ADA-C01 exam dumps

ADA-C01 practice question 1 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 1

Single answerI need one more page for Domain 6.0.Here are all 6 domains with every skill and sub-item:

A Snowflake administrator is reviewing account security after an internal audit. The audit found that several service users connect from approved corporate networks, but some also use username/password authentication without network restrictions. The security team wants to reduce the risk of credential misuse while minimizing disruption to existing workloads. Which action should the administrator take to enforce that these users can authenticate only from approved network locations while preserving existing user objects and role assignments?

  1. A

    Create a network policy with the approved IP address list and assign the policy to the affected users or at the account level

  2. B

    Create a masking policy to restrict authentication attempts based on source IP address

  3. C

    Grant the SECURITYADMIN role to the service users so they can manage their own trusted IP addresses

  4. D

    Configure a resource monitor to block logins from unapproved IP addresses

  5. E

    Move the users to a separate virtual warehouse that is accessible only from approved corporate networks

Show answer and explanation

Correct answer: A

Explanation

This scenario tests knowledge of Snowflake access control and authentication hardening in a practical administrative context. The correct solution is to use a network policy, which supports allowed and blocked IP lists and can be associated either with the account or specific users. That makes it appropriate when an organization wants to enforce source network restrictions without replacing user identities or changing RBAC design. By contrast, masking policies protect query output, resource monitors manage credit usage, and warehouses do not provide authentication boundaries. As a best practice, administrators should combine network policies with stronger authentication methods such as key-pair authentication, OAuth, or MFA where applicable, while following least-privilege principles for role assignment. Relevant Snowflake documentation includes guidance on network policies, user security, and account access control.

  • A. Correct.

    Correct. Snowflake network policies are the supported control for restricting authentication based on allowed and/or blocked IP addresses. They can be applied at the account level or to individual users, which allows an administrator to tighten access without recreating users or changing role assignments. This directly addresses the requirement to limit authentication to approved network locations while minimizing disruption.

  • B. Incorrect.

    Incorrect. Masking policies are used to control how sensitive data is exposed in query results, not to control login behavior or source-network restrictions. This option reflects a common confusion between data governance controls and authentication/access controls.

  • C. Incorrect.

    Incorrect. Granting SECURITYADMIN would increase privileges significantly and does not enforce source IP restrictions for authentication. It would also violate least-privilege principles by allowing service users to manage security-related objects unnecessarily.

  • D. Incorrect.

    Incorrect. Resource monitors track and control credit consumption for warehouses. They can suspend warehouses or send notifications when usage thresholds are reached, but they do not evaluate client source IP addresses or control authentication.

  • E. Incorrect.

    Incorrect. Virtual warehouses are compute resources for query execution. Network access restrictions are not enforced by placing users on a particular warehouse. Authentication controls such as network policies are the proper mechanism for restricting where users can connect from.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam