Be able to map a business scenario to the right Snowflake security component: SCIM for identity sync, Data Shares and reader accounts for sharing, Tri-Secret Secure for key control. The critical skill is distinguishing identity provisioning from authorization and knowing which sharing feature fits a partner without a Snowflake account.
Start practicing
Accounts and Security — choose a session length
Free · No account required
Domain overview
This domain covers identity federation, access control, data sharing governance, and encryption key management in Snowflake. Questions present architectural scenarios — Okta SCIM provisioning, Data Share security properties, Data Exchange access for non-Snowflake partners, and Tri-Secret Secure — and ask you to select the correct component, feature, or benefit rather than recall a syntax detail.
Exam objectives
SCIM integration with Okta for automated user and group provisioning into Snowflake
Security properties and limitations of Snowflake Data Shares and reader accounts
Data Exchange and reader accounts for sharing with partners lacking Snowflake accounts
Tri-Secret Secure combining a customer-managed key with Snowflake's key hierarchy
Assuming SCIM alone grants privileges; SCIM syncs identities, while role and grant management still govern access.
Believing a Data Share consumer can see or modify the provider's underlying data or warehouse.
Confusing Tri-Secret Secure with standard Snowflake-managed encryption or with client-side encryption.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which TWO of the following statements correctly describe the behavior of Key Pair Authentication in Snowflake?
2An architect is designing a security model where a specific service account should only have access to perform SELECT operations on tables within a specific schema. How should this be implemented to adhere to the principle of least privilege?
3Which THREE of the following are valid methods for securing data in transit for connections to Snowflake?
4An architect needs to audit all queries executed by users in the last 30 days. Which approach is most efficient?
5Which feature is essential for ensuring that queries on PII (Personally Identifiable Information) columns are masked from unauthorized users?
6An organization has a Network Policy applied at the Account level to restrict IP ranges. A specific user requires access from a home office IP not in the account range. How should the architect configure this while maintaining the strictest security posture?
7A Snowflake architect is using the Data Exchange to share data with a partner who does not have a Snowflake account. What is the most appropriate feature to use?
8What is the primary benefit of implementing Snowflake Tri-Secret Secure?
9Which security integration type should an architect use to allow a third-party BI tool to access Snowflake without storing the user's credentials in the tool?
10A financial organization needs to ensure that only connections originating from their corporate VPN IP range can access their Snowflake account. Which feature should the architect implement?
11Refer to the exhibit. An architect attempts to connect to Snowflake from 10.0.0.5. Based on the configuration, what will happen?
12An organization wants to centralize user management by integrating Snowflake with their corporate Okta instance using SCIM. Which architectural component facilitates the synchronization of user metadata between Okta and Snowflake?
13Which object type should an architect use to manage granular access permissions to a specific schema within a database?
14An architect is tasked with auditing all failed login attempts for a security investigation. Which view should be queried?
15When designing a role hierarchy, what is the primary benefit of granting one role to another role instead of directly to users?
16Which TWO of the following are true regarding the use of Snowflake Data Shares for security purposes?
17Which of the following describes the correct behavior of a Masking Policy applied to a column that is also referenced in a Row Access Policy?
18A global enterprise is consolidating multiple Snowflake accounts into a single Organization to optimize billing and data sharing. They need to move a large production database from an account in 'aws_us_east_1' to an account in 'azure_west_us'. What is the most efficient architectural approach to achieve this while maintaining data consistency?
19Refer to the exhibit. Based on the security integration definition provided, what is the primary purpose of the 'token_user_field' parameter in this specific configuration?
20Refer to the exhibit. An administrator has executed a 'SHOW GRANTS TO ROLE ANALYST_ROLE' command. Based on the output, what is the significance of the 'grant_option' value for the 'SELECT' privilege on the 'SALES_DATA' table?
21A security team is designing a Snowflake deployment where they need to centrally manage user access to a set of databases across multiple accounts in an organization. They want to define a set of privileges once and grant them to roles in each account without recreating the roles in every account. Which Snowflake feature should they use?
22A financial services firm uses Snowflake with Tri-Secret Secure. They have integrated AWS KMS with Snowflake and manage their own key. During a security audit, the auditor asks how Snowflake ensures that data cannot be decrypted if the customer revokes access to their key. Which statement accurately describes the behavior?
23A Snowflake architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that tenant administrators can manage roles and users within their own database but cannot affect other tenants. Which Snowflake feature should be used to achieve this isolation?
24A healthcare company stores PHI in a Snowflake database and must ensure that only authorized roles can decrypt the data at rest. They want an additional layer of protection so that even Snowflake cannot access the data without a customer-held key. Which Snowflake feature should the architect implement?
25A security architect at a financial services company needs to ensure that all data stored in Snowflake is encrypted with keys that the company controls and can revoke at any time. They have already enabled Tri-Secret Secure. Which additional configuration is required to meet this requirement?
26A healthcare organization uses Snowflake to store sensitive patient data. They need to implement column-level security that allows users with the role 'DOCTOR' to see full patient IDs, while users with the role 'RESEARCHER' should see only the last four digits. The organization wants a centralized, reusable solution that can be applied to multiple columns across different tables. Which Snowflake feature should the architect use?
27A financial institution uses Snowflake with Tri-Secret Secure backed by a customer-managed key in AWS KMS. The security team wants to rotate the customer-managed key without causing downtime or requiring re-encryption of all data. What is the correct procedure?
28A Snowflake architect is designing a solution where external users need to access specific data in a Snowflake database without having Snowflake accounts. They want to provide read-only access to a few tables and ensure that the external users cannot see any other data. Which Snowflake feature should they use?
29A data architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that users from one tenant cannot access data from another tenant, even if they have the same role name. Which Snowflake feature should the architect use to isolate access?
30A security architect is configuring access control for a Snowflake environment. They need to ensure that a service account used by an ETL tool can only access specific tables in a schema and cannot create or drop any objects. The ETL tool connects using key-pair authentication. Which set of privileges should be granted to the service account's role to adhere to the principle of least privilege?
31An architect is configuring key-pair authentication for a service account used by an automated ETL process. They need to ensure the private key is stored securely and the public key is assigned to the user. Which two actions should be performed? (Choose two.)
32A company wants to allow their data analysts to query data in a specific database but prevent them from viewing the underlying table definitions. Which Snowflake feature should the architect recommend?
33A startup is preparing for its first SOC 2 audit. The auditor asks how the company prevents a compromised employee credential from being used from an unknown location while still allowing legitimate travel. The architect has already created a network policy listing the corporate ranges. What should the architect do to apply this control account-wide?
34A security architect is designing a Snowflake environment for a company with strict data governance requirements. They need to implement column-level security to mask sensitive data based on the user's role and also track which columns are being accessed by which users. Which two Snowflake features should the architect use to achieve these goals? (Choose two.)
Be able to map a business scenario to the right Snowflake security component: SCIM for identity sync, Data Shares and reader accounts for sharing, Tri-Secret Secure for key control. The critical skill is distinguishing identity provisioning from authorization and knowing which sharing feature fits a partner without a Snowflake account.
The Courseiva ARA-C01 question bank contains 34 questions in the Accounts and Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Accounts and Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included