ARA-C01 Accounts and Security Practice Question
A financial organization needs to ensure that only connections originating from their corporate VPN IP range can access their Snowflake account. Which feature should the architect implement?
⚠ Common exam trap
Candidates often suggest object-level security or user-level settings. They fail to recognize that network-based access restrictions must be applied at the account level via Network Policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a Network Policy at the account level.
Network Policies provide the primary mechanism for controlling access based on IP addresses. By defining an allowed list of CIDR blocks, the architect creates a perimeter defense that prevents unauthorized access from public networks. This is crucial for compliance in highly regulated industries, ensuring that data exposure risks are mitigated by restricting the attack surface to trusted network locations only, effectively blocking any connection attempts outside the defined enterprise perimeter.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MFA for all users.
Why it's wrong here
Multi-Factor Authentication provides an additional layer of identity verification but does not inherently restrict the source IP of the connection request. While highly recommended for security, it fails to address the specific requirement of limiting access to a predefined corporate network boundary or VPN IP range.
- ✗
Configure SCIM provisioning.
Why it's wrong here
System for Cross-domain Identity Management focuses on automating user and group provisioning from an Identity Provider to Snowflake. It handles identity lifecycle management rather than enforcing network-level access controls or IP filtering, making it irrelevant to the specific requirement of restricting connection origins by network range.
- ✓
Apply a Network Policy at the account level.
Why this is correct
Network Policies at the account level are the standard way to enforce IP allowlists and blocklists globally. By applying the policy to the account, Snowflake inspects the source IP of every incoming request against the defined CIDR blocks, ensuring that only traffic from the VPN is permitted.
- ✗
Implement OAuth security integration.
Why it's wrong here
OAuth integrations manage token-based authentication for external applications accessing Snowflake. While they secure the authentication flow, they do not manage network traffic or enforce source IP restrictions. An architect would still need a Network Policy to ensure that the OAuth-authenticated sessions originate from the allowed IP range.
Visual reference
About these practice questions
Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.