Courseiva
Accounts and Security →mediumMultiple Choice

ARA-C01 Accounts and Security Practice Question

An architect needs to audit all queries executed by users in the last 30 days. Which approach is most efficient?

⚠ Common exam trap

Candidates frequently mistake INFORMATION_SCHEMA for ACCOUNT_USAGE views, forgetting that INFORMATION_SCHEMA only retains query history for the last 7 days.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query the SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY view.

The SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY view is the standard interface for auditing executed queries. It provides a comprehensive historical record of all SQL commands, their execution times, and the users who ran them. This is the most efficient and scalable method for auditing compared to manual logs or local metadata, as it is maintained and optimized by Snowflake, ensuring minimal impact on production query performance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Query the INFORMATION_SCHEMA.QUERY_HISTORY view.

    Why it's wrong here

    The INFORMATION_SCHEMA.QUERY_HISTORY view only contains data for the last 7 days. Since the requirement is to audit data for the last 30 days, this view is insufficient. The ACCOUNT_USAGE schema is necessary for longer-term auditing as it provides a significantly larger data retention period and account-wide historical visibility.

  • ✓

    Query the SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY view.

    Why this is correct

    The ACCOUNT_USAGE.QUERY_HISTORY view contains query metadata for up to 365 days, making it the correct choice for a 30-day lookback requirement. It is designed for audit and analysis purposes, providing a centralized and consistent view of all query activity across the account without requiring the maintenance of custom logging solutions.

  • ✗

    Enable query logging in the user profile.

    Why it's wrong here

    There is no user-level query logging feature that can be enabled. Query history is automatically captured at the system level and surfaced through the QUERY_HISTORY views. Manually attempting to track queries through client-side logs is inefficient and prone to gaps, as it would not capture queries executed through other tools or interfaces.

  • ✗

    Use the GET_QUERY_HISTORY() function.

    Why it's wrong here

    The GET_QUERY_HISTORY() function is designed for ad-hoc, session-specific queries or limited timeframes. It is not the most efficient tool for analyzing a large-scale 30-day audit, as it requires programmatic execution and pagination. The ACCOUNT_USAGE view provides a persistent, queryable table structure that is far superior for broad auditing and long-term analysis.

About these practice questions

This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.