ARA-C01 Accounts and Security Practice Question
A data architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that users from one tenant cannot access data from another tenant, even if they have the same role name. Which Snowflake feature should the architect use to isolate access?
⚠ Common exam trap
The trap here is assuming that database roles or secure views alone can provide complete tenant isolation, when they only provide fine-grained access control within a shared account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Separate accounts per tenant
For strict multi-tenant isolation, using separate Snowflake accounts per tenant is the most robust approach. Each account is a separate security and management domain, ensuring that users, roles, and data are completely isolated. This prevents any possibility of cross-tenant access through shared roles or objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network policies
Why it's wrong here
Network policies restrict access based on IP addresses and do not prevent users from one tenant from accessing another tenant's data if they are within the allowed IP range. They are a network-level control, not a data-level isolation mechanism.
- ✓
Separate accounts per tenant
Why this is correct
Using separate Snowflake accounts for each tenant provides the strongest isolation because accounts are completely independent. There is no shared metadata or access control, so users in one account cannot access data in another. This is a common pattern for multi-tenant architectures requiring strict isolation.
- ✗
Database roles
Why it's wrong here
Database roles are scoped to a specific database and can be granted to account roles, but they do not inherently prevent users from one tenant from accessing another tenant's database if the same account role is granted access to both. They provide finer-grained privileges within a database, not cross-tenant isolation.
- ✗
Secure views
Why it's wrong here
Secure views hide the view definition and underlying data from unauthorized users, but they do not provide tenant isolation by themselves. They are useful for restricting row-level access, but without a mechanism to filter by tenant, they cannot prevent cross-tenant access.
About these practice questions
This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.