ARA-C01 · domain
Accounts and Security
This domain covers identity federation, access control, data sharing governance, and encryption key management in Snowflake. Questions present architectural scenarios — Okta SCIM provisioning, Data Share security properties, Data Exchange access for non-Snowflake partners, and Tri-Secret Secure — and ask you to select the correct component, feature, or benefit rather than recall a syntax detail.
Focused practice
Practice Accounts and Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Accounts and Security
Be able to map a business scenario to the right Snowflake security component: SCIM for identity sync, Data Shares and reader accounts for sharing, Tri-Secret Secure for key control. The critical skill is distinguishing identity provisioning from authorization and knowing which sharing feature fits a partner without a Snowflake account.
SCIM integration with Okta for automated user and group provisioning into Snowflake
Security properties and limitations of Snowflake Data Shares and reader accounts
Data Exchange and reader accounts for sharing with partners lacking Snowflake accounts
Tri-Secret Secure combining a customer-managed key with Snowflake's key hierarchy
Watch out for
Common Accounts and Security exam traps
- ▸Assuming SCIM alone grants privileges; SCIM syncs identities, while role and grant management still govern access.
- ▸Believing a Data Share consumer can see or modify the provider's underlying data or warehouse.
- ▸Confusing Tri-Secret Secure with standard Snowflake-managed encryption or with client-side encryption.
Question index
All Accounts and Security questions (34)
Click any question to see the full explanation, or start a practice session above.
A Snowflake architect is designing a solution where external users need to access specific data in a Snowflake database without having Snowflake accounts. They want to provide read-only access to a few tables and ensure that the external users cannot see any other data. Which Snowflake feature should they use?
Medium2Which of the following describes the correct behavior of a Masking Policy applied to a column that is also referenced in a Row Access Policy?
Hard3A company wants to allow their data analysts to query data in a specific database but prevent them from viewing the underlying table definitions. Which Snowflake feature should the architect recommend?
Easy4A startup is preparing for its first SOC 2 audit. The auditor asks how the company prevents a compromised employee credential from being used from an unknown location while still allowing legitimate travel. The architect has already created a network policy listing the corporate ranges. What should the architect do to apply this control account-wide?
Easy5A healthcare organization uses Snowflake to store sensitive patient data. They need to implement column-level security that allows users with the role 'DOCTOR' to see full patient IDs, while users with the role 'RESEARCHER' should see only the last four digits. The organization wants a centralized, reusable solution that can be applied to multiple columns across different tables. Which Snowflake feature should the architect use?
Hard6A data architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that users from one tenant cannot access data from another tenant, even if they have the same role name. Which Snowflake feature should the architect use to isolate access?
Easy7Which THREE of the following are valid methods for securing data in transit for connections to Snowflake?
Hard8When designing a role hierarchy, what is the primary benefit of granting one role to another role instead of directly to users?
Medium9A security team is designing a Snowflake deployment where they need to centrally manage user access to a set of databases across multiple accounts in an organization. They want to define a set of privileges once and grant them to roles in each account without recreating the roles in every account. Which Snowflake feature should they use?
Medium10Refer to the exhibit. An administrator has executed a 'SHOW GRANTS TO ROLE ANALYST_ROLE' command. Based on the output, what is the significance of the 'grant_option' value for the 'SELECT' privilege on the 'SALES_DATA' table?
Medium11Which object type should an architect use to manage granular access permissions to a specific schema within a database?
Medium12A security architect is designing a Snowflake environment for a company with strict data governance requirements. They need to implement column-level security to mask sensitive data based on the user's role and also track which columns are being accessed by which users. Which two Snowflake features should the architect use to achieve these goals? (Choose two.)
Medium13Which security integration type should an architect use to allow a third-party BI tool to access Snowflake without storing the user's credentials in the tool?
Hard14An architect is designing a security model where a specific service account should only have access to perform SELECT operations on tables within a specific schema. How should this be implemented to adhere to the principle of least privilege?
Hard15Which feature is essential for ensuring that queries on PII (Personally Identifiable Information) columns are masked from unauthorized users?
Hard16A financial organization needs to ensure that only connections originating from their corporate VPN IP range can access their Snowflake account. Which feature should the architect implement?
Medium17An architect needs to audit all queries executed by users in the last 30 days. Which approach is most efficient?
Medium18A Snowflake architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that tenant administrators can manage roles and users within their own database but cannot affect other tenants. Which Snowflake feature should be used to achieve this isolation?
Medium19A financial services firm uses Snowflake with Tri-Secret Secure. They have integrated AWS KMS with Snowflake and manage their own key. During a security audit, the auditor asks how Snowflake ensures that data cannot be decrypted if the customer revokes access to their key. Which statement accurately describes the behavior?
Hard20A security architect is configuring access control for a Snowflake environment. They need to ensure that a service account used by an ETL tool can only access specific tables in a schema and cannot create or drop any objects. The ETL tool connects using key-pair authentication. Which set of privileges should be granted to the service account's role to adhere to the principle of least privilege?
Hard21An architect is tasked with auditing all failed login attempts for a security investigation. Which view should be queried?
Hard22Refer to the exhibit. Based on the security integration definition provided, what is the primary purpose of the 'token_user_field' parameter in this specific configuration?
Hard23A healthcare company stores PHI in a Snowflake database and must ensure that only authorized roles can decrypt the data at rest. They want an additional layer of protection so that even Snowflake cannot access the data without a customer-held key. Which Snowflake feature should the architect implement?
Medium24Which TWO of the following statements correctly describe the behavior of Key Pair Authentication in Snowflake?
Medium25Refer to the exhibit. An architect attempts to connect to Snowflake from 10.0.0.5. Based on the configuration, what will happen?
Medium26A global enterprise is consolidating multiple Snowflake accounts into a single Organization to optimize billing and data sharing. They need to move a large production database from an account in 'aws_us_east_1' to an account in 'azure_west_us'. What is the most efficient architectural approach to achieve this while maintaining data consistency?
Medium27An architect is configuring key-pair authentication for a service account used by an automated ETL process. They need to ensure the private key is stored securely and the public key is assigned to the user. Which two actions should be performed? (Choose two.)
Medium28A security architect at a financial services company needs to ensure that all data stored in Snowflake is encrypted with keys that the company controls and can revoke at any time. They have already enabled Tri-Secret Secure. Which additional configuration is required to meet this requirement?
Medium29An organization wants to centralize user management by integrating Snowflake with their corporate Okta instance using SCIM. Which architectural component facilitates the synchronization of user metadata between Okta and Snowflake?
Hard30Which TWO of the following are true regarding the use of Snowflake Data Shares for security purposes?
Hard31A financial institution uses Snowflake with Tri-Secret Secure backed by a customer-managed key in AWS KMS. The security team wants to rotate the customer-managed key without causing downtime or requiring re-encryption of all data. What is the correct procedure?
Hard32A Snowflake architect is using the Data Exchange to share data with a partner who does not have a Snowflake account. What is the most appropriate feature to use?
Easy33What is the primary benefit of implementing Snowflake Tri-Secret Secure?
Hard34An organization has a Network Policy applied at the Account level to restrict IP ranges. A specific user requires access from a home office IP not in the account range. How should the architect configure this while maintaining the strictest security posture?
MediumOther domains
All ARA-C01 exam domains
Frequently asked questions
- What does the Accounts and Security domain cover on the ARA-C01 exam?
- Be able to map a business scenario to the right Snowflake security component: SCIM for identity sync, Data Shares and reader accounts for sharing, Tri-Secret Secure for key control. The critical skill is distinguishing identity provisioning from authorization and knowing which sharing feature fits a partner without a Snowflake account.
- How many questions are in this domain?
- This page lists all 34 Accounts and Security questions in the ARA-C01 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Accounts and Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.