COF-C03 exam dumps

COF-C03 practice question 149 of 350

SnowPro® Core Certification (COF-C03). Associate level, Snowflake. Free question with the correct answer and a full explanation.

COF-C03 Question 149

Single answerMulti-Factor Authentication (MFA)

A Snowflake administrator is enabling stronger access controls for users who sign in with Snowflake-managed usernames and passwords. The security team requires multi-factor authentication (MFA) for interactive access to Snowsight and the Classic Console, but service accounts used by automated ETL jobs must continue to run without manual prompts. Which approach best meets these requirements?

  1. A

    Configure Snowflake MFA for all human users who authenticate with Snowflake credentials, and keep automated ETL accounts as non-interactive service users using key-pair authentication instead of password-based sign-in.

  2. B

    Enable MFA at the warehouse level so that users are prompted only when they start a virtual warehouse, while ETL jobs can continue running because they do not open the console.

  3. C

    Require MFA for every user in the account, including service accounts that connect through drivers, because Snowflake can cache the second factor for unattended jobs.

  4. D

    Disable password authentication for all users and require OAuth for both administrators and ETL accounts, because OAuth is the only Snowflake authentication method that supports MFA.

Show answer and explanation

Correct answer: A

Explanation

The key requirement is to enforce MFA for human, interactive access while preserving unattended execution for automated jobs. In Snowflake, MFA is relevant for users signing in with Snowflake-managed credentials to interactive interfaces such as Snowsight and the Classic Console. For service accounts and automation, best practice is to avoid password-based interactive authentication and use non-interactive mechanisms such as key-pair authentication. This separates human authentication controls from machine authentication patterns. Snowflake documentation on authentication and security best practices distinguishes between Snowflake MFA for user sign-in and alternative authentication methods such as key-pair authentication, OAuth, and federated SSO. A candidate should recognize that MFA is not applied at the warehouse level and that unattended processes should not be designed around manual second-factor prompts.

  • A. Correct.

    Correct. This is the practical and recommended approach. Snowflake MFA applies to users authenticating with Snowflake-managed username/password credentials for interactive login experiences such as Snowsight and the Classic Console. Automated ETL or service accounts should avoid interactive password-based authentication and instead use a non-interactive method such as key-pair authentication, which is designed for programmatic access without manual MFA prompts.

  • B. Incorrect.

    Incorrect. MFA is not configured at the warehouse level. Warehouses control compute resources, not authentication policy. Authentication and MFA are user sign-in controls, so this option reflects a common misunderstanding between access/authentication controls and compute objects.

  • C. Incorrect.

    Incorrect. Service accounts used by unattended jobs should not depend on manual second-factor challenges. Snowflake does not use MFA in the way described here for unattended driver-based jobs with cached prompts as a general design pattern. The better practice is to use non-interactive authentication such as key-pair authentication for service users.

  • D. Incorrect.

    Incorrect. OAuth can be used for authentication and federation scenarios, but it is not the only Snowflake authentication method that can be part of a secure MFA strategy. Also, disabling password authentication for all users is broader than the requirement and does not specifically address the need to preserve non-interactive ETL execution. Snowflake MFA is supported for Snowflake-managed credentials, and federated SSO solutions can also enforce MFA outside Snowflake.

Timed practice exam

Take a COF-C03 practice test under exam conditions

100 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam