ARA-C01 Snowflake Architecture Practice Question
A financial services company runs a Snowflake account in the AWS us-east-1 region. The security team mandates that all data at rest must be encrypted with customer-managed keys, and they require an audit trail of key usage. Which Snowflake feature should the architect implement to meet these requirements with minimal administrative overhead?
⚠ Common exam trap
The trap here is assuming that Snowflake's default encryption or client-side encryption satisfies customer-managed key requirements, when only Tri-Secret Secure provides that level of control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Tri-Secret Secure with a customer-managed key in AWS KMS.
Tri-Secret Secure is the only Snowflake feature that allows customers to use their own AWS KMS key in combination with a Snowflake-managed key, providing customer-managed encryption at rest with an audit trail through AWS CloudTrail. The other options either do not provide customer-managed keys or do not meet the audit trail requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable client-side encryption using the Snowflake JDBC driver's encryption capabilities.
Why it's wrong here
Client-side encryption via the JDBC driver is not a Snowflake feature for data at rest; it would require custom application logic and does not provide centralized key management or audit trails. It also would not encrypt data loaded via other tools like Snowpipe or the SnowSQL CLI, leaving gaps in the encryption coverage.
- ✗
Implement a Snowflake External Function that encrypts data before writing to internal stages.
Why it's wrong here
External Functions call external APIs and are not designed for encrypting data at rest. They would add latency and complexity, and data would still be stored in Snowflake's internal storage encrypted with Snowflake-managed keys. This does not provide customer-managed keys or an audit trail for data at rest.
- ✗
Use Snowflake's default encryption with AES-256 and enable periodic key rotation.
Why it's wrong here
Snowflake's default encryption uses Snowflake-managed keys, not customer-managed keys. While key rotation is automatic, the customer does not control the keys and there is no separate audit trail of key usage. This fails the mandate for customer-managed keys and an audit trail of key usage.
- ✓
Configure Tri-Secret Secure with a customer-managed key in AWS KMS.
Why this is correct
Tri-Secret Secure combines a Snowflake-managed key with a customer-managed key in AWS KMS, ensuring that data cannot be decrypted without both keys. It provides an audit trail of key usage via AWS CloudTrail and meets the requirement for customer-managed encryption at rest with minimal overhead because Snowflake integrates directly with KMS.
About these practice questions
Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.