Courseiva
Accounts and Security →mediumMultiple Choice

ARA-C01 Accounts and Security Practice Question

A financial organization needs to ensure that only connections originating from their corporate VPN IP range can access their Snowflake account. Which feature should the architect implement?

⚠ Common exam trap

Candidates often suggest object-level security or user-level settings. They fail to recognize that network-based access restrictions must be applied at the account level via Network Policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a Network Policy at the account level.

Network Policies provide the primary mechanism for controlling access based on IP addresses. By defining an allowed list of CIDR blocks, the architect creates a perimeter defense that prevents unauthorized access from public networks. This is crucial for compliance in highly regulated industries, ensuring that data exposure risks are mitigated by restricting the attack surface to trusted network locations only, effectively blocking any connection attempts outside the defined enterprise perimeter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MFA for all users.

    Why it's wrong here

    Multi-Factor Authentication provides an additional layer of identity verification but does not inherently restrict the source IP of the connection request. While highly recommended for security, it fails to address the specific requirement of limiting access to a predefined corporate network boundary or VPN IP range.

  • ✗

    Configure SCIM provisioning.

    Why it's wrong here

    System for Cross-domain Identity Management focuses on automating user and group provisioning from an Identity Provider to Snowflake. It handles identity lifecycle management rather than enforcing network-level access controls or IP filtering, making it irrelevant to the specific requirement of restricting connection origins by network range.

  • ✓

    Apply a Network Policy at the account level.

    Why this is correct

    Network Policies at the account level are the standard way to enforce IP allowlists and blocklists globally. By applying the policy to the account, Snowflake inspects the source IP of every incoming request against the defined CIDR blocks, ensuring that only traffic from the VPN is permitted.

  • ✗

    Implement OAuth security integration.

    Why it's wrong here

    OAuth integrations manage token-based authentication for external applications accessing Snowflake. While they secure the authentication flow, they do not manage network traffic or enforce source IP restrictions. An architect would still need a Network Policy to ensure that the OAuth-authenticated sessions originate from the allowed IP range.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.