Courseiva
Snowflake Architecture →hardMultiple Choice

ARA-C01 Snowflake Architecture Practice Question

An architect is configuring a Snowflake account to use Federated Authentication with Okta as the identity provider (IdP). The requirement is to allow users to authenticate to Snowflake using their Okta credentials and to automatically provision users and roles based on Okta group memberships. Which configuration steps must the architect perform to meet these requirements?

⚠ Common exam trap

Watch out — candidates often confuse authentication protocols with provisioning protocols; SAML handles authentication but not user synchronization, which requires SCIM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure SAML 2.0 in Okta and Snowflake, and enable SCIM provisioning to synchronize users and groups.

The correct configuration involves setting up SAML 2.0 for authentication and SCIM for automatic provisioning. SAML allows Okta to authenticate users, while SCIM synchronizes users and groups, enabling automatic creation and updates of Snowflake users and roles based on Okta group memberships. This dual approach satisfies both authentication and provisioning requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Snowflake to use Okta as an external OAuth server, and use Snowflake's built-in user provisioning.

    Why it's wrong here

    Snowflake does not provide built-in user provisioning based on external OAuth servers. External OAuth is for token-based access, not for federated identity with group-based role assignment. SCIM is the supported protocol for automatic user and group provisioning with Okta.

  • ✗

    Configure SAML 2.0 in Okta and Snowflake, and manually create users and roles in Snowflake to match Okta groups.

    Why it's wrong here

    While SAML 2.0 enables authentication, manual user and role creation does not meet the automatic provisioning requirement. This approach is error-prone and does not scale. SCIM is required for automated synchronization of users and groups from Okta to Snowflake.

  • ✓

    Configure SAML 2.0 in Okta and Snowflake, and enable SCIM provisioning to synchronize users and groups.

    Why this is correct

    SAML 2.0 handles authentication by allowing Okta to act as IdP and Snowflake as SP. SCIM provisioning automates user and role creation and updates based on Okta group assignments. This combination meets both authentication and automatic provisioning requirements without manual intervention.

  • ✗

    Configure OAuth 2.0 in Okta and Snowflake, and use the Snowflake Connector for Okta to sync users.

    Why it's wrong here

    OAuth 2.0 is typically used for API authorization, not for federated user authentication with automatic provisioning. There is no native Snowflake Connector for Okta for user synchronization; SCIM is the standard for provisioning. OAuth alone would not automatically create users or roles based on Okta groups.

About these practice questions

One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.