01. At a payments processor, fraud investigators hold one role that reads unmasked cardholder data and a second role that can write to an external stage for evidence exports. Policy says a single statement must never draw on both entitlements at once. Investigators need each role on different days, administrators refuse to maintain two user objects per investigator, and investigators currently activate all of their roles through secondary roles.
Which control best satisfies the policy while keeping both roles on each investigator's user?
a) A masking policy returning clear card values only when CURRENT_ROLE() is the cardholder-reading role
b) An alert that flags any statement issued while both roles were active in its session
c) Revoke the export role and grant it back through a ticketed request when an export is due
d) A session policy on the investigators' users that permits no secondary roles, so each session runs under one role at a time
02. To stop analysts exporting data through desktop drivers, an insurer attached an account-level authentication policy permitting only the Snowsight client type. Overnight, every ingestion pipeline failed to authenticate. The platform team then attached a second authentication policy, permitting driver clients with key-pair authentication, to each pipeline's user object.
The pipelines recovered, and analysts remain restricted to Snowsight.
Which statement explains why the second change restored the pipelines without loosening the analyst restriction?
a) The two policies are combined, so each pipeline user is allowed the union of both client lists
b) A policy set on a user object takes precedence over the account policy for that user
c) Key-pair authentication is checked before client types, so key-pair drivers pass
d) The user-level policy is applied after the account policy admits a client and can only narrow access
03. A CI/CD deployment role creates tables in a regular analytics schema that is not managed access, and it must grant SELECT on each new table to a reporting role within the same deployment. A reviewer finds that the deployment role was granted MANAGE GRANTS on the account when the grant step first failed. The root cause turned out to be a script that ran the GRANT under a different role from the one that had created the table.
Which remediation meets the deployment requirement with the least privilege?
a) Revoke MANAGE GRANTS and run the grant step under the deployment role, which owns what it creates
b) Keep MANAGE GRANTS on the deployment role and alert on every GRANT statement it issues in the query history
c) Revoke MANAGE GRANTS and convert the schema to managed access so the schema owner issues every grant
d) Replace MANAGE GRANTS by granting SECURITYADMIN to the deployment role
04. During a routine review at an HR software vendor, an analyst examines the ACCESS_HISTORY record for one query run by a data scientist. No masking or projection policy protected the payroll table at the time. The record shows:
Base objects accessed: HR.PAYROLL, columns SALARY and EMPLOYEE_ID
Objects modified: SANDBOX.COMP_STUDY, column SALARY
Base source of the modified SALARY column: HR.PAYROLL.SALARY
Which conclusion does this evidence support?
a) The sandbox table was joined to payroll data, so no values were copied into it
b) Payroll salary values were read by the query and not stored anywhere else
c) Payroll salary values were written to a sandbox table now in scope
d) The data scientist can be shown to have exported salary values out of the account
05. A university's governance team creates a custom tag named PII and assigns a STRING masking policy to it. It then runs Snowflake data classification over a new admissions schema with default settings. The classification results are visible as semantic and privacy category tags on EMAIL, PHONE and NAME columns. Analysts still see every value in clear.
What is the most likely cause?
a) Tag-based masking reaches just the columns created after its policy was assigned to the tag
b) Classification recorded its results in system tags, and nothing has set the custom PII tag
c) Classification results must be approved before any tag-based policy can take effect on them
d) The STRING policy signature does not match those columns' VARCHAR type
06. An auditor at a hospital network must confirm that the account parameter allowing MFA tokens to be cached in the client operating system's keystore stayed disabled for the whole audit period, which runs up to the present day. The period falls within the account usage retention window, and the parameter can be set only for the account, not for individual users or sessions.
Which evidence together supports that conclusion?
(Select TWO.)
a) A Trust Center finding describing the account's posture at the end of the period
b) POLICY_REFERENCES, showing an authentication policy requiring MFA attached to the account
c) The parameter's current value and level, as reported by SHOW PARAMETERS in the account
d) QUERY_HISTORY, showing no ALTER ACCOUNT statement that changed it during the period
e) Time Travel on the account, used to read the parameter as of the start of the period
07. A pharmaceutical distributor's tag-based masking policy masks columns tagged INTERNAL or RESTRICTED under its SENSITIVITY tag. An audit finds a patient-address column tagged RESTRICED, a typo the policy did not recognize, which left addresses in clear. Each data team must keep setting the tag on its own columns.
Which change prevents a misspelled value from being set on the tag in the future?
a) Rewrite the policy's default branch so any unrecognized tag value returns a mask
b) Revoke APPLY on the tag from every role except one central governance role
c) Schedule a TAG_REFERENCES query alerting on values outside the approved set
d) Define an allowed-values list on the tag itself
08. After an audit finding about a view shared with an external party, a platform team redefined every view in its analytics databases as a secure view. Dashboard queries built on internal convenience views have since slowed noticeably. Those convenience views are queried only by roles that already hold SELECT on the underlying tables, and they hide nothing from those roles.
What should the team do?
a) Keep them secure and scale up the warehouses serving the dashboards
b) Replace the convenience views with masking policies on the table columns
c) Return the internal convenience views to standard views
d) Materialize the convenience views into tables that a scheduled task refreshes
09. An online retailer fulfilled a customer's erasure request by deleting that customer's rows from the ORDERS table and confirming they were gone. Weeks later, a faulty load was found to have started before the erasure was performed. An engineer repaired it by cloning ORDERS as of a timestamp before that load and swapping the clone into production. An audit now finds the erased customer's orders present again.
What is the most likely cause?
a) Fail-safe restored the deleted micro-partitions when the swap was treated as a recovery operation
b) The swap removed the table's masking policies, so rows that were hidden became visible to auditors
c) Time Travel reverses a delete once its retention ends
d) The clone came from a point before the deletion and carried the erased rows back
10. In a claims database, a database-level future grant gives an analyst role SELECT on new tables in every schema. The finance schema also carries a schema-level future grant giving a finance reader role SELECT on its new tables. An audit role holds USAGE on the database and a schema-level future grant of SELECT on new tables in the operations schema, but was never granted USAGE on that schema.
After new tables appear, the analyst role reads new tables in schemas that have no future grants of their own but not in finance or operations, and the audit role cannot query the new operations tables although its SELECT grants on them are present.
Which statements explain these observations?
(Select TWO.)
a) Database-level future grants reach only the schemas created after that grant was defined
b) Schema-level future grants take precedence over database-level future grants for the same object type in that schema\
c) The operations schema is managed access, which suppresses future grants defined by the schema owner
d) Future grants take effect only after a role holding MANAGE GRANTS confirms each new object
e) Querying a table requires USAGE on its schema in addition to SELECT on the table