COF-C03 Account Management and Data Governance Practice Question
A security administrator needs to ensure that all data loaded into Snowflake is encrypted using a customer-managed key. Which feature should be configured?
⚠ Common exam trap
Candidates often confuse Tri-Secret Secure with standard encryption-at-rest or Time Travel features, failing to recognize it specifically as the customer-managed key integration feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tri-Secret Secure.
Tri-Secret Secure is the Snowflake feature that enables customers to maintain control over their data encryption keys. By combining a customer-managed key with a Snowflake-managed key, the organization ensures that data is encrypted at the storage layer while allowing for key rotation and revocation. This is a vital component for high-compliance industries requiring total control over the data lifecycle and access to encrypted storage buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Snowflake-managed keys with automatic rotation.
Why it's wrong here
Snowflake-managed keys handle the rotation process automatically and securely, but they do not provide the customer with control over the key itself. For requirements demanding customer-managed keys, this solution is insufficient as it does not allow the customer to revoke access independently of Snowflake's infrastructure.
- ✓
Tri-Secret Secure.
Why this is correct
Tri-Secret Secure combines a customer-managed key (stored in their cloud provider's key management service) with a Snowflake-managed key. This setup provides an additional layer of security and auditability, ensuring that Snowflake cannot decrypt customer data without access to the customer-provided key material.
- ✗
Always Encrypted feature.
Why it's wrong here
Always Encrypted is not a native Snowflake feature name. While client-side encryption can be implemented before loading data, Snowflake relies on Tri-Secret Secure at the platform level to manage encryption keys. Using third-party tools for pre-encryption adds significant latency and overhead compared to native platform features.
- ✗
Column-Level Security encryption.
Why it's wrong here
Column-Level Security handles the masking and visibility of data within queries, not the underlying encryption at rest. While it is an excellent governance tool, it does not fulfill the requirement of managing the master encryption keys that protect the data stored in the underlying cloud storage.
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.