ExamDumpster

Free SEA-C01 sample questions

Real questions from the SnowPro Advanced: Security Engineer practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

A security engineer is configuring authentication policies in Snowflake for a multinational enterprise. The organization has set an account-level authentication policy that requires multi-factor authentication (MFA) for all users. However, a specific service account named `ETL_SVC_ACCOUNT` is used by an automated pipeline that cannot process MFA prompts. The engineer creates a new authentication policy that disables the MFA requirement and assigns it directly to the `ETL_SVC_ACCOUNT` user. When the ETL pipeline attempts to connect, which of the following describes the outcome?

Question 2Choose 2

An organization is enforcing strict discretionary access control (DAC) by utilizing Managed Access Schemas. A data engineer with a custom role named `DATA_ENGINEER_ROLE` creates a new table within a Managed Access Schema. Which of the following entities have the authority to grant privileges on this newly created table to other roles? (Select TWO)

Question 3Choose one

A financial services institution is building a custom web application that requires access to Snowflake data. The security architecture mandates the use of OAuth for delegating authorization. The application will act as an external OAuth client. The security engineering team needs to configure a security integration in Snowflake for this custom client. The requirements stipulate that the access tokens issued must expire in exactly 30 minutes to minimize the window of exposure, and refresh tokens must not be issued to this specific client due to the application's stateless nature. During the implementation, the lead engineer creates the security integration using the `CREATE SECURITY INTEGRATION` command. However, during testing, the security team notices that the application is still receiving refresh tokens, and the access tokens are valid for the default 10 minutes rather than the requested 30 minutes. Based on this scenario, which combination of properties must be explicitly set on the security integration to meet the strict security requirements?

Question 4Choose one

A Snowflake administrator needs to group several AWS VPC endpoints and public IP addresses together so they can be referenced by multiple network policies across the account. Which Snowflake object should be created to fulfill this requirement?

Question 5Choose one

True or False: When a user executes the `USE SECONDARY ROLES ALL` command in a Snowflake session, they can only perform actions that require the intersection (overlap) of privileges from all their granted roles.

Question 6Choose one

A security engineer is performing an automated credential rotation for an application that connects to Snowflake via Key Pair Authentication. To achieve zero downtime during the rotation process, which operational sequence must the engineer follow?

6 more free samples are waiting

Create a free account to unlock the whole SEA-C01 sample bank, or get full access to all 156 practice questions in the simulator.

Create account