Courseiva
Accounts and Security →hardMultiple Choice

ARA-C01 Accounts and Security Practice Question

A financial institution uses Snowflake with Tri-Secret Secure backed by a customer-managed key in AWS KMS. The security team wants to rotate the customer-managed key without causing downtime or requiring re-encryption of all data. What is the correct procedure?

⚠ Common exam trap

The trap here is thinking that rotating the customer-managed key requires re-encrypting all data or that Snowflake automatically re-encrypts everything when the key changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rotate the customer-managed key by creating a new key version in AWS KMS; Snowflake will automatically use the new version for new data and continue to decrypt old data using the old version.

Tri-Secret Secure uses a customer-managed key in AWS KMS to add an extra layer of encryption. Key rotation in KMS is achieved by creating a new key version. Snowflake can use the new version for new data while still decrypting old data with previous versions, because KMS retains all versions. This allows seamless rotation without downtime or data re-encryption. The other options involve incorrect commands or unnecessary re-encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new customer-managed key in AWS KMS, update the Snowflake account to use the new key, and Snowflake will automatically re-encrypt all data in the background.

    Why it's wrong here

    Snowflake does not automatically re-encrypt all data when the customer-managed key is changed. Tri-Secret Secure uses the customer-managed key to protect the Snowflake-managed key hierarchy, but changing the key only affects future key wrapping operations. Existing data remains encrypted with the old key until it is re-encrypted, which is not automatic and would require data rewrites.

  • ✗

    Disable Tri-Secret Secure, rotate the key, and then re-enable Tri-Secret Secure; this will automatically re-wrap all data encryption keys with the new key.

    Why it's wrong here

    Disabling Tri-Secret Secure removes the customer-managed key from the key hierarchy, reverting to Snowflake-managed keys. Re-enabling it would require re-establishing the key hierarchy and does not automatically re-wrap all data encryption keys. This process would cause downtime and is not the correct method for key rotation.

  • ✗

    Manually re-encrypt all data by running ALTER ACCOUNT SET ENCRYPTION_KEY, which triggers a full re-encryption process.

    Why it's wrong here

    There is no ALTER ACCOUNT SET ENCRYPTION_KEY command in Snowflake. Tri-Secret Secure configuration is done through the Snowflake UI or API, and it does not support manual re-encryption commands. The key hierarchy is managed internally, and you cannot force a re-encryption of all data with a simple SQL command.

  • ✓

    Rotate the customer-managed key by creating a new key version in AWS KMS; Snowflake will automatically use the new version for new data and continue to decrypt old data using the old version.

    Why this is correct

    AWS KMS supports key rotation by creating new key versions under the same customer-managed key. Snowflake Tri-Secret Secure uses the KMS key to wrap the Snowflake-managed key. When a new key version is created, Snowflake can use it for new wrapping operations while still decrypting existing wrapped keys with the old version, as KMS retains all versions. This enables seamless rotation without downtime or re-encryption of data.

About these practice questions

This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.