ARA-C01 Accounts and Security Practice Question
A healthcare company stores PHI in a Snowflake database and must ensure that only authorized roles can decrypt the data at rest. They want an additional layer of protection so that even Snowflake cannot access the data without a customer-held key. Which Snowflake feature should the architect implement?
⚠ Common exam trap
Watch out — candidates often confuse access control features like masking policies with encryption key management features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tri-Secret Secure
Tri-Secret Secure is designed to give customers control over a key that is part of the encryption hierarchy. By combining a customer-managed key with Snowflake's key, it ensures that data cannot be decrypted without the customer's key, providing an extra layer of protection. This directly addresses the need for customer-controlled encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network policies with private connectivity
Why it's wrong here
Network policies and private connectivity restrict network access, not data encryption. They do not provide an additional encryption key layer. While important for security, they do not satisfy the requirement for customer-controlled encryption keys that prevent Snowflake from accessing data.
- ✗
Column-level security with masking policies
Why it's wrong here
Masking policies control what data is visible to roles at query time, but they do not affect encryption at rest. The data remains encrypted with Snowflake-managed keys, and Snowflake can still access it. Masking is for access control, not for adding a customer-controlled encryption layer.
- ✗
Client-side encryption with Snowflake's ENCRYPT function
Why it's wrong here
Client-side encryption using ENCRYPT requires the application to manage keys and encrypt data before loading. While it adds a layer, it does not integrate with Snowflake's key hierarchy and does not prevent Snowflake from accessing data if the key is provided. It also complicates querying and does not meet the requirement for a managed, account-level feature.
- ✓
Tri-Secret Secure
Why this is correct
Tri-Secret Secure combines a customer-managed key in a cloud KMS with Snowflake's internal key, creating a composite master key. This ensures that data cannot be decrypted without the customer's key, satisfying the requirement that even Snowflake cannot access data without customer consent. It is the correct choice for an additional layer of protection for data at rest.
About these practice questions
This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.