ARA-C01 Accounts and Security Practice Question
Exhibit
{
"name": "MY_OAUTH_INT",
"type": "EXTERNAL_OAUTH",
"enabled": true,
"issuer": "https://sts.windows.net/tenant-id/",
"jks_url": "https://login.microsoftonline.com/common/discovery/keys",
"audience_list": ["https://analysis.windows.net/powerbi/connector/snowflake"],
"token_user_field": "upn",
"scope_mapping_attribute": "scp"
}Refer to the exhibit. Based on the security integration definition provided, what is the primary purpose of the 'token_user_field' parameter in this specific configuration?
⚠ Common exam trap
Candidates often confuse the 'token_user_field' with the 'issuer' or 'client_id', failing to understand that this field specifically maps the identity provider's claim to the Snowflake login_name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It defines the field in the OAuth token that Snowflake uses to match against the login_name of a Snowflake user.
External OAuth allows third-party identity providers like Microsoft Entra ID to authorize access to Snowflake. The `token_user_field` is a critical configuration parameter that tells Snowflake which claim in the incoming JWT (JSON Web Token) should be used to identify the Snowflake user. In this exhibit, setting it to 'upn' ensures the user identity is mapped correctly from the Microsoft environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It specifies the Snowflake role that the user will be assigned when they connect via the OAuth provider.
Why it's wrong here
The role assignment in External OAuth is typically handled by the `scope_mapping_attribute` or the `EXTERNAL_OAUTH_ANY_ROLE_MODE` parameter, not the `token_user_field`. The `token_user_field` is strictly used for user identification and mapping, rather than determining the privileges or roles the user assumes during their session.
- ✓
It defines the field in the OAuth token that Snowflake uses to match against the login_name of a Snowflake user.
Why this is correct
The `token_user_field` parameter identifies the claim within the JWT, such as 'upn' or 'email', that Snowflake will extract to find a matching user record. If the value in this field does not match a user's `login_name` in Snowflake, the authentication attempt will fail because the identity cannot be resolved.
- ✗
It identifies the public key used to verify the digital signature of the incoming OAuth access token.
Why it's wrong here
Verification of the digital signature is performed using the public keys retrieved from the URL specified in the `jks_url` parameter. The `token_user_field` is only evaluated after the token signature has been successfully validated, serving as a secondary step to link the validated token to a specific Snowflake user.
- ✗
It determines the audience for which the token was issued to prevent token substitution attacks.
Why it's wrong here
The audience validation is handled by the `audience_list` parameter, which contains the expected values for the 'aud' claim in the JWT. This ensures that the token was intended for the Snowflake service, whereas the `token_user_field` specifically identifies the subject or user who is attempting to authenticate.
About these practice questions
One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.