COF-C03 exam dumps

COF-C03 practice question 219 of 350

SnowPro® Core Certification (COF-C03). Associate level, Snowflake. Free question with the correct answer and a full explanation.

COF-C03 Question 219

Single answerServer-side encryption

A financial services company is migrating regulated data to Snowflake and must satisfy an internal security requirement that encryption keys used to protect data at rest can be rotated independently and controlled through the company's cloud key management service. The security team also wants Snowflake to continue handling encryption operations without requiring application changes. Which Snowflake feature should the architect recommend?

  1. A

    Use Tri-Secret Secure so Snowflake data is protected with a Snowflake-managed key plus a customer-managed key from the cloud provider's key management service

  2. B

    Use client-side encryption for all tables so Snowflake no longer needs to manage any server-side encryption keys

  3. C

    Disable Snowflake managed encryption and store all table data in externally encrypted internal stages only

  4. D

    Use network policies together with MFA to satisfy the encryption-at-rest key control requirement

Show answer and explanation

Correct answer: A

Explanation

The best answer is Tri-Secret Secure. Snowflake always encrypts data at rest and in transit, but some regulated environments require customer participation in key management for server-side encryption. Tri-Secret Secure addresses this by incorporating a customer-managed key from the cloud provider's key management service in addition to Snowflake-controlled keys. This gives the organization stronger control over access to encrypted data, including the ability to rotate or revoke the customer-managed key, while preserving Snowflake's transparent encryption architecture. In Snowflake documentation and security best practices, Tri-Secret Secure is the feature associated with customer-managed keys for encryption at rest. By contrast, client-side encryption changes the application responsibility model, and access controls such as MFA or network policies do not satisfy encryption key control requirements.

  • A. Correct.

    Correct. Tri-Secret Secure is designed for organizations that need additional control over encryption at rest by combining Snowflake's server-side encryption with a customer-managed key from the cloud provider's key management service. This allows the customer to control and rotate their key independently while Snowflake continues to perform encryption and decryption operations transparently for supported workloads. This directly addresses the requirement for customer-controlled key management without changing applications.

  • B. Incorrect.

    Incorrect. Client-side encryption is not the right recommendation for this requirement. The scenario specifically asks for Snowflake to continue handling encryption operations without application changes. Client-side encryption shifts responsibility to the client or application layer and typically requires changes in how data is encrypted before Snowflake receives it. That does not meet the operational goal in the scenario.

  • C. Incorrect.

    Incorrect. Snowflake does not support disabling its native server-side encryption for stored data. Snowflake automatically encrypts data at rest. Also, storing data only in externally encrypted internal stages does not replace encryption of Snowflake table storage or provide the integrated customer key control described in the requirement.

  • D. Incorrect.

    Incorrect. Network policies and MFA are important security controls for access management, but they do not address server-side encryption key ownership, independent key rotation, or encryption-at-rest control. A candidate might choose this option by confusing identity and network protections with cryptographic key management.

Timed practice exam

Take a COF-C03 practice test under exam conditions

100 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam