問題文
Which Snowflake-specific condition should a threat model treat as a high-priority finding because it turns a single stolen credential into account-wide exposure?
選択肢
- A database whose data retention time is set to the account default, which leaves historical versions of every table reachable to any role that can query it.
- A person-type user who has enrolled in multi-factor authentication but has not signed in for several weeks, because the dormant enrollment means the second factor has not been exercised recently and may no longer be under that person's control.
- A service user whose role has been granted privileges far beyond the job it performs.
- A table protected by a masking policy whose exempted role list includes two roles, so both of those roles see the raw values whenever either credential is used.