SEA-C01 Sample Questions

SEA-C01 Sample Questions & Answers

Encryption and broader data protection carry the most weight, next to user identity and authentication, audit logging and compliance monitoring, spotting threats and responding to incidents, and locking down AI, ML and application workloads.

Launch the full SEA-C01 simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Access Control and Identity Management · Authentication mechanisms

    A Snowflake administrator needs to group several AWS VPC endpoints and public IP addresses together so they can be referenced by multiple network policies across the account. Which Snowflake object should be created to fulfill this requirement?

    Show answer & explanation

    Correct answer: D

    A Network Rule is a Snowflake object that groups network identifiers, such as IPv4 addresses or VPC endpoints, into a single logical unit. These rules can then be referenced by network policies (or external access integrations) to control traffic flow, making administration much more scalable than defining IPs directly inside multiple policies.

  2. Question 2Beginner

    Access Control and Identity Management · Access control model

    True or False: When a user executes the USE SECONDARY ROLES ALL command in a Snowflake session, they can only perform actions that require the intersection (overlap) of privileges from all their granted roles.

    Show answer & explanation

    Correct answer: B

    When USE SECONDARY ROLES ALL is executed, the user's session utilizes the aggregate (union) of all privileges granted to their primary role and all secondary roles, not the intersection. This allows the user to query cross-database objects seamlessly without constantly switching primary roles.

  3. Question 3Intermediate

    Access Control and Identity Management · Authentication mechanisms

    A security engineer is performing an automated credential rotation for an application that connects to Snowflake via Key Pair Authentication. To achieve zero downtime during the rotation process, which operational sequence must the engineer follow?

    Show answer & explanation

    Correct answer: C

    Snowflake supports assigning up to two public keys to a single user (RSA_PUBLIC_KEY and RSA_PUBLIC_KEY_2). To achieve zero downtime during rotation, the engineer should assign the new key to RSA_PUBLIC_KEY_2. While both keys are active, the client is updated to use the new private key. Once the transition is verified, the old key can be safely removed from RSA_PUBLIC_KEY.

  4. Question 4Intermediate

    Access Control and Identity Management · Access control model

    A new data analytics team requires the ability to create custom roles and assign them to new users joining their department. Following the principle of least privilege, which system-defined role should be granted to the team lead to fulfill this specific administrative task without exposing broader security configurations?

    Show answer & explanation

    Correct answer: A

    The USERADMIN role is specifically designed for creating and managing users and roles. While SECURITYADMIN can also do this (because it inherits USERADMIN), granting SECURITYADMIN violates the principle of least privilege as it also includes the global MANAGE GRANTS privilege and the ability to alter network policies.

  5. Question 5Intermediate

    Access Control and Identity Management · Authentication mechanisms

    An organization wants to strictly enforce Multi-Factor Authentication (MFA) for all human users while allowing service accounts to bypass MFA. They decide to use Snowflake Authentication Policies to accomplish this. Which of the following approaches represents the most scalable and secure implementation?

    Show answer & explanation

    Correct answer: D

    Applying an authentication policy that requires MFA (MFA_ENROLLMENT = REQUIRED) at the account level ensures all standard password-based logins enforce MFA. Service accounts utilizing Key Pair Authentication inherently bypass MFA requirements because Key Pair Auth does not support or require MFA, making this the most secure and scalable approach without needing complex user-level policy mappings.

  6. Question 6Beginner

    Access Control and Identity Management · Access control model

    Which system-defined role in Snowflake is strictly recommended to be used ONLY for configuring account-level parameters, viewing billing information, and managing account-level objects, but should generally NOT be used to create custom databases or schemas?

    Show answer & explanation

    Correct answer: C

    The ACCOUNTADMIN role is the most powerful role in Snowflake. Best practices dictate that it should be reserved for account-level administrative tasks (billing, account parameters, integrations). Creating databases or tables with ACCOUNTADMIN breaks the decentralized management model and prevents SYSADMIN from managing those objects.

Ready for the real thing?

The full SEA-C01 simulator has every exam-style question, timed mode, and instant scoring.