Courseiva

ARA-C01 · topic practice

Accounts and Security practice questions

This domain covers identity federation, access control, data sharing governance, and encryption key management in Snowflake. Questions present architectural scenarios — Okta SCIM provisioning, Data Share security properties, Data Exchange access for non-Snowflake partners, and Tri-Secret Secure — and ask you to select the correct component, feature, or benefit rather than recall a syntax detail.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Accounts and Security

What the exam tests

What to know about Accounts and Security

Be able to map a business scenario to the right Snowflake security component: SCIM for identity sync, Data Shares and reader accounts for sharing, Tri-Secret Secure for key control. The critical skill is distinguishing identity provisioning from authorization and knowing which sharing feature fits a partner without a Snowflake account.

SCIM integration with Okta for automated user and group provisioning into Snowflake

Security properties and limitations of Snowflake Data Shares and reader accounts

Data Exchange and reader accounts for sharing with partners lacking Snowflake accounts

Tri-Secret Secure combining a customer-managed key with Snowflake's key hierarchy

Watch out for

Common Accounts and Security exam traps

  • ▸Assuming SCIM alone grants privileges; SCIM syncs identities, while role and grant management still govern access.
  • ▸Believing a Data Share consumer can see or modify the provider's underlying data or warehouse.
  • ▸Confusing Tri-Secret Secure with standard Snowflake-managed encryption or with client-side encryption.

Practice set

Accounts and Security questions

20 questions · select your answer, then reveal the explanation

An organization requires that all users logging into Snowflake from outside the corporate network must provide a second authentication factor. How can an architect enforce this requirement globally?

A security architect needs to ensure that data access logs are immutable and available for auditing for at least one year. Which feature should be used to achieve this compliance requirement?

An architect is configuring SCIM for user provisioning. Why is the `provisioner_role` crucial in this setup?

A security architect wants to prevent users from creating external stages with embedded credentials. What is the most effective approach?

Which TWO actions should an architect take to ensure that data stored in Snowflake is protected from unauthorized access at rest?

A user reports they can see data in a table, but their assigned role does not have explicit SELECT permissions. What is the most likely cause?

An architect is asked to ensure that an application service account does not use a password. What is the recommended strategy for machine authentication?

Which TWO statements are true regarding Snowflake's SCIM implementation with external Identity Providers?

Refer to the exhibit. Based on the commands shown, what is the resulting privilege structure for the user 'jsmith'?

Exhibit

GRANT ROLE analyst TO ROLE senior_analyst;
GRANT ROLE senior_analyst TO USER jsmith;

An architect needs to implement Key-Pair authentication for a service account used by an ETL tool. What is a requirement for the public key when configuring the user in Snowflake?

An Architect is designing a secure connection between a corporate VPC and Snowflake using AWS PrivateLink. Which TWO components are required to ensure the connection is private and secure?

When configuring Account Replication, which object type is NOT automatically replicated from the primary to the secondary account?

Which TWO best practices should be followed when implementing Multi-Factor Authentication (MFA) for a Snowflake account?

Refer to the exhibit. If a user with the role 'DEVELOPER' queries a column protected by this policy, what will they see?

Exhibit

CREATE OR REPLACE MASKING POLICY email_mask AS (val string)
  RETURNS string ->
  CASE
    WHEN current_role() IN ('ANALYST') THEN val
    ELSE '*********'
  END;

An architect is considering the use of Secondary Roles in a user session. Which TWO statements accurately describe the behavior of Secondary Roles?

Refer to the exhibit. What is the primary purpose of this row access policy when applied to a sales table?

Exhibit

CREATE OR REPLACE ROW ACCESS POLICY region_policy
  AS (sales_region string) RETURNS BOOLEAN ->
  EXISTS (
    SELECT 1 FROM sales_managers
    WHERE manager_role = CURRENT_ROLE()
    AND region = sales_region
  );

In a Snowflake organization with multiple accounts, what is the unique capability of the ORGADMIN role?

Which TWO session parameters can be adjusted to control user session timeouts and security in Snowflake?

An architect is designing an authentication strategy for a large organization. Which TWO options are required to enable Key-Pair authentication for a service user?

Which THREE actions are necessary to implement a secure, multi-layered data access model using row-level security and column-level masking?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Accounts and Security sessions

Start a Accounts and Security only practice session

Every question in these sessions is drawn from the Accounts and Security domain — nothing else.

Related practice questions

Related ARA-C01 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ARA-C01 exam test about Accounts and Security?
Be able to map a business scenario to the right Snowflake security component: SCIM for identity sync, Data Shares and reader accounts for sharing, Tri-Secret Secure for key control. The critical skill is distinguishing identity provisioning from authorization and knowing which sharing feature fits a partner without a Snowflake account.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Accounts and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Accounts and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ARA-C01 topics?
Use the topic links above to move to related areas, or go back to the ARA-C01 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ARA-C01 exam covers. They are not copied from any real exam or dump site.