Often shipped modules need additional runtime configuration options, which are usually done via .conf files in /etc/modprobe.d
The kernel snap should be enhanced to allow to ship these files and additionally i think the kernel-module-control interface should grow read/write access for this directory …
In terms of the security policy, kernel-module-control already allows inserting modules with arbitrary parameters so allowing write access to /etc/modprobe.d seems fine.