Courseiva

COF-C03 Practice Question: Snowflake AI Data Cloud Features and Architecture

A company needs to ensure that data stored in a Snowflake table is encrypted at rest with keys that the company manages and rotates independently. Which Snowflake feature should be configured?

⚠ Common exam trap

The trap here is assuming that Snowflake's automatic key rotation or client-side encryption meets the requirement for customer-managed keys with independent rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tri-Secret Secure with customer-managed keys.

Tri-Secret Secure allows customers to add their own key from a cloud provider's KMS to Snowflake's encryption hierarchy. The customer can rotate or revoke their key at any time, giving them control over data access. This satisfies the need for customer-managed keys with independent rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tri-Secret Secure with customer-managed keys.

    Why this is correct

    Tri-Secret Secure combines a Snowflake-managed key with a customer-managed key in a composite master key. This allows the customer to control key rotation and revoke access by removing their key. It meets the requirement for customer-managed encryption at rest with independent rotation, as the customer manages their key in a cloud provider's KMS.

  • ✗

    Periodic rekeying of Snowflake-managed keys.

    Why it's wrong here

    Snowflake automatically rotates its internal keys, but the customer does not manage or control these keys. The requirement specifies customer-managed keys with independent rotation. Periodic rekeying by Snowflake does not provide the customer with control over the keys or the ability to rotate them independently. This option does not satisfy the customer-managed key requirement.

  • ✗

    Client-side encryption before loading data into Snowflake.

    Why it's wrong here

    Client-side encryption encrypts data before it reaches Snowflake, but then Snowflake cannot decrypt it for processing unless the customer manages decryption outside. This approach prevents Snowflake from performing many operations and is not the intended use of Snowflake's encryption features. It does not provide encryption at rest within Snowflake managed by the customer through Snowflake's mechanisms.

  • ✗

    Enabling AES-256 encryption on the virtual warehouse.

    Why it's wrong here

    Virtual warehouses do not store data persistently; they are compute resources. Encryption at rest applies to storage, not compute. Configuring encryption on a warehouse is not a Snowflake feature for data-at-rest encryption. This option misunderstands where encryption at rest is applied and how it is managed.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.