which are covered by their own separate parameters

    • A. Correct. It is a user-level parameter that can also be set for the account.
    • B. It only affects unloading with COPY INTO <location>. Files that already exist can still be retrieved.
    • C. Correct. The restriction covers unloads to every kind of internal stage.
    • D. PUT uploads are not unloads, so loading files into internal stages is unaffected.
    • E. Correct. External destinations are controlled separately by the inline URL and storage integration parameters.
    • F. It applies to users regardless of the active role.

    Subdomain 2.7: Manage secure replication and failover operations.

    16.A failover group replicates databases, roles, users, network policies, and integrations. After promotion, which TWO items still need manual work by the security team? Select all that apply.(Select 2)

    1. A.Cloud-side trust for each replicated storage integration, using the identifiers generated in the new primary account.
    2. B.Access from external functions to remote services through each replicated API integration, which requires setup on the cloud side.
    3. C.Re-creating each network policy on the new primary, because policy allowed IP lists are never part of replicated object types.
    4. D.Rebuilding the role hierarchy, because grants between roles replicate only when the roles are owned by ACCOUNTADMIN.
    5. E.Recreating each user's default role and default warehouse, because user properties are excluded from user replication.
    Show answer & explanation

    Correct answers: A, B — Cloud-side trust for each replicated storage integration, using the identifiers generated in the new primary account.; Access from external functions to remote services through each replicated API integration, which requires setup on the cloud side.

    • A. Correct. Replicated storage integrations need a new trust relationship with the cloud storage for the target account.
    • B. Correct. API integrations replicate, but external function access to remote services must be configured again outside Snowflake.
    • C. Incorrect. Network policies are a supported object type and replicate with their allowed and blocked lists, so no re-creation is needed.
    • D. Incorrect. Role hierarchies replicate with the roles in the group regardless of which role owns them.
    • E. Incorrect. User properties such as default role and warehouse are part of what user replication carries.

    Subdomain 2.7: Manage secure replication and failover operations.

    17.A team promotes a secondary and must confirm that the replicated network policy restricting logins to corporate IP ranges is actually enforced on the new primary. Which validation is most convincing?

    1. A.On the new primary, run SHOW PARAMETERS LIKE 'NETWORK_POLICY' IN ACCOUNT, describe the named policy, and try a login from an IP outside its allowed list.
    2. B.On the old primary, run SHOW NETWORK POLICIES and confirm the policy still exists there, since the copy on the new primary is identical by design.
    3. C.Run SHOW FAILOVER GROUPS on the new primary and confirm the group status column reads PRIMARY, which proves that all policies are enforced.
    4. D.Unset and set the account NETWORK_POLICY parameter on the new primary using the policy name, assuming activation does not carry over from the old primary.
    Show answer & explanation

    Correct answer: A — On the new primary, run SHOW PARAMETERS LIKE 'NETWORK_POLICY' IN ACCOUNT, describe the named policy, and try a login from an IP outside its allowed list.

    • A. Correct. Checking the account parameter, the policy contents, and a negative login test together proves the policy exists, is active, and is enforced on the new primary.
    • B. Incorrect. The old primary is a different account, and the existence of a policy there says nothing about enforcement on the new primary.
    • C. Incorrect. Promotion status shows which account is primary, not whether any particular network policy is active.
    • D. Incorrect. Re-applying the parameter blindly changes the live security configuration without first verifying what was replicated, and is not validation.

    Domain 3: Auditing, Monitoring, and Compliance

    Subdomain 3.2: Implement a strategic security architecture to balance data protection and credit efficiency.

    18.A team is deciding which Trust Center scanner packages to enable for cost and coverage. Which statements are accurate? (Select TWO.)(Select 2)

    1. A.Every Trust Center scanner package, including Security Essentials, bills serverless credits on each scheduled run, so disabling all of them is the only savings.
    2. B.Trust Center scanners run on the account's default warehouse, so their cost is controlled by that warehouse's resource monitor and auto-suspend setting.
    3. C.Optional packages such as CIS Benchmarks and Threat Intelligence incur serverless compute charges when they run, so enabling them is a cost decision.
    4. D.Scanner packages are free for Enterprise accounts and only incur charges on Business Critical accounts, where scanner findings are retained longer.
    5. E.The Security Essentials scanner package is enabled by default, cannot be deactivated, and runs on its fixed schedule without serverless compute charges.
    6. F.Disabling the CIS Benchmarks package deletes the account's existing findings and also prevents Security Essentials from raising its own findings.
    Show answer & explanation

    Correct answers: C, E — Optional packages such as CIS Benchmarks and Threat Intelligence incur serverless compute charges when they run, so enabling them is a cost decision.; The Security Essentials scanner package is enabled by default, cannot be deactivated, and runs on its fixed schedule without serverless compute charges.

    • A. Incorrect: Security Essentials runs without serverless compute charges, so the claim that every package bills is wrong.
    • B. Incorrect: scanners are serverless and do not run on the default warehouse, so warehouse resource monitors do not govern them.
    • C. Correct: other packages use serverless compute when they run, so each one trades extra coverage for credits.
    • D. Incorrect: charges depend on the package, not on the edition, and there is no Business Critical-only billing rule for scanners.
    • E. Correct: Security Essentials is on by default, cannot be turned off, and does not add serverless cost.
    • F. Incorrect: Security Essentials is independent of the optional packages, and disabling one does not stop another from raising findings.

    Subdomain 3.2: Implement a strategic security architecture to balance data protection and credit efficiency.

    19.Finance flags a sudden rise in AI-related credits, and the security team suspects a stolen user's credentials are driving heavy calls to Cortex LLM functions. Which view lets them attribute the credits to specific functions and models?

    1. A.SNOWFLAKE.ACCOUNT_USAGE.WAREHOUSE_LOAD_HISTORY, which records queued and running Cortex requests per warehouse, expressed as credits.
    2. B.SNOWFLAKE.ACCOUNT_USAGE.ACCESS_HISTORY, which lists the credits consumed by every column read when a query invokes an AI function.
    3. C.SNOWFLAKE.ACCOUNT_USAGE.CORTEX_FUNCTIONS_USAGE_HISTORY, which lists credits and tokens by function and model for each time interval.
    4. D.SNOWFLAKE.ACCOUNT_USAGE.LOGIN_HISTORY, which reports the credits billed for each authenticated session along with the client application used.
    Show answer & explanation

    Correct answer: C — SNOWFLAKE.ACCOUNT_USAGE.CORTEX_FUNCTIONS_USAGE_HISTORY, which lists credits and tokens by function and model for each time interval.

    • A. Incorrect: WAREHOUSE_LOAD_HISTORY tracks warehouse load, and Cortex LLM billing does not appear there.
    • B. Incorrect: ACCESS_HISTORY records which objects and columns were read, not the credits spent.
    • C. Correct: the Cortex functions usage history view reports credits and token counts per function and model, which is what attributes AI spend.
    • D. Incorrect: LOGIN_HISTORY records authentication events and has no credit columns.

    Subdomain 3.3: Design and manage data compliance policies.

    20.An organisation must retain six years of data-access evidence, but `ACCESS_HISTORY` in Account Usage keeps one year. Which design meets the requirement?

    1. A.Create a scheduled task that appends new `ACCESS_HISTORY` rows to a governed archive table well before they pass 365 days of age
    2. B.Raise retention of the `SNOWFLAKE` database to six years with `ALTER DATABASE SNOWFLAKE SET DATA_RETENTION_TIME_IN_DAYS = 2190`
    3. C.Ask the cloud provider to extend log retention for the account, because Account Usage views are backed by provider-level storage logs
    4. D.Query the `INFORMATION_SCHEMA` table functions six years later, since they hold the same history as the Account Usage views
    Show answer & explanation

    Correct answer: A — Create a scheduled task that appends new `ACCESS_HISTORY` rows to a governed archive table well before they pass 365 days of age

    • A. Correct. Account Usage retention cannot be extended, so copying rows into a customer-owned table on a schedule preserves evidence beyond the 365-day window.
    • B. Incorrect. The SNOWFLAKE database is a read-only shared database, and its retention is not configurable by customers.
    • C. Incorrect. Cloud providers do not hold Snowflake's Account Usage data in customer-visible logs that can be extended.
    • D. Incorrect. Information Schema table functions hold only a short window of recent history, not six years.

    Subdomain 3.3: Design and manage data compliance policies.

    21.A GDPR programme requires that personal data stay in EU regions. The account runs in Frankfurt and uses replication for disaster recovery and Cortex AI functions for text analysis. Which two measures keep processing inside the EU?(Select 2)

    1. A.Create accounts only in EU regions and list only those accounts in `ALLOWED_ACCOUNTS` of replication and failover groups
    2. B.Set the account parameter `CORTEX_ENABLED_CROSS_REGION` to `DISABLED` so that Cortex inference runs only in the home region
    3. C.Enable Tri-Secret Secure, since holding the customer-managed key in an EU key service confines all data copies to the EU
    4. D.Attach an account network policy that allows only EU IP ranges, which prevents Snowflake from storing data outside the EU
    5. E.Publish the data through a listing with auto-fulfilment to every region, then restrict consumers to EU-based users by role
    Show answer & explanation

    Correct answers: A, B — Create accounts only in EU regions and list only those accounts in `ALLOWED_ACCOUNTS` of replication and failover groups; Set the account parameter `CORTEX_ENABLED_CROSS_REGION` to `DISABLED` so that Cortex inference runs only in the home region

    • A. Correct. Replication targets are limited to the accounts named in the group, so restricting them to EU accounts keeps copies in the EU.
    • B. Correct. Cross-region inference can route prompts to another region, and disabling it keeps Cortex processing in the home region.
    • C. Incorrect. A customer-managed key controls access to encrypted data, not where Snowflake stores or processes it.
    • D. Incorrect. Network policies restrict client connections and say nothing about the location where data is stored.
    • E. Incorrect. Auto-fulfilment to every region copies the data across regions, and role restrictions do not reverse that.

    Subdomain 3.1: Monitor data security.

    22.Which statement best describes Snowflake Trail?

    1. A.It is a Trust Center scanner package that replays ACCESS_HISTORY to reconstruct the path an attacker took through the account.
    2. B.It replaces ACCOUNT_USAGE by streaming LOGIN_HISTORY and QUERY_HISTORY rows into a customer's SIEM in real time without latency.
    3. C.It is a partner program in which monitoring vendors install agents inside the virtual warehouse to capture telemetry from running queries.
    4. D.It is an observability capability that emits logs, metrics, and traces to an event table, with OpenTelemetry export to external tools.
    Show answer & explanation

    Correct answer: D — It is an observability capability that emits logs, metrics, and traces to an event table, with OpenTelemetry export to external tools.

    • A. Trust Center scanner packages are a separate feature, and none replays access history.
    • B. ACCOUNT_USAGE views still carry their ingestion latency, and Trail does not replace them.
    • C. Snowflake does not run third-party agents inside warehouses for Trail telemetry.
    • D. Trail builds on event tables and OpenTelemetry-compatible telemetry for Snowflake workloads.

    Subdomain 3.1: Monitor data security.

    23.A team needs an email when a user has more than five failed logins within the last scheduled interval, with no separate orchestration code. Which design is best?

    1. A.Write a stored procedure that raises an exception on repeated failures, because Snowflake emails the registered address of every user on any error.
    2. B.Create an alert that checks LOGIN_HISTORY for failures since its last run and calls SYSTEM$SEND_EMAIL through an email notification integration.
    3. C.Turn on the Trust Center notification setting for Security Essentials, which emails a count of failed logins at the chosen threshold.
    4. D.Create a resource monitor with a NOTIFY trigger on the SOC warehouse, since failed logins consume credits that the monitor will count.
    Show answer & explanation

    Correct answer: B — Create an alert that checks LOGIN_HISTORY for failures since its last run and calls SYSTEM$SEND_EMAIL through an email notification integration.

    • A. Exceptions in a procedure do not generate emails to users.
    • B. Alerts combine a schedule, a condition, and an action, which suits threshold-based notification.
    • C. Trust Center notifications are tied to findings and severity, with no per-user threshold on failed logins.
    • D. Resource monitors react to credit consumption and not to authentication events.

    Domain 4: Threats, Risk Assessment, Incident Response, and Forensics

    Subdomain 4.1: Perform threat modeling, identification, and analyses.

    24.Which ACCOUNT_USAGE view should an analyst query to list every table column that currently carries the `PRIVACY_CATEGORY` tag, together with the tag value, when ranking assets by sensitivity?

    1. A.`TAGS`, because the view returns each tag definition along with the objects and columns it has been assigned to
    2. B.`OBJECT_DEPENDENCIES`, because tagged columns are recorded as referenced objects of the tag that was applied to them
    3. C.`POLICY_REFERENCES`, because tag assignments are stored alongside masking and row access policy attachments in one place
    4. D.`TAG_REFERENCES`, because it lists each object or column with the tag name, tag value and the level at which it applies
    Show answer & explanation

    Correct answer: D — `TAG_REFERENCES`, because it lists each object or column with the tag name, tag value and the level at which it applies

    • A. Incorrect. The TAGS view lists tag definitions only (name, schema, allowed values); it does not record which objects carry them.
    • B. Incorrect. OBJECT_DEPENDENCIES tracks references such as a view depending on a table, not tag assignments on columns.
    • C. Incorrect. POLICY_REFERENCES lists masking, row access and similar policy attachments; tag assignments are not stored there.
    • D. Correct. TAG_REFERENCES maps every tagged object and column to the tag and its value, including inherited ones, which is what a criticality inventory needs.

    Subdomain 4.1: Perform threat modeling, identification, and analyses.

    25.A provider account shares data with several partners and a new auditor asks exactly which databases, schemas, tables and secure views the outbound share `PARTNER_SHARE` exposes today. Which statement answers this directly?

    1. A.`SHOW GRANTS OF SHARE PARTNER_SHARE`, which lists every database object currently granted to the share
    2. B.`SHOW SHARES LIKE 'PARTNER_SHARE'`, which returns the share together with the full set of objects it contains
    3. C.`SHOW GRANTS TO SHARE PARTNER_SHARE`, which lists the usage and select privileges granted on each shared object
    4. D.`SHOW MANAGED ACCOUNTS`, which lists reader accounts together with the objects each of them can currently query
    Show answer & explanation

    Correct answer: C — `SHOW GRANTS TO SHARE PARTNER_SHARE`, which lists the usage and select privileges granted on each shared object

    • A. Incorrect. The OF form lists the consumer accounts the share is granted to, not the objects inside it.
    • B. Incorrect. SHOW SHARES returns share metadata such as owner and consumer names but not the contained objects.
    • C. Correct. The TO form returns the privileges granted to the share on its databases, schemas, tables and secure views.
    • D. Incorrect. This lists provider-created reader accounts only; it does not describe which objects a share includes.

    Subdomain 4.2: Perform risk assessment and manage risk.

    26.A risk register lists many scanner findings. Which TWO factors should drive prioritization by likelihood and potential impact?(Select 2)

    1. A.The serverless credits the scanner consumed while running the checks that produced each individual finding
    2. B.Sensitivity of the data reachable through the affected roles, judged from classification tags and breadth of grants
    3. C.The order in which the scanner package happened to list its findings in the Trust Center interface
    4. D.The number of checks in the same scanner package that passed during the most recent scan of the account
    5. E.Evidence the weakness is exploitable now, such as password-only users, missing network policies or failed-login spikes
    Show answer & explanation

    Correct answers: B, E — Sensitivity of the data reachable through the affected roles, judged from classification tags and breadth of grants; Evidence the weakness is exploitable now, such as password-only users, missing network policies or failed-login spikes

    • A. Incorrect: scanner credit use does not reflect the likelihood or impact of a finding.
    • B. Correct: reachable sensitive data and grant breadth indicate potential impact.
    • C. Incorrect: display order is a UI artifact, not a risk measure.
    • D. Incorrect: passed checks say nothing about how likely or damaging the failed check is.
    • E. Correct: observable exploitability indicates likelihood and raises priority.

    Subdomain 4.3: Identify and manage security incidents.

    27.A login alert shows a service user authenticating successfully from an unfamiliar IP address after dozens of failures. You must determine what the session actually did before deciding on containment. Which investigation path links the login to the statements that were run?

    1. A.Query `GRANTS_TO_USERS` for the compromised user, since the grant timeline reveals every statement issued under each of its roles.
    2. B.Read `WAREHOUSE_METERING_HISTORY` for the login time window, since credit consumption identifies the individual statements the session executed.
    3. C.Take the login event ID from `LOGIN_HISTORY`, match `SESSIONS.LOGIN_EVENT_ID`, then join session IDs to `QUERY_HISTORY` to list the statements.
    4. D.Filter `ACCESS_HISTORY` by the attacker's IP address, since each row records the client IP together with the objects the query touched.
    Show answer & explanation

    Correct answer: C — Take the login event ID from `LOGIN_HISTORY`, match `SESSIONS.LOGIN_EVENT_ID`, then join session IDs to `QUERY_HISTORY` to list the statements.

    • A. Incorrect. GRANTS_TO_USERS shows which roles a user was granted and when. It says nothing about the statements executed under those roles.
    • B. Incorrect. Metering history aggregates credit use per warehouse per hour. It cannot attribute individual statements to a session or an IP.
    • C. Correct. SESSIONS carries LOGIN_EVENT_ID, which ties a session back to its login, and QUERY_HISTORY carries SESSION_ID, so the three views chain together to rebuild the attacker's activity.
    • D. Incorrect. ACCESS_HISTORY records the user, query ID and objects accessed, but not the client IP address. You would need the login and session chain to connect the IP to queries.

    Subdomain 4.3: Identify and manage security incidents.

    28.Which statement correctly describes how to cut off a single consumer account from an outbound data share while keeping the share and its grants available for later investigation?

    1. A.Run `DROP SHARE <share>`, which removes only the one consumer and retains the object grants so the share can be recreated from its recorded history.
    2. B.Run `ALTER SHARE <share> SET SECURE_OBJECTS_ONLY = TRUE`, which makes existing consumers lose access until they reaccept the share later.
    3. C.Run `REVOKE USAGE ON DATABASE <db> FROM SHARE <share>`, which removes only the named consumer's ability to read the shared database objects.
    4. D.Run `ALTER SHARE <share> REMOVE ACCOUNTS = <consumer_account>`, ending that consumer's access while the share and its object grants stay intact.
    Show answer & explanation

    Correct answer: D — Run `ALTER SHARE <share> REMOVE ACCOUNTS = <consumer_account>`, ending that consumer's access while the share and its object grants stay intact.

    • A. Incorrect. Dropping the share removes access for every consumer at once and deletes the share definition, which loses the configuration you wanted to inspect.
    • B. Incorrect. That setting only restricts which object types may be added to a share. It does not remove or suspend any consumer's existing access.
    • C. Incorrect. Revoking USAGE on the database from the share affects every consumer of that share, not one consumer account, and it alters the object grants you wanted to keep.
    • D. Correct. REMOVE ACCOUNTS detaches a specific consumer account from the share. The share object, its granted objects and the other consumers are left untouched, preserving evidence.

    Subdomain 4.4: Conduct a post-security-incident forensic analysis.

    29.An analyst starts a forensic review at 09:00 and filters SNOWFLAKE.ACCOUNT_USAGE.ACCESS_HISTORY for statements run between 08:30 and 08:50. The view returns no rows, although QUERY_HISTORY shows the statements ran. What is the most likely explanation and the right next step?

    1. A.ACCOUNT_USAGE views ingest with latency, and ACCESS_HISTORY can lag by roughly three hours, so re-run the filter later and use INFORMATION_SCHEMA query history functions meanwhile.
    2. B.ACCESS_HISTORY only records rows after an administrator runs ALTER ACCOUNT SET ENABLE_ACCESS_HISTORY = TRUE, so the account must enable logging and wait for future activity to appear.
    3. C.The analyst role is not ACCOUNTADMIN, so ACCOUNT_USAGE silently filters every row out, and the query must be re-run from ACCOUNTADMIN to see any access records for the window.
    4. D.Rows from the last 24 hours are withheld until the Fail-safe period begins, so the analyst must ask Snowflake Support to release the records for the window.
    Show answer & explanation

    Correct answer: A — ACCOUNT_USAGE views ingest with latency, and ACCESS_HISTORY can lag by roughly three hours, so re-run the filter later and use INFORMATION_SCHEMA query history functions meanwhile.

    • A. Correct. ACCOUNT_USAGE views are not real-time, and ACCESS_HISTORY has one of the longest delays (up to about 180 minutes). Re-querying later and using INFORMATION_SCHEMA functions for immediate visibility is the standard workaround.
    • B. Incorrect. No such parameter exists; access history is recorded automatically on Enterprise Edition or higher. An empty result for a recent window is a latency effect, not a missing setting.
    • C. Incorrect. Missing privileges on ACCOUNT_USAGE cause an authorization error rather than a silently empty result, and database roles or IMPORTED PRIVILEGES can grant access without ACCOUNTADMIN.
    • D. Incorrect. Fail-safe applies to table data after Time Travel, not to audit view rows, and Support is not involved in releasing ACCOUNT_USAGE records.

    Subdomain 4.4: Conduct a post-security-incident forensic analysis.

    30.ACCESS_HISTORY shows that a user read a table named CUSTOMER_STAGE_OLD. Afterward the table was renamed and then dropped, so a name lookup against ACCOUNT_USAGE.TABLES finds nothing current. How should the analyst identify the original table reliably?

    1. A.Match the objectName text with a LIKE pattern against the current TABLES view, since renamed tables keep the original name prefix in their stored metadata.
    2. B.Use the objectId from the ACCESS_HISTORY entry and match it to TABLE_ID in ACCOUNT_USAGE.TABLES, which keeps dropped tables with a DELETED value.
    3. C.Query the table with AT(OFFSET => -3600) to read its prior name from the stored data, since Time Travel keeps object names as part of every row.
    4. D.Search the POLICY_REFERENCES view for the old name, since masking and row access policy bindings record the original object name permanently for audit.
    Show answer & explanation

    Correct answer: B — Use the objectId from the ACCESS_HISTORY entry and match it to TABLE_ID in ACCOUNT_USAGE.TABLES, which keeps dropped tables with a DELETED value.

    • A. Incorrect. A rename replaces the name, and a dropped table no longer appears under current names, so string matching is unreliable and can mis-attribute rows.
    • B. Correct. Object IDs stay stable across renames, and ACCOUNT_USAGE.TABLES keeps dropped objects, so the join resolves the table's history, owner and drop time.
    • C. Incorrect. Time Travel returns table data, not object metadata, and it cannot be used on a dropped table until it is restored with UNDROP.
    • D. Incorrect. POLICY_REFERENCES shows current policy attachments and does not serve as a name-history ledger for renamed or dropped objects.

    Domain 5: Securing Snowflake Services and Features for AI/ML and Applications

    Subdomain 5.1: Secure and govern applications with Snowpark Container Services.

    31.A security engineer is drafting the VALUE_LIST for a network rule (MODE = EGRESS, TYPE = HOST_PORT) that will back an external access integration for a service. Which TWO entries are valid for Snowpark Container Services egress?(Select 2)

    1. A.'api.vendor.example.com:443' to allow HTTPS calls to exactly one fully named vendor host.
    2. B.'*.vendor.example.com:443' to cover every present and future subdomain with one wildcard entry.
    3. C.'db.vendor.example.com:5432' to allow outbound connections to a PostgreSQL server on a high port.
    4. D.'smtp.vendor.example.com:25' to let the service submit mail over the traditional SMTP port.
    5. E.'10.0.0.0/8' in a TYPE = IPV4 rule to allow containers to reach the whole private address range.
    Show answer & explanation

    Correct answers: A, C — 'api.vendor.example.com:443' to allow HTTPS calls to exactly one fully named vendor host.; 'db.vendor.example.com:5432' to allow outbound connections to a PostgreSQL server on a high port.

    • A. Correct: a fully qualified hostname with an allowed port is the standard HOST_PORT form, and port 443 is permitted for egress.
    • B. Incorrect: wildcards are not supported in SPCS egress host lists, so every hostname must be written out in full.
    • C. Correct: egress permits ports 22, 80, 443 and anything from 1024 upward, so a database on port 5432 can be allowed by hostname.
    • D. Incorrect: port 25 is outside the permitted set of 22, 80, 443 and 1024 and above, so this entry cannot be used for container egress.
    • E. Incorrect: SPCS egress relies on HOST_PORT rules naming hostnames and ports; a CIDR-style IPV4 rule is not how container egress is granted.

    Subdomain 5.2: Leverage Snowflake Cortex AI to enhance data security.

    32.A compliance team stores free-text support tickets and wants each ticket labeled as `pii`, `financial` or `none` so that a governance task can apply sensitivity tags. How should `SNOWFLAKE.CORTEX.CLASSIFY_TEXT` be used in this design?

    1. A.Call CLASSIFY_TEXT with the ticket text only, and read per-category probability scores from the output to apply a 0.8 threshold before tagging each row.
    2. B.Call CLASSIFY_TEXT on the ticket column once, and rely on it to attach the matching sensitivity tag to the source column through the tag lineage graph.
    3. C.Call CLASSIFY_TEXT inside a masking policy body so that every SELECT automatically replaces tickets labeled `pii` with a hash, with no tagging step at all.
    4. D.Call CLASSIFY_TEXT with the ticket text and the three categories, extract the returned `label` value, and let a task assign tags from it.
    Show answer & explanation

    Correct answer: D — Call CLASSIFY_TEXT with the ticket text and the three categories, extract the returned `label` value, and let a task assign tags from it.

    • A. Incorrect: the function needs categories supplied by the caller and returns the label, not a score per category. A threshold cannot be applied to its output.
    • B. Incorrect: CLASSIFY_TEXT is a scalar function that returns a label and never writes governance tags. Tag assignment needs explicit statements.
    • C. Incorrect: calling an LLM function per query inside a masking policy would be costly and does not produce tags. Masking policies are normally driven by tags rather than creating them.
    • D. Correct: CLASSIFY_TEXT takes the text and a list of user-defined categories and returns an object whose `label` field holds the chosen category. Applying tags is a separate step that the team must automate.

    Subdomain 5.2: Leverage Snowflake Cortex AI to enhance data security.

    33.A governance team builds a Cortex Agent with a Cortex Analyst tool and a custom stored-procedure tool. They worry the orchestration model could reach data beyond the intended scope. Which design is most appropriate?

    1. A.Grant the agent's owner role ACCOUNTADMIN so every tool call resolves, and instruct the orchestration model in its prompt to avoid sensitive tables.
    2. B.Add every available tool to the specification for flexibility, and rely on the model's reflection step to stop calls that touch unauthorized data.
    3. C.Run all agent requests through one shared service user with broad SELECT access, so that audit logs show a single consistent identity for tool calls.
    4. D.Configure only the needed tools in the agent specification and give the calling role least-privilege access to each tool's tables and procedure.
    Show answer & explanation

    Correct answer: D — Configure only the needed tools in the agent specification and give the calling role least-privilege access to each tool's tables and procedure.

    • A. Incorrect: an over-privileged owner combined with a prompt instruction is not a control. Prompts can be bypassed and privileges decide access.
    • B. Incorrect: the reflection step evaluates results for task completion and is not an authorization mechanism. Extra tools only widen the attack surface.
    • C. Incorrect: a shared broad identity erases per-user accountability and lets every user see data beyond their entitlement.
    • D. Correct: data access follows the privileges and execution context of each tool, so limiting both the tool list and the grants bounds what the agent can reach.

    Subdomain 5.3: Manage security in Snowflake Native Apps.

    34.A Native App must call a SaaS API on behalf of each consumer's users using OAuth 2.0, and the consumer's security team insists that the app owns no consumer credentials. Which configuration fits?

    1. A.The consumer creates an API_AUTHENTICATION integration and an OAUTH2 secret, then binds both to the app through references with an approved egress path
    2. B.The provider embeds its own OAuth client secret in the setup script and shares a single refresh token across every consumer account for all of their users
    3. C.The app asks each analyst to paste a personal token into a Streamlit text field and caches it in a table in the application schema for later calls
    4. D.The provider creates a SAML2 security integration in the consumer account so the app can request OAuth access tokens for the external service
    Show answer & explanation

    Correct answer: A — The consumer creates an API_AUTHENTICATION integration and an OAUTH2 secret, then binds both to the app through references with an approved egress path

    • A. This is correct. Consumer-owned security integration and secret objects keep OAuth client details in the consumer account. The app only uses them through references and the approved external access path.
    • B. This is incorrect. A shared secret and refresh token in package files exposes all consumers to one credential and violates the rule against sensitive data in the package.
    • C. This is incorrect. Collecting tokens in a form and storing them in a plain table creates an unmanaged credential store. Snowflake SECRET objects exist to avoid it.
    • D. This is incorrect. A SAML2 integration is for single sign-on into Snowflake and does not issue OAuth tokens for an outside API. Providers also cannot create integrations in consumer accounts.

    Subdomain 5.3: Manage security in Snowflake Native Apps.

    35.A consumer's delegated administrator needs to install Native Apps from listings without holding ACCOUNTADMIN. Which grant lets that role install an app, and what follows from it?

    1. A.Grant the CREATE APPLICATION PACKAGE privilege on the account to the role, because this is what authorizes consumers to install released versions of an app
    2. B.Grant the CREATE INTEGRATION privilege on the account to the role, because every app installation creates a security integration from its manifest
    3. C.Grant the CREATE APPLICATION privilege on the account to the role; the installing role becomes the app owner, so use a dedicated role
    4. D.Grant MANAGE RELEASES on the application package to the role, which lets a consumer install any released version with no account-level privileges
    Show answer & explanation

    Correct answer: C — Grant the CREATE APPLICATION privilege on the account to the role; the installing role becomes the app owner, so use a dedicated role

    • A. This is incorrect. CREATE APPLICATION PACKAGE is a provider privilege for building packages. It plays no part in installing an app.
    • B. This is incorrect. Installing an app does not create security integrations in this way. External access is approved separately through reviewed references and specifications.
    • C. This is correct. CREATE APPLICATION is the account-level privilege for installing apps. The role that creates the application owns it, which is why a dedicated role is the usual choice.
    • D. This is incorrect. MANAGE RELEASES belongs to the provider side and manages release directives. Consumers still need CREATE APPLICATION to install.

    Want the full experience?

    These are just samples. Practice the full Snowflake SnowPro Advanced: Security Engineer (SEA-C01) question bank in quiz mode — free, no signup, with domain practice and exam simulation.