問題文
A security engineer is applying threat modeling to a Snowflake account for the first time. The account already enforces private connectivity and has a strict network policy. Which consideration must the model still address?
選択肢
- Only the third-party packages that user-defined functions import.
- Only the encryption of data at rest, since that is the last line of defense.
- Nothing further, because with private connectivity in place there is no route into the account from an untrusted network.
- The paths that carry data out without a network connection from the outside, such as shares, listings, and over-privileged roles inside the account.