ADA-C01 exam dumps

ADA-C01 practice question 124 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 124

Single answerManage users and groups with SCIM

A company uses an external identity provider (IdP) to provision Snowflake users and role assignments through SCIM. The security team has disabled an employee in the IdP after the employee left the company. A Snowflake administrator discovers that the user object still exists in Snowflake and wants to ensure the departed employee can no longer access Snowflake, while keeping historical ownership and audit information intact. What should the administrator expect when SCIM deprovisions the user from the IdP?

  1. A

    Snowflake drops the user automatically, removes all owned objects, and revokes all grants.

  2. B

    Snowflake disables the user from logging in, but the user object remains in Snowflake until an administrator explicitly drops it if desired.

  3. C

    Snowflake converts the user to a service user so object ownership is preserved but interactive login is blocked.

  4. D

    Snowflake immediately transfers ownership of all objects owned by the user to the SECURITYADMIN role.

Show answer and explanation

Correct answer: B

Explanation

The key concept is that SCIM deprovisioning in Snowflake is intended to stop access, not to perform destructive cleanup. When an IdP disables or deprovisions a user through SCIM, Snowflake retains the user object but prevents further access. This behavior supports enterprise offboarding requirements by preserving object ownership, dependency integrity, and audit history. Administrators should use separate lifecycle procedures for any later cleanup, such as reviewing grants, transferring ownership of objects, and then dropping the user if appropriate. This aligns with Snowflake SCIM provisioning and user management best practices: use SCIM for identity lifecycle synchronization, but handle object ownership and privilege cleanup deliberately through administrative controls rather than expecting automatic deletion or ownership reassignment.

  • A. Incorrect.

    Incorrect. SCIM deprovisioning does not automatically DROP USER in Snowflake, and Snowflake does not automatically remove owned objects as part of SCIM deprovisioning. Automatically dropping users and deleting ownership relationships would be risky in enterprise environments because object ownership and historical records often need to be preserved.

  • B. Correct.

    Correct. In a SCIM-integrated environment, deprovisioning from the IdP results in the Snowflake user being disabled for access rather than automatically dropped. This prevents further login while preserving the user object, object ownership, grant history, and auditability. If the organization later wants to remove the user object entirely, an administrator can do so through a separate administrative process after handling ownership transfer and dependencies.

  • C. Incorrect.

    Incorrect. Snowflake does not automatically convert deprovisioned SCIM users into a different user type such as a service user. This option reflects a plausible misconception because administrators often want a non-interactive state that preserves ownership, but SCIM deprovisioning simply disables access rather than changing the user classification.

  • D. Incorrect.

    Incorrect. Snowflake does not automatically transfer ownership of the user's objects to SECURITYADMIN during SCIM deprovisioning. Ownership transfer must be performed explicitly by an administrator using the appropriate SQL commands and governance process. Automatic reassignment would be unsafe and could violate least-privilege practices.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam