COF-C03 exam dumps

COF-C03 practice question 218 of 350

SnowPro® Core Certification (COF-C03). Associate level, Snowflake. Free question with the correct answer and a full explanation.

COF-C03 Question 218

Single answerServer-side encryption

A financial services company is migrating regulated data to Snowflake. Its security team requires that all data stored by Snowflake remain encrypted at rest, and they want to reduce operational overhead for key rotation and storage. During a design review, an architect is asked which statement best describes how Snowflake server-side encryption meets this requirement by default.

  1. A

    Snowflake encrypts customer data at rest by default using a hierarchical key model, where key management and rotation are handled by Snowflake.

  2. B

    Snowflake requires customers to manually encrypt all staged and table data before loading it, because server-side encryption applies only to query results.

  3. C

    Snowflake stores data unencrypted in internal stages unless Tri-Secret Secure is enabled, because standard accounts do not support encryption at rest.

  4. D

    Snowflake uses a single account-level encryption key for all data files, and customers must rotate that key on a fixed schedule to remain compliant.

Show answer and explanation

Correct answer: A

Explanation

Snowflake provides server-side encryption by default for data at rest, using a hierarchical key model designed to secure stored data while reducing administrative burden on customers. This is the best answer for a scenario where the organization wants strong encryption controls without taking on manual key lifecycle tasks. Snowflake documentation describes encryption of data in transit and at rest as part of the platform's core security model, with Snowflake-managed key handling and rotation for standard deployments. Features such as Tri-Secret Secure may be used when organizations need additional control involving a customer-managed key, but they are not required to achieve default server-side encryption at rest.

  • A. Correct.

    Correct. Snowflake encrypts data at rest by default and uses a hierarchical key model for server-side encryption. Snowflake manages the encryption keys and key rotation, which aligns with the requirement to protect stored data while minimizing customer operational overhead.

  • B. Incorrect.

    Incorrect. This reflects a common misunderstanding between client-side and server-side encryption. Snowflake already provides server-side encryption for data at rest by default, including data stored in Snowflake-managed storage. Customers do not need to manually encrypt all data before loading it in order to get at-rest protection.

  • C. Incorrect.

    Incorrect. Internal stages and other data stored by Snowflake are encrypted at rest by default. Tri-Secret Secure is an additional feature for customers with stricter key control requirements, but it is not required for standard encryption at rest.

  • D. Incorrect.

    Incorrect. Snowflake does not rely on a single account-level key for all stored data in the simple manner described here. Instead, it uses a hierarchy of keys to protect data, and Snowflake manages rotation. The option is plausible because many systems expose a single customer-managed key, but that does not accurately describe Snowflake's default server-side encryption model.

Timed practice exam

Take a COF-C03 practice test under exam conditions

100 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam