
Snowflake SnowPro Advanced:Security Engineer
Domain 4Objective 2
Execute Security Incident Response Protocols SNOWPRO-ADVANCED-SECURITY-ENGINEER Practice Questions (Page 3)
Part of the Threat and Risk Management domain, which makes up ~27% of our current practice bank.
29questions here
6free pages
9concepts
Questions 11–15
- 11
In the incident response lifecycle, which phase involves restoring affected systems and validating that they are operating securely before returning them to normal use?
Select an answer first - 12
During an incident investigation, you discover that a compromised service account has been used to create a new warehouse and run heavy queries. You need to contain the incident while preserving evidence for forensic analysis. Which action should you take FIRST?
Select an answer first - 13
A security analyst is triaging a potential incident where a user's credentials were used to run a series of queries that returned sensitive data. The analyst needs to determine the scope of the incident. Which combination of data sources would provide the MOST comprehensive view of the incident's scope?
Select an answer first - 14
A security engineer at a large enterprise discovers that a compromised user has been using a role with elevated privileges to create and drop tables in a production database. The engineer needs to contain the incident while minimizing disruption to business operations. Which action BEST balances containment and business continuity?
Select an answer first - 15
What is the primary purpose of communication protocols during a security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Snowflake. “SNOWPRO-ADVANCED-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.