ARA-C01 Data Engineering Practice Question
An organization requires that all data ingested into Snowflake must be encrypted at rest with customer-managed keys. Which feature enables this security requirement for data stored in Snowflake?
⚠ Common exam trap
Candidates frequently confuse Tri-Secret Secure with general data encryption at rest or Time Travel, failing to recognize it as the specific feature for customer-managed key (CMK) integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tri-Secret Secure
Tri-Secret Secure uses a combination of a Snowflake-managed key and a customer-managed key stored in a cloud provider's Key Management Service (KMS). This provides an additional layer of security, ensuring that data is encrypted using a key outside of Snowflake's direct control. This is vital for highly regulated industries like finance or healthcare that must maintain strict data governance and compliance over their encryption keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Masking
Why it's wrong here
Data Masking is a column-level security feature used to obfuscate sensitive data in result sets for specific users or roles. It does not provide encryption-at-rest capabilities or allow for the integration of customer-managed keys for the underlying data stored in the persistent storage layer.
- ✓
Tri-Secret Secure
Why this is correct
Tri-Secret Secure combines a Snowflake-managed key and a customer-managed key (stored in AWS KMS, Azure Key Vault, or Google Cloud KMS) to encrypt the data. This meets the requirement for customer-managed keys, giving the client ultimate control over the data's encryption state and access policies.
- ✗
Row-Level Security
Why it's wrong here
Row-Level Security (RLS) is used to restrict which rows a user can see based on specific policy functions. It controls data visibility at the query execution level, not the storage level, and does not involve key management or encryption mechanisms for the physical data files.
- ✗
Access Control Lists (ACLs)
Why it's wrong here
Access Control Lists are a networking or system-level method for defining permissions. While important for security, they do not provide data encryption at rest or the ability to manage encryption keys. They are purely concerned with the authorization of users and services to access specific resources.
About these practice questions
One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.