ADA-C01 exam dumps

ADA-C01 practice question 107 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 107

Single answerAnalyze network policy behavior when both account-level and user-level network rules exist

A Snowflake administrator is troubleshooting why a contractor can still sign in from a public coffee shop IP address. The account has an account-level network policy named CORP_POLICY that allows only the company VPN range 198.51.100.0/24 and blocks all other public IPs. The contractor's Snowflake user, CONTRACTOR_1, has a user-level network policy named TEMP_REMOTE that explicitly allows 203.0.113.0/24 so the contractor can work while traveling. No other relevant security policies are assigned. The contractor successfully connects from 203.0.113.25. What should the administrator conclude?

  1. A

    The connection succeeds because a user-level network policy takes precedence over the account-level network policy for that user.

  2. B

    The connection succeeds only because the IP appears in both the user-level and account-level allowed lists.

  3. C

    The connection should have been denied because account-level network policies are evaluated before user-level network policies and cannot be overridden.

  4. D

    The connection should have been denied unless the user was connecting through a private connectivity endpoint such as AWS PrivateLink, Azure Private Link, or Google Cloud Private Service Connect.

Show answer and explanation

Correct answer: A

Explanation

Snowflake supports assigning a network policy at both the account level and the user level. When both exist, the user-level network policy overrides the account-level network policy for that specific user. This design enables administrators to enforce a broad corporate policy at the account level while granting controlled exceptions for individual users when necessary. In the scenario, CORP_POLICY restricts the account to 198.51.100.0/24, but CONTRACTOR_1 has TEMP_REMOTE assigned directly to the user, allowing 203.0.113.0/24. Therefore, the login from 203.0.113.25 succeeds. This aligns with Snowflake documentation on network policy assignment and precedence, which states that a user-level network policy applies in place of the account-level policy for that user. Best practice is to use user-level policies sparingly, document exceptions clearly, and review them regularly to avoid weakening account-wide access controls.

  • A. Correct.

    Correct. In Snowflake, if a network policy is assigned directly to a user, that user-level policy applies to that user instead of the account-level policy. This is why CONTRACTOR_1 can connect from 203.0.113.25 even though the account-level policy allows only 198.51.100.0/24. This reflects the documented precedence behavior of network policies.

  • B. Incorrect.

    Incorrect. The scenario states that the account-level policy allows only 198.51.100.0/24, while the user-level policy allows 203.0.113.0/24. The public coffee shop IP 203.0.113.25 is not in the account-level allowed range. The success is due to policy precedence, not overlap between lists.

  • C. Incorrect.

    Incorrect. This is a common misconception. Although an account-level network policy protects users broadly, Snowflake allows a user-level network policy to be set for a specific user, and that user-level assignment takes precedence for that user.

  • D. Incorrect.

    Incorrect. Private connectivity can affect how traffic reaches Snowflake, but it is not required for a user-level network policy to allow a public IP range. In this scenario, the login succeeds because the assigned user-level policy permits the source IP.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam