SEA-C01 Sample Questions & Answers
Encryption and broader data protection carry the most weight, next to user identity and authentication, audit logging and compliance monitoring, spotting threats and responding to incidents, and locking down AI, ML and application workloads.
Launch the full SEA-C01 simulator →Showing 6 of 12 free samples.
- Question 1Beginner
Access Control and Identity Management · Authentication mechanisms
A Snowflake administrator needs to group several AWS VPC endpoints and public IP addresses together so they can be referenced by multiple network policies across the account. Which Snowflake object should be created to fulfill this requirement?
Show answer & explanation
Correct answer: D
A Network Rule is a Snowflake object that groups network identifiers, such as IPv4 addresses or VPC endpoints, into a single logical unit. These rules can then be referenced by network policies (or external access integrations) to control traffic flow, making administration much more scalable than defining IPs directly inside multiple policies.
- Question 2Beginner
Access Control and Identity Management · Access control model
True or False: When a user executes the
USE SECONDARY ROLES ALLcommand in a Snowflake session, they can only perform actions that require the intersection (overlap) of privileges from all their granted roles.Show answer & explanation
Correct answer: B
When
USE SECONDARY ROLES ALLis executed, the user's session utilizes the aggregate (union) of all privileges granted to their primary role and all secondary roles, not the intersection. This allows the user to query cross-database objects seamlessly without constantly switching primary roles. - Question 3Intermediate
Access Control and Identity Management · Authentication mechanisms
A security engineer is performing an automated credential rotation for an application that connects to Snowflake via Key Pair Authentication. To achieve zero downtime during the rotation process, which operational sequence must the engineer follow?
Show answer & explanation
Correct answer: C
Snowflake supports assigning up to two public keys to a single user (
RSA_PUBLIC_KEYandRSA_PUBLIC_KEY_2). To achieve zero downtime during rotation, the engineer should assign the new key toRSA_PUBLIC_KEY_2. While both keys are active, the client is updated to use the new private key. Once the transition is verified, the old key can be safely removed fromRSA_PUBLIC_KEY. - Question 4Intermediate
Access Control and Identity Management · Access control model
A new data analytics team requires the ability to create custom roles and assign them to new users joining their department. Following the principle of least privilege, which system-defined role should be granted to the team lead to fulfill this specific administrative task without exposing broader security configurations?
Show answer & explanation
Correct answer: A
The
USERADMINrole is specifically designed for creating and managing users and roles. WhileSECURITYADMINcan also do this (because it inheritsUSERADMIN), grantingSECURITYADMINviolates the principle of least privilege as it also includes the globalMANAGE GRANTSprivilege and the ability to alter network policies. - Question 5Intermediate
Access Control and Identity Management · Authentication mechanisms
An organization wants to strictly enforce Multi-Factor Authentication (MFA) for all human users while allowing service accounts to bypass MFA. They decide to use Snowflake Authentication Policies to accomplish this. Which of the following approaches represents the most scalable and secure implementation?
Show answer & explanation
Correct answer: D
Applying an authentication policy that requires MFA (
MFA_ENROLLMENT = REQUIRED) at the account level ensures all standard password-based logins enforce MFA. Service accounts utilizing Key Pair Authentication inherently bypass MFA requirements because Key Pair Auth does not support or require MFA, making this the most secure and scalable approach without needing complex user-level policy mappings. - Question 6Beginner
Access Control and Identity Management · Access control model
Which system-defined role in Snowflake is strictly recommended to be used ONLY for configuring account-level parameters, viewing billing information, and managing account-level objects, but should generally NOT be used to create custom databases or schemas?
Show answer & explanation
Correct answer: C
The
ACCOUNTADMINrole is the most powerful role in Snowflake. Best practices dictate that it should be reserved for account-level administrative tasks (billing, account parameters, integrations). Creating databases or tables withACCOUNTADMINbreaks the decentralized management model and preventsSYSADMINfrom managing those objects.
Ready for the real thing?
The full SEA-C01 simulator has every exam-style question, timed mode, and instant scoring.