Courseiva
Accounts and Security →mediumMultiple Choice

ARA-C01 Accounts and Security Practice Question

A security architect at a financial services company needs to ensure that all data stored in Snowflake is encrypted with keys that the company controls and can revoke at any time. They have already enabled Tri-Secret Secure. Which additional configuration is required to meet this requirement?

⚠ Common exam trap

The trap here is assuming that enabling Tri-Secret Secure alone provides customer-controlled keys, when in fact it must be paired with a customer-managed key in the cloud KMS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the account to use a customer-managed key (CMK) stored in a supported cloud KMS.

Tri-Secret Secure requires a customer-managed key (CMK) in a supported cloud KMS to give the customer control over encryption keys. By configuring the CMK, the company can revoke access by disabling the key. The other options do not provide key control: rekeying is automatic and not customer-controlled, network policies are unrelated to encryption, and there is no Snowflake privilege to manage encryption keys directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom role with the MANAGE ENCRYPTION KEYS privilege and assign it to the security team.

    Why it's wrong here

    Snowflake does not have a 'MANAGE ENCRYPTION KEYS' privilege. Key management for Tri-Secret Secure is handled through the cloud provider's KMS, not through Snowflake roles. Creating such a role is not possible and would not grant the ability to control or revoke the encryption keys. The correct approach involves configuring a CMK in the cloud KMS.

  • ✗

    Set up a network policy that restricts access to the Snowflake account to only the company's IP ranges.

    Why it's wrong here

    A network policy controls network access based on IP addresses, but it does not affect encryption keys or the ability to revoke them. While network policies are important for security, they do not satisfy the requirement for customer-controlled encryption keys that can be revoked. The scenario specifically asks for key control, not network restriction.

  • ✓

    Configure the account to use a customer-managed key (CMK) stored in a supported cloud KMS.

    Why this is correct

    Tri-Secret Secure combines a Snowflake-managed key with a customer-managed key (CMK) that you create and control in your cloud provider's KMS (AWS KMS, Azure Key Vault, or GCP KMS). By configuring the CMK, the company retains control over the key and can revoke access by disabling or deleting the CMK, which renders the data inaccessible. This is exactly what the scenario requires.

  • ✗

    Enable periodic rekeying of the Snowflake-managed key through the ACCOUNTADMIN role.

    Why it's wrong here

    Periodic rekeying of the Snowflake-managed key is not a feature that provides customer control over encryption keys. Snowflake automatically rotates its internal keys, but this does not give the customer the ability to revoke access. The requirement is for the company to control and revoke keys, which necessitates a customer-managed key, not just rekeying the Snowflake-managed key.

About these practice questions

One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.