Courseiva
Accounts and Security →mediumMultiple Choice

ARA-C01 Accounts and Security Practice Question

A healthcare company stores PHI in a Snowflake database and must ensure that only authorized roles can decrypt the data at rest. They want an additional layer of protection so that even Snowflake cannot access the data without a customer-held key. Which Snowflake feature should the architect implement?

⚠ Common exam trap

Watch out — candidates often confuse access control features like masking policies with encryption key management features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tri-Secret Secure

Tri-Secret Secure is designed to give customers control over a key that is part of the encryption hierarchy. By combining a customer-managed key with Snowflake's key, it ensures that data cannot be decrypted without the customer's key, providing an extra layer of protection. This directly addresses the need for customer-controlled encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network policies with private connectivity

    Why it's wrong here

    Network policies and private connectivity restrict network access, not data encryption. They do not provide an additional encryption key layer. While important for security, they do not satisfy the requirement for customer-controlled encryption keys that prevent Snowflake from accessing data.

  • ✗

    Column-level security with masking policies

    Why it's wrong here

    Masking policies control what data is visible to roles at query time, but they do not affect encryption at rest. The data remains encrypted with Snowflake-managed keys, and Snowflake can still access it. Masking is for access control, not for adding a customer-controlled encryption layer.

  • ✗

    Client-side encryption with Snowflake's ENCRYPT function

    Why it's wrong here

    Client-side encryption using ENCRYPT requires the application to manage keys and encrypt data before loading. While it adds a layer, it does not integrate with Snowflake's key hierarchy and does not prevent Snowflake from accessing data if the key is provided. It also complicates querying and does not meet the requirement for a managed, account-level feature.

  • ✓

    Tri-Secret Secure

    Why this is correct

    Tri-Secret Secure combines a customer-managed key in a cloud KMS with Snowflake's internal key, creating a composite master key. This ensures that data cannot be decrypted without the customer's key, satisfying the requirement that even Snowflake cannot access data without customer consent. It is the correct choice for an additional layer of protection for data at rest.

About these practice questions

This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.