Courseiva
Data Engineering →mediumMultiple Choice

ARA-C01 Data Engineering Practice Question

An organization requires that all data ingested into Snowflake must be encrypted at rest with customer-managed keys. Which feature enables this security requirement for data stored in Snowflake?

⚠ Common exam trap

Candidates frequently confuse Tri-Secret Secure with general data encryption at rest or Time Travel, failing to recognize it as the specific feature for customer-managed key (CMK) integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tri-Secret Secure

Tri-Secret Secure uses a combination of a Snowflake-managed key and a customer-managed key stored in a cloud provider's Key Management Service (KMS). This provides an additional layer of security, ensuring that data is encrypted using a key outside of Snowflake's direct control. This is vital for highly regulated industries like finance or healthcare that must maintain strict data governance and compliance over their encryption keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data Masking

    Why it's wrong here

    Data Masking is a column-level security feature used to obfuscate sensitive data in result sets for specific users or roles. It does not provide encryption-at-rest capabilities or allow for the integration of customer-managed keys for the underlying data stored in the persistent storage layer.

  • ✓

    Tri-Secret Secure

    Why this is correct

    Tri-Secret Secure combines a Snowflake-managed key and a customer-managed key (stored in AWS KMS, Azure Key Vault, or Google Cloud KMS) to encrypt the data. This meets the requirement for customer-managed keys, giving the client ultimate control over the data's encryption state and access policies.

  • ✗

    Row-Level Security

    Why it's wrong here

    Row-Level Security (RLS) is used to restrict which rows a user can see based on specific policy functions. It controls data visibility at the query execution level, not the storage level, and does not involve key management or encryption mechanisms for the physical data files.

  • ✗

    Access Control Lists (ACLs)

    Why it's wrong here

    Access Control Lists are a networking or system-level method for defining permissions. While important for security, they do not provide data encryption at rest or the ability to manage encryption keys. They are purely concerned with the authorization of users and services to access specific resources.

About these practice questions

One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.