Courseiva
Snowflake Architecture →mediumMultiple Choice

ARA-C01 Snowflake Architecture Practice Question

An architect is designing a Snowflake environment for a financial services company that requires the highest level of security. The company must ensure that data is encrypted at rest and in transit, and that encryption keys are managed by the customer, not Snowflake. Which Snowflake feature should the architect implement?

⚠ Common exam trap

The trap here is assuming that client-side encryption or database-level parameters can provide customer-managed keys for Snowflake's internal encryption, when only Tri-Secret Secure does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Tri-Secret Secure with a customer-managed key in AWS KMS or Azure Key Vault.

Tri-Secret Secure is the Snowflake feature that allows customers to use their own encryption key, managed in a cloud KMS, in addition to Snowflake's key. This provides customer control over encryption keys and meets the highest security requirements. The other options either do not provide customer-managed keys for Snowflake's internal encryption or are not valid Snowflake features.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable periodic rekeying of Snowflake-managed keys and store the keys in an external HSM.

    Why it's wrong here

    Snowflake automatically rotates its internal keys, but customers cannot store Snowflake-managed keys in an external HSM. Tri-Secret Secure allows customers to use their own key in a cloud KMS, but it does not involve exporting Snowflake's keys. This option misrepresents how key management works in Snowflake.

  • ✗

    Use the ENCRYPTION parameter in the CREATE DATABASE command to specify a customer key.

    Why it's wrong here

    Snowflake does not support specifying a customer key directly in the CREATE DATABASE command. Encryption is managed at the account level, and customer-managed keys are configured through Tri-Secret Secure. This option is not a valid Snowflake feature.

  • ✓

    Enable Tri-Secret Secure with a customer-managed key in AWS KMS or Azure Key Vault.

    Why this is correct

    Tri-Secret Secure combines a Snowflake-managed key with a customer-managed key to create a composite master key. This ensures that the customer controls one of the keys, and data cannot be decrypted without both. It meets the requirement for customer-managed encryption keys and is available in Business Critical edition and higher.

  • ✗

    Configure Snowflake to use client-side encryption with a customer-provided key before loading data.

    Why it's wrong here

    Client-side encryption encrypts data before it reaches Snowflake, but it does not integrate with Snowflake's encryption at rest. Snowflake would still encrypt the data again with its own keys. This approach does not provide customer-managed keys for Snowflake's internal encryption and would break many Snowflake features that rely on reading the data.

About these practice questions

Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.