Courseiva
Accounts and Security →hardMultiple Choice

ARA-C01 Accounts and Security Practice Question

An organization wants to centralize user management by integrating Snowflake with their corporate Okta instance using SCIM. Which architectural component facilitates the synchronization of user metadata between Okta and Snowflake?

⚠ Common exam trap

Test-takers frequently confuse manual user creation scripts or OAuth configurations with SCIM when asked about automated user metadata synchronization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Snowflake SCIM provisioning integration.

SCIM (System for Cross-domain Identity Management) is an open standard that allows for the automation of user provisioning. By using the Snowflake SCIM integration, the architect ensures that user additions, updates, and deletions in Okta are automatically reflected in Snowflake. This eliminates manual administrative overhead and reduces the risk of orphaned accounts or stale permissions, which are common security vulnerabilities in large organizations where employee turnover is high and manual tracking is prone to errors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Snowflake Data Share.

    Why it's wrong here

    Data Shares are designed for secure, read-only access to database objects across different Snowflake accounts. They do not manage user identities, provisioning, or synchronization workflows, and have no capability to interface with external identity providers like Okta for the purpose of managing user access or credentials.

  • ✓

    Snowflake SCIM provisioning integration.

    Why this is correct

    The SCIM provisioning integration acts as the bridge between the identity provider and Snowflake. It exposes a REST API endpoint that Okta calls to push user and group changes, ensuring that identity information remains synchronized without requiring manual intervention by the Snowflake administrator for each new joiner or leaver.

  • ✗

    External OAuth security integration.

    Why it's wrong here

    External OAuth is used to manage authentication and authorization using tokens issued by an identity provider, not for synchronizing user metadata. While it works alongside SCIM, it handles the login process and permission scoping rather than the actual creation and maintenance of user objects within the database system.

  • ✗

    Snowflake Native App.

    Why it's wrong here

    Native Apps are packaged applications that run within Snowflake. They are intended for extending platform functionality or providing specific business logic to end-users. They are not part of the core infrastructure for identity lifecycle management or synchronization, and using them for SCIM tasks would be architecturally incorrect and inefficient.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.