オンラインNAS-C01テストブレーン問題集とテストエンジン [Q103-Q128]

Share

オンラインNAS-C01テストブレーン問題集とテストエンジン

リアルSnowflake NAS-C01試験問題集には正解378問題と解答があります

質問 # 103
You're developing a Snowflake Native App that includes a function, , which retrieves sensitive customer dat a. You want to ensure that this data is only accessible by authorized roles within the consumer's account, even after the application is installed. Which of the following strategies are appropriate for securing the application's data and function access? (Choose two)

  • A. Grant the 'EXECUTE privilege on the function to specific, consumer-defined roles within the consumer's account via the provider's setup script.
  • B. Implement a masking policy on the underlying customer data table that restricts access based on the current role.
  • C. Use a secure UDF to encapsulate the data retrieval logic, preventing direct access to the underlying tables.
  • D. Rely solely on the consumer's account administrator to manage access to the function and data after installation.
  • E. Grant the 'EXECUTE privilege on the function to the 'application role'.

正解:A、B

解説:
Implementing a masking policy (Option A) directly on the underlying data table ensures that data is masked or restricted based on the user's role, regardless of how the data is accessed. Granting 'EXECUTE to consumer-defined roles (Option C) allows the provider to explicitly control which roles in the consumer's account have access to the function. Option B is incorrect as giving Execute permission to application role won't restrict access within consumer account. Option D can enhance security, it requires role base access control to be truly useful as the UDF will still need explicit role definitions of user access. Option E is insufficient; the provider needs to actively participate in securing the data through mechanisms like masking policies and role-based access control via grants in the setup script.


質問 # 104
You are developing a Snowflake Native Application for a data enrichment service and plan to list it on the Snowflake Marketplace. You want to control the costs incurred by consumers of your application while maximizing its accessibility. Which of the following strategies represent Snowflake Marketplace best practices for cost management and pricing?

  • A. Offer a free trial period with limited functionality to allow potential consumers to evaluate the application before committing to a paid subscription.
  • B. Use Snowflake's built-in resource monitors to proactively track application consumption and alert consumers when they approach predefined spending limits.
  • C. Provide detailed cost estimation documentation outlining the expected costs for different usage scenarios and data volumes.
  • D. Implement a tiered pricing model based on data volume processed, compute resources consumed, or number of users accessing the application. Offer a free basic tier with limited functionality.
  • E. Refrain from providing any cost-related information upfront to encourage broader adoption, deferring cost discussions until after installation and usage.

正解:A、B、C、D

解説:
Offering a free trial (A) allows users to evaluate. Tiered pricing (B) offers flexibility and accommodates different budgets. Providing cost estimation documentation (C) is transparent and helps users plan. Using resource monitors for alerts (E) enables proactive cost control. Hiding cost information (D) is not a best practice and can lead to negative user experiences and discourage adoption.


質問 # 105
You are developing a Snowflake Native Application that interacts with sensitive customer dat a. You want to implement robust security scanning before publishing to the Snowflake Marketplace. Which of the following strategies are MOST effective to detect and prevent potential vulnerabilities before submitting your application, considering limitations on marketplace pre-publication scanning capabilities?

  • A. Only use Snowflake provided templates and example codes as these are already pre-approved from security perspectives
  • B. Rely solely on Snowflake's built-in scanning during the Marketplace submission process, as it covers all known vulnerabilities.
  • C. Manually review all code for potential security flaws and ensure adherence to secure coding practices.
  • D. Implement a comprehensive CI/CD pipeline that includes static code analysis (SAST) using tools like SonarQube or similar, focusing on SQL injection, cross-site scripting (XSS), and insecure deserialization vulnerabilities. Include unit and integration tests with parameterized inputs. Regularly update dependency versions and scan for known vulnerabilities in third-party libraries included in your application's code (e.g., Python libraries).
  • E. Employ a third-party penetration testing service to perform a black-box test of the application after deployment in a staging environment but prior to Marketplace submission.

正解:D、E

解説:
Option B and D provides a good answer as Snowflake's Marketplace scanning is limited, a multi-layered approach is crucial. SAST and dependency scanning within a CI/CD pipeline (B) allows for early detection of many common vulnerabilities. Penetration testing (D) provides an external, real-world assessment of the application's security posture. Relying solely on Snowflake's scanning (A) is insufficient. Manual code review (C), while helpful, is prone to human error. Only using Snowflake provided templates is very restrictive and not a solution.


質問 # 106
You are developing a Snowflake Native Application that includes a Python UDE This UDF needs to interact with an external API that requires authentication using OAuth 2.0. The application package should securely manage the OAuth credentials without exposing them to the consumer account. How can you securely configure and access the OAuth credentials from within the UDF?

  • A. Store the OAuth credentials in a secure external storage (e.g., AWS Secrets Manager) and retrieve them using an external function.
  • B. Configure an OAuth integration in Snowflake and grant the UDF's role access to it, allowing the UDF to obtain tokens using 'SYSTEM$GET OAUTH TOKEN'.
  • C. Store the OAuth client ID and secret directly in the UDF code as string literals.
  • D. Store the OAuth client ID and secret in environment variables within the Snowflake environment for the application.
  • E. Use Snowflake's secret management feature to store the OAuth client ID and secret, and access them from the UDF using 'SYSTEM$GET SECRET.

正解:B、E

解説:
Storing credentials directly in the code (A) is a major security risk. Environment variables in Snowflake (B) are not designed for sensitive credentials. Snowflake's secret management (C) provides a secure way to store and access secrets. Using an external storage with an external function (D) is a viable option but adds complexity. OAuth integration (E) allows Snowflake to handle the OAuth flow, providing secure token management. Therefore, C and E provide the most secure and manageable solutions.


質問 # 107
You are developing a Snowflake Native Application that leverages Snowflake Event Tables to log application events. You notice that while the application is successfully writing events to the event table, consumers are reporting that they cannot query the event table. Assume that you have successfully implemented the logging mechanism in your code and data is being logged. Consider the following manifest section:

Which of the following steps is MOST critical to resolve this issue and ensure consumers can query the event table?

  • A. Ensure that the consumer account has the 'MONITOR privilege on the application, as this is required to query event tables associated with native applications.
  • B. Confirm that the event table is explicitly listed in the 'shared_objects' section of the application manifest with the correct 'object_name', 'source_type' set to event_table', and 'privileges' including 'SELECT'.
  • C. Grant the 'APPLY MASKING POLICY privilege to the application role on the event table to enable consumers to see masked data, and the REFERENCE_USAGE privilege on the database and schema that contains the event table.
  • D. Verify that the application role defined in the application manifest has been granted the 'SELECT privilege on the event table within the provider account.
  • E. The correct approach is not listed, as consumers cannot directly query event tables associated with Snowflake Native Applications for security reasons.

正解:B

解説:
The most critical step is to ensure that the event table is correctly configured in the application manifest under the 'shared_objectS section, with the 'source_type' defined as 'event_table' and the 'privileges' including ' SELECT. This explicitly tells Snowflake that the event table is intended to be shared with consumers and that they should have the 'SELECT privilege on it. Without this, consumers will not be able to query the event table, regardless of other privileges. Other options are either not relevant or do not address the root cause of the problem. Option A, option B and option D are all wrong, as they are not related to the root cause of the problem. Option E, is correct as it ensures masking policy is not a problem. The privileges are not relevant in this case.


質問 # 108
A Native Application deployed on Snowflake uses a warehouse 'APP WH'. You want to monitor the warehouse usage costs specifically attributed to this application. Which of the following approaches provides the MOST granular and accurate way to track these costs?

  • A. Tag all queries originating from the application with a specific tag and then filter the 'QUERY_HISTORY view based on this tag and the warehouse name.
  • B. Create a separate warehouse solely for the application and then examine the 'WAREHOUSE METERING HISTORY view.
  • C. Examine the 'WAREHOUSE METERING HISTORY view in the 'SNOWFLAKE database without any filtering.
  • D. Use the view and filter by 'USER_NAME associated with the application role.
  • E. Rely on the total credits consumed by the account, as the application's usage is insignificant.

正解:B

解説:
Creating a separate warehouse exclusively for the application is the most precise method. The view then provides accurate usage data. Tagging queries (Option B) is a viable alternative but requires diligent implementation and maintenance of the tagging strategy. Filtering 'QUERY_HISTORY by (Option D) may not accurately reflect costs if the role is used for other purposes. Examining without filtering (Option A) is too broad, and assuming the application's usage is insignificant (Option E) is incorrect for proper cost management.


質問 # 109
A provider is developing a Snowflake Native App. They have created a database named 'app_db' using 'CREATE DATABASE app_db WITH MANAGED ACCESS;'. Subsequently, they need to create a schema within this database and grant specific privileges on the schema's objects to a role 'app_admin' . Which of the following SQL statements are valid and necessary to set this up securely and effectively?

  • A.
  • B.
  • C.
  • D.
  • E.

正解:A、B

解説:
Since the database 'app_db' was created with 'MANAGED ACCESS, simply creating the schema using 'CREATE SCHEMA app_db.internal_schema;' inherits the managed access properties. Granting 'USAGES is necessary to allow the role to access objects within the schema. Granting ownership is typically not required and could unnecessarily elevate privileges. Option B, while valid syntax, will result in an error, the MANAGED ACCESS is already inherited from the DATABASE and therefore redudnant. Option D is too permissive. Option E, using all privileges, is not best security practice, rather only the specific USAGE is needed in this scenario.


質問 # 110
You are developing a Snowflake Native App that requires accessing a specific table within the consumer's account. The consumer should not have direct access to this table. Which of the following is the MOST secure and appropriate method to grant the necessary access?

  • A. Granting the CONSUMPTION usage privilege on the provider account database to the consumer account, and then granting SELECT on the specific table to a role that the app assumes.
  • B. Creating a Snowflake Secure UDF that queries the table within the provider account and exposing the UDF to the consumer account through a package.
  • C. Creating a Snowflake Secure View on the table in the provider account and sharing this view with the consumer account using Data Sharing.
  • D. Granting direct SELECT access to the consumer role on the table in the provider account, ensuring to revoke access after the app is installed.
  • E. Employing a Stored Procedure owned by the application role that queries the table in the provider account, and allowing access to the procedure via API integration.

正解:B

解説:
Secure UDFs allow you to execute queries in the provider account without exposing the underlying table directly to the consumer. This isolates the data and minimizes the risk of unauthorized access. Stored procedures offer similar functionality, but UDFs are generally simpler and more performant for basic data retrieval. Secure Views via data sharing expose the structure to the consumer account, and granting direct access is a major security risk.


質問 # 111
You are developing a Snowflake Native App that needs to perform asynchronous tasks in the consumer's account. Which of the following approaches is the MOST suitable and secure way to achieve this, ensuring minimal impact on the consumer's resources and maintaining data integrity?

  • A. Create a Snowflake Task that is executed within the consumer's account, triggered by events within the application, and configured to run on a Snowflake-managed compute pool.
  • B. The Native App can create task and warehouse in the consumer account to execute the code using CREATE APPLICATION command. The application uses SNOWFLAKE.CORE.AUTHZ.PASS PRIVILEGES() to execute these tasks.
  • C. Implement a scheduled stored procedure that polls for new tasks every minute and processes them, potentially consuming significant compute resources in the consumer's account. The stored procedure is deployed in the consumer's account using CREATE APPLICATION.
  • D. Implement a Snowpark UDF that starts a new thread to handle the asynchronous task within the consumer's compute environment.
  • E. Utilize an external message queue (e.g., AWS SQS, Azure Queue Storage) to offload asynchronous tasks, requiring the consumer to configure network policies to allow egress traffic to the queue.

正解:A

解説:
Using Snowflake Tasks (Option A) is the recommended approach for asynchronous task execution within a Snowflake Native App. The task is managed within the consumer's account but still deployed as part of app package, avoiding the need for external dependencies or extensive consumer configuration. Option B introduces complexity and security concerns with external message queues. Option C can be resource-intensive and inefficient. Option D is incorrect as apps are not allowed to create warehouses. Option E is not supported, UDFs do not run in separate threads.


質問 # 112
You are developing a Snowflake Native Application that processes sensitive dat a. During the application lifecycle management, including version updates, what steps should you take to ensure the data security and privacy of the consumers' data, especially considering that your development team might need access to a subset of the data for testing?

  • A. Utilize Snowflake's external functions to process the data in a secure enclave outside of Snowflake, minimizing the risk of data exposure. Ensure external functions called are encrypted.
  • B. Use Snowflake's data classification features to identify sensitive data and implement row-level security to restrict access to the development team.
  • C. Create a separate Snowflake account for testing and populate it with synthetic data that mimics the structure and characteristics of the consumer's data.
  • D. Implement data masking and anonymization techniques to create a sanitized test dataset derived from the consumer's data. Provide the development team with access only to the masked data, via data sharing from the producer to consumer account.
  • E. Grant the development team direct access to the consumer's data warehouse to facilitate testing. Ensure proper auditing is enabled.

正解:C、D

解説:
The best answers are (B) and (D). Providing direct access to consumer data (A) is a major security risk. Option (B) utilizes masking/anonymization, crucial for protecting sensitive data. Data is shared from Producer account to Consumer accounts with masking policies applied for developers testing/access. Option (D) with synthetic data offers a secure testing environment. While data classification (C) and row-level security are useful, they aren't sufficient to protect data during development and testing, as developers could still potentially access sensitive data. External functions (E) could be used in conjunction with options B or D, but aren't a standalone solution.


質問 # 113
You are developing a subscription-based Snowflake Native Application that offers tiered pricing (Basic, Premium, Enterprise) based on resource consumption (e.g., compute hours, data storage). Consumers select their desired tier during the subscription process. Your application needs to dynamically adjust resource limits based on the selected tier. Which combination of the following actions should you take to correctly implement this?

  • A. Leverage Snowflake's data governance features, creating row access policies for each tier and assigning them based on the consumer's subscription status
  • B. Implement role-based access control (RBAC) using different roles for each tier, granting each role appropriate privileges for data access and compute resources. Assign users to roles based on their subscription tier.
  • C. Store tier-specific resource limits (e.g., compute hours, data storage limits) in a configuration table within the application. Implement stored procedures that enforce these limits during runtime using custom logic.
  • D. Create separate resource monitors for each tier and associate the consumer's account with the appropriate resource monitor based on their selected tier during application installation.
  • E. Use 'ALTER WAREHOUSE commands within the application to dynamically adjust warehouse sizes based on the selected tier, after retrieving the selected tier information via the application's configuration metadata.

正解:C、E

解説:
The correct answers are A and D. Option A: Adjusting warehouse sizes dynamically with 'ALTER WAREHOUSE allows you to provide different compute resources based on the tier. Option D: Storing tier-specific resource limits in a configuration table and enforcing them in stored procedures allows for granular control over resource consumption. Option B is not a suitable solution for controlling resources within an application container. Resource monitors are more suited for organization-level control. Option C (RBAC) controls data access but doesn't inherently limit resource consumption. Option E is focused on row-level security and not relevant for governing overall resource limits.


質問 # 114
A software vendor is developing a Snowflake Native App that provides data enrichment services. As part of the application lifecycle, they need to automate the process of packaging, deploying, and upgrading their application across multiple Snowflake regions. Which of the following approaches provide the MOST efficient and reliable way to automate the deployment and upgrade process for this Native App? Select TWO options.

  • A. Create a custom deployment tool that directly manipulates Snowflake's metadata tables to register the application package.
  • B. Leverage Snowflake's Native Apps API (if available) to programmatically manage the application package lifecycle.
  • C. Integrate with CI/CD pipelines, creating packages and updating versions to control the application's deployment and upgrade process.
  • D. Use Snowflake's CLI (SnowSQL) in conjunction with scripting tools (e.g., Bash, Python) to automate the creation of application packages and deployments.
  • E. Manually create application packages for each region and upload them to Snowflake using the web interface.

正解:C、D

解説:
Using Snowflake's CLI (SnowSQL) with scripting allows for automating tasks like creating application packages and deployments. Integrating with CI/CD pipelines automates the entire deployment process, from building the application package to deploying it to multiple regions. Manual package creation is inefficient (A). Directly manipulating Snowflake's metadata tables is not recommended and unsupported (D). While Snowflake's Native Apps API (C) would be ideal, at the time of this writing, a fully featured API may not be available, so CLI scripting is currently the better option. CI/CD integration is also a valid response for this.


質問 # 115
A data provider wants to distribute a Snowflake Native Application that includes a secure view 'PROVIDER DB.PUBLIC.SALES SUMMARY' which aggregates sales dat a. They want to allow consumers of the application to query this view, but prevent them from accessing the underlying base tables. Which minimum set of privileges must be granted on the 'SALES SUMMARY view to enable this, assuming the application role is 'APP ROLE and the installing account doesn't want to use 'imported privileges' ?

  • A. GRANT ALL PRIVILEGES ON VIEW PROVIDER DB.PUBLISALES SUMMARY TO ROLE APP ROLE;
  • B. GRANT REFERENCES ON VIEW PROVIDER DB.PUBLIC.SALES SUMMARY TO ROLE APP ROLE;
  • C. GRANT USAGE ON DATABASE PROVIDER DB TO ROLE APP ROLE; GRANT USAGE ON SCHEMA PROVIDER DPUBLIC TO ROLE APP ROLE; GRANT SELECT ON VIEW PROVIDER DB.PUBLIC.SALES SUMMARY TO ROLE APP ROLE;
  • D. GRANT SELECT ON VIEW PROVIDER DB.PUBLIC.SALES SUMMARY TO ROLE APP ROLE;
  • E. GRANT SELECT ON VIEW PROVIDER DB.PUBLIC.SALES SUMMARY TO SHARE WITH APP ROLE;

正解:C

解説:
The consumer needs 'USAGE' privilege on the database and schema containing the view to access it. The 'SELECT' privilege on the view itself is required to query it. 'GRANT ALL PRIVILEGES' is excessive. 'GRANT ... TO SHARE is not a valid syntax. REFERENCES is for foreign keys.


質問 # 116
You are developing a Snowflake Native App that requires specific privileges to be granted to the consumer account. These privileges are necessary for the app to access and process data within the consumer's Snowflake environment. Which section of the manifest file is primarily used to declare these required consumer-side privileges?

  • A.
  • B.
  • C.
  • D.
  • E.

正解:A

解説:
The application.privileges section in the manifest file is specifically designed to declare the privileges required by the Native App in application . privileges the consumer's account. This ensures that the app has the necessary permissions to function correctly within the consumer's Snowflake environment. The other options are related to different aspects of the app's behavior, resources, and setup but not the declaration of required privileges.


質問 # 117
You are developing a Snowflake Native Application that requires maintaining multiple live versions for different customer segments. Some customers need to stay on an older version for compatibility reasons, while new customers should use the latest version. How can you best manage these different versions using Snowflake Native App features?

  • A. By implementing a custom versioning system within the application's stored procedures and functions, relying on consumer-provided parameters to determine which version of the logic to execute.
  • B. By using streams and tasks to replicate data and logic between different versions of the application, ensuring data consistency.
  • C. By creating separate Snowflake accounts for each customer segment, each with a different version of the application installed.
  • D. By creating separate application packages for each version and managing them independently, allowing consumers to choose which version to install. The 'APPLICATION ROLE is used to define application-level access.
  • E. By leveraging the 'APPLICATION ROLE to control access to different versions using conditional logic within the application code.

正解:D

解説:
The correct answer is (C). Snowflake Native Apps allow you to create separate application packages for each version. Consumers can then choose the version that best suits their needs. Using the 'APPLICATION ROLE allows for controlling access to different resources within the application, ensuring proper data governance and security. Options A, D, and E are less efficient or not directly supported by the Snowflake Native App framework. Option B is partially correct that you can leverage application role but version control is through separate application packages.


質問 # 118
You are tasked with designing a Snowflake Native App that requires multiple roles with different levels of access to its functionalities. The app needs to define which roles can perform specific actions, such as viewing data, modifying data, or managing app settings. Which of the following methods are CORRECT ways to control role-based access within a Snowflake Native App? (Select all that apply)

  • A. Defining application roles within the provider account and mapping them to consumer roles during the installation process. These application roles can then be used for fine-grained access control.
  • B. Using the 'allowed_roleS section in the manifest file to restrict access to certain functionalities based on the consumer's roles. This ensures that only authorized roles can interact with those components.
  • C. Granting specific privileges to roles directly within the application's stored procedures and functions, checking the current role using and conditionally executing code based on the role.
  • D. Creating separate versions of the application for each role, with each version containing only the functionalities that the role is allowed to access.
  • E. Defining roles within the setup script with specific privileges and instructing the consumer to grant their existing roles to these newly created roles.

正解:A、C

解説:
Option A is correct because using within stored procedures and functions allows you to conditionally execute code based on the current role, providing fine-grained access control. Option D is also correct because defining application roles within the provider account and mapping them to consumer roles during installation allows for a structured and manageable approach to role-based access control within the app.


質問 # 119
You are developing a Snowflake Native Application that uses Snowpark Container Services. Your application consists of multiple containerized services that require varying levels of computational resources. You want to optimize resource utilization and minimize costs by using a single Compute Pool for all services, while ensuring that each service has guaranteed access to resources. Which of the following strategies and SQL commands (or configurations) can be used to achieve this?

  • A. Use a single Compute Pool, create separate user-defined functions (UDFs) for each service and control resource allocation using the 'RESOURCE MONITOR parameter for each UDF.
  • B. Create a resource monitor and assign it to the COMPUTE POOL to manage cost. Resource monitors cannot be used to granular control the compute pool usage for native applications.
  • C. Use a single Compute Pool and rely on the container orchestration system to dynamically allocate resources among the services. Monitor utilization and adjust the Compute Pool size as needed. No SQL commands are needed.
  • D. Create a single Compute Pool and configure resource quotas for each service using container orchestration-specific configurations (e.g., Kubernetes resource quotas). While not directly managed via SQL, proper configuration of the container orchestrator is required.
  • E. Create separate Compute Pools for each service, sizing each pool according to the service's peak resource requirements.

正解:C、D

解説:
Option B is valid because the underlying container orchestration system dynamically allocates resources. Option C is also valid because resources can be configured in container orchestration systems to achieve resource guarantees for each service. Creating separate compute pools may be costly and inefficient in terms of resource management. Resource Monitors are for cost control not fine-grained service-level resource management. It provides control to monitor cost. The correct configuration of the container orchestrator is critical to achieve desired outcomes.


質問 # 120
A consumer installs a Snowflake Native App that collects usage statistics. The app uses an internal stage to store temporary data before aggregating it and sending it to the provider. The consumer notices that the internal stage is consuming a significant amount of storage and wants to understand if they are being charged for this storage. As a consumer, what level of visibility and control do you have over the storage costs associated with the internal stage created and managed by the installed Snowflake Native App?

  • A. The consumer is billed for the storage used by the internal stage, but they have no direct visibility into its usage or control over its lifecycle. The provider manages the stage's lifecycle.
  • B. The consumer has full visibility into the stage's storage consumption through the Snowflake web interface and can directly manage the stage's lifecycle to control costs.
  • C. The consumer can only see the stage's metadata but cannot see the data residing in it.
  • D. The consumer has no visibility into the stage's storage consumption or control over its lifecycle. All costs are borne by the application provider.
  • E. The consumer can view the overall storage consumption of the application but cannot differentiate between the internal stage and other data stored by the application.

正解:A

解説:
As a consumer, you are billed for the storage used by the application's internal stage. However, you have no direct visibility into the stage's usage or control over its lifecycle. The application provider manages the stage and data within. The consumer is billed for the storage within their account that the application uses. They are unaware of the data details within the application but still responsible for charges.


質問 # 121
You are creating a Snowflake Native Application that uses Snowpark Container Services. The application needs to process large datasets and requires a Compute Pool with specific GPU resources. You use the following SQL command to create a compute pool:

After creating the compute pool, you notice that your Snowpark Container Service is unable to start. Upon inspecting the 'SYSTEM$GET CP POLICY' for the allowed instance families list does not contain 'GPU NV M'. What is the MOST likely reason for this and how do you rectify it?

  • A. The specified instance family is invalid or not supported in your region. Use 'SYSTEM$GET_CP POLICY to verify the available instance families and choose a supported one.
  • B. The COMPUTE POOL needs to be explicitly associated to the application package by running ALTER APPLICATION PACKAGE ADD COMPUTE POOL my_compute_poor.
  • C. You need to explicitly grant the 'USAGE privilege on the instance family to the application role used by the container service using "GRANT USAGE ON INSTANCE FAMILY GPU NV M TO ROLE
  • D. GPU instance types are automatically enabled as part of SPCS and there is no account restriction.
  • E. The account does not have access to GPU-based instance families. Contact Snowflake support to enable GPU instance families for your account.

正解:E

解説:
GPU instance families are not automatically enabled for all accounts. Access must be explicitly granted. Without the necessary account permissions, the compute pool creation might succeed, but the container service will fail to start. The account admin needs to contact Snowflake to enable it.


質問 # 122
You are developing a Snowflake Native App that needs to be configurable by the consumer during installation. You define parameters in the 'manifest.ymr file. During application installation, the consumer provides values for these parameters. How can you access these parameter values within your application's setup script ('setup.sql')?

  • A. You must use the 'GET_DDL' function to retrieve the parameter values from the application object definition. The returned DDL string will contain the parameter values, which you need to parse.
  • B. Parameter values are passed as arguments to the 'setup.sqr script. You need to define input parameters in the script declaration and then access them by their position or name.
  • C. Use the ' SYSTEM$GET PARAMETER function within the 'setup.sqr script, passing the parameter name as an argument. This function retrieves the current value of the specified parameter for the application.
  • D. Parameter values are stored in a dedicated table automatically created by Snowflake during application installation. You can query this table using standard SQL to retrieve the parameter values.
  • E. Parameter values are automatically available as global variables within the 'setup.sqr script. You can reference them directly by their name as defined in the 'manifest.yml'.

正解:C

解説:
The correct answer is D. The 'SYSTEM$GET_PARAMETER function is the designated way to access the parameter values specified by the consumer during installation from within the application's setup script. This function allows you to dynamically configure the application based on the consumer's input.


質問 # 123
You are developing a Snowflake Native Application that leverages Snowpark Python for data transformation. Your CI/CD pipeline utilizes GitHub Actions for automated testing and deployment. One of your Snowpark functions relies on a UDF that reads data from an external stage. To ensure seamless integration testing in different environments (development, staging, production), you need to dynamically configure the stage URL during the test execution. Consider that you're using environment variables to store environment-specific values. Which of the following approaches provides the MOST secure and maintainable way to configure the stage URL in your Snowpark test code?

  • A. Use the 'os.environ' module in Python to read the stage URL from the environment variable. Pass the URL directly to the UDF as a string argument.
  • B. Create a Snowflake Secret object to store the stage URL. Within your Snowpark Python code, use the function to retrieve the secret value and pass it to the UDF.
  • C. Hardcode the stage URL directly within the Snowpark Python code. Use different code branches for each environment to manage the different URLs.
  • D. Define the stage URL as a global variable within your Snowpark session. Set the global variable to the correct URL at the beginning of the test script, using 'os.environ.get()'.
  • E. Store the stage URL in a configuration file (e.g., JSON or YAML) within the application package. Read the configuration file during test execution and pass the URL to the UDE

正解:B

解説:
Option C is the MOST secure and maintainable. Snowflake Secrets provide a secure and centralized way to manage sensitive information like stage URLs. The function allows you to retrieve the secret value within your Snowpark code without exposing the actual URL in the code or environment variables. Option A is not maintainable or secure. Option B exposes the stage URL in the environment, which is less secure than using Snowflake Secrets. Option D is a viable option but managing configuration files can be complex. Option E is not best practice; the Snowflake Sessions are also immutable.


質問 # 124
A consumer installs a Snowflake Native App that performs data transformations. The consumer wants to monitor the resource consumption (e.g., credits used) of the application. Which of the following SQL queries can the consumer use to retrieve the warehouse- level credit usage information associated with the installed application 'my_app'?

  • A. SELECT start_time, end_time, warehouse_name, credits_used FROM snowflake.account_usage.metering_history WHERE application_name = 'my_app';
  • B. SELECT start_time, end_time, warehouse_name, credits_used FROM snowflake.account_usage.warehouse_metering_history WHERE application_name = 'my_app';
  • C. SELECT start_time, end_time, warehouse_name, credits_used FROM snowflake.account_usage.resource_monitors WHERE application_name = 'my_app';
  • D. SELECT start_time, end_time, warehouse_name, credits_used FROM snowflake.account_usage.database_storage_usage_history WHERE application_name = 'my_app';
  • E. SELECT start_time, end_time, warehouse_name, credits_used FROM snowflake.account_usage.query_history WHERE application_name = 'my_app';

正解:B

解説:
The 'snowflake.account_usage.warehouse_metering_history& view provides warehouse-level credit usage information. Filtering by application_name = 'my_app" allows the consumer to see the credit consumption specifically for the installed application. 'metering_history' contains overall account usage. 'query_history' contains query details, not credit usage. 'resource_monitorS are for setting limits, not usage. database_storage_usage_history' shows storage usage, not credit consumption for compute.


質問 # 125
You are developing a Native Application that needs to access data from a consumer's table. The data contains personally identifiable information (PII), and your application requires explicit consent from the consumer to access this dat a. You have implemented a consent mechanism within your application's UI. Which of the following steps are NECESSARY to ensure compliance with data privacy regulations when accessing the consumer's data?

  • A. Use Snowflake's dynamic data masking policies on the PII columns and grant the application's service account the APPLY MASKING POLICY privilege. Revoke the UNMASK privilege from the application's service account.
  • B. Implement a secure view that filters the PII data unless the consumer's consent flag is set to TRUE in a separate consent table. Grant SELECT on the secure view to the application's service account.
  • C. Implement a row access policy on the table based on the consumer's consent flag, ensuring the application only sees data for consumers who have granted consent. Grant the SELECT privilege on the table to the application.
  • D. Implement a stored procedure that checks the consumer's consent flag. If consent is granted, the stored procedure retrieves and returns the requested data. Grant EXECUTE TASK privilege on the stored procedure to the application's service account.
  • E. Grant the SELECT privilege on the table directly to the application's service account after the consumer provides consent.

正解:B、C

解説:
Options B and E are correct and the best solutions. Option B uses a secure view which only exposes data when consent is given, adds an extra security. Row access policies (Option E) is the best solution by filtering the rows the application can see based on consent. Option A is incorrect because directly granting SELECT without a consent check bypasses the consent requirement. Option C is correct as store procedure also work but secure view is better. Option D doesn't prevent unauthorized access before explicit consent is given.


質問 # 126
You are creating a Snowflake Native Application that will be distributed to consumer accounts. As part of the installation process, you need to ensure that a specific database role, 'DATA READER, is created in the consumer account and granted 'SELECT' privileges on a specific table in the consumer's shared dat a. Which of the following code snippets, when placed within the application's setup script (install.sql), will correctly achieve this, assuming the application is granted 'CREATE DATABASE ROLE?

  • A.
  • B.
  • C.
  • D.
  • E.

正解:B

解説:
Option D correctly creates the database role, grants the necessary privileges, and associates it with the application. Here's a breakdown: 'CREATE OR REPLACE DATABASE ROLE DATA_READER;': creates or replaces the database role 'DATA_READER in the consumer account. 'GRANT SELECT ON TABLE CONSUMER DB.PUBLIC.MY TABLE TO DATABASE ROLE DATA READER;': Grants the 'SELECT privilege on the specified table to the 'DATA_READER role. It assumes that already exists in the consumer account through data sharing or some other mechanism. 'GRANT DATABASE ROLE DATA READER TO APPLICATION ROLE app_public;': This grants the database role to the application role, making the database role available to the application via the 'app_public' application role. 'GRANT APPLICATION ROLE app_public TO APPLICATION This is essential. This makes sure the application has the privileges from the application role granted. Without this, the database role is effectively useless to the application. In the consumer account, this means it will be able to use application. It should have an application object representing installed app in Consumer Account. Option A is incorrect because granting to 'SHARE is not the appropriate way to grant the role to the application. This is meant for granting to other accounts. Option B is incorrect because application will not be able to use app_public if not granted. Option C is incorrect because you need to assign database role to application role so it can be properly managed at the application level. You also need to grant the application role to the applicatiom Option E is incorrect because you should not grant the application role to SHARE; it will provide access to any accounts using the share, and can lead to over-privileged access.


質問 # 127
You are managing a Snowflake Native Application that provides data enrichment services. Over time, you've accumulated several application package versions: v1 .0 (initial release), v1.1 (bug fixes), v2.0 (new features and schema changes), and v2.1 (performance improvements for v2.0). Some consumers are still using v1 .0, while others have upgraded to v2.1. You need to retire v1.0 to reduce maintenance overhead. Which of the following actions and considerations are MOST important when deprecating vl .0? Select TWO that apply.

  • A. Keep v1.0 indefinitely to ensure compatibility with all existing application instances, regardless of usage.
  • B. Automatically migrate all consumers still using v1.0 to the latest version (v2.1 ) without their consent to simplify management.
  • C. Immediately drop version v1.0 from the application package to free up storage space.
  • D. Update the application's metadata in the Snowflake Marketplace to indicate that v1.0 is no longer supported.
  • E. Identify consumers still using v1.0. Communicate the deprecation timeline and provide clear instructions on how to upgrade to a supported version. Offer support during the transition.

正解:D、E

解説:
Options B and C are the most crucial. It's vital to communicate with consumers still using v1.0, providing ample notice and support for upgrading. Updating the Marketplace listing accurately reflects the application's supported versions. Option A without considering user base is not optimal. Option D forcing upgrades could lead to data loss if the user doesn't plan to upgrade. Option E is not practical to keep legacy versions forever. The optimal approach involves providing ample notice, migration support, and updating the application listing.


質問 # 128
......

有効なNAS-C01テスト解答とSnowflake NAS-C01試験PDF:https://jp.fast2test.com/NAS-C01-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어