ADA-C01 exam dumps

ADA-C01 practice question 154 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 154

Single answerManage Tri-Secret Secure

A financial services company is onboarding a highly regulated workload to Snowflake and must use Tri-Secret Secure so that access to encrypted data depends on both Snowflake-controlled encryption and a key managed by the customer in their cloud provider KMS. The security team wants to ensure they can immediately prevent Snowflake from decrypting data if their KMS key policy changes or the key is disabled, while keeping operational responsibility for that customer-managed key. Which action should the Snowflake administrator take to meet this requirement?

  1. A

    Configure Tri-Secret Secure for the account and associate a customer-managed key from the cloud provider KMS so Snowflake encryption depends on both the Snowflake root key and the customer-managed key

  2. B

    Create a network policy that restricts all access to the account from approved corporate IP ranges so data cannot be decrypted outside the company network

  3. C

    Enable client-side encryption for all staged files so Snowflake no longer needs to use its own key hierarchy for data at rest

  4. D

    Use a password policy and mandatory MFA for all privileged users because Tri-Secret Secure relies on stronger authentication to revoke decryption access

Show answer and explanation

Correct answer: A

Explanation

Tri-Secret Secure is intended for organizations that need an additional layer of customer-controlled encryption governance beyond Snowflake's standard encryption at rest. In practice, Snowflake continues to use its encryption architecture, but data access is made dependent on an external customer-managed key stored in the supported cloud provider KMS. This gives the customer an independent control point: if the KMS key is disabled, revoked, or rendered inaccessible by policy, Snowflake cannot complete the decryption flow for protected data. For exam purposes, distinguish Tri-Secret Secure from network controls, authentication controls, and client-side file encryption. Those are useful security measures, but they do not provide the same cryptographic dependency and revocation model as Tri-Secret Secure. This aligns with Snowflake best practices and product documentation describing Tri-Secret Secure as a customer-managed key integration for enhanced control over encryption of data at rest.

  • A. Correct.

    Correct. Tri-Secret Secure adds a customer-managed key from the cloud provider's key management service into Snowflake's envelope encryption model. This is designed for customers who require control such that data decryption depends on both Snowflake-managed key material and a customer-controlled key. If the customer disables, revokes, or otherwise makes the KMS key unavailable according to the cloud provider controls, Snowflake cannot use that key in the decryption path. This directly satisfies the requirement for customer-controlled cryptographic revocation while the customer retains operational responsibility for the external key.

  • B. Incorrect.

    Incorrect. Network policies control where users can connect from, not whether Snowflake can decrypt stored data. Restricting IP addresses may reduce access risk, but it does not provide cryptographic control over Snowflake's data-at-rest encryption and does not meet the requirement that decryption depends on a customer-managed KMS key.

  • C. Incorrect.

    Incorrect. Client-side encryption for staged files is a different control and applies to file handling workflows, not to the core account-level encryption architecture for Snowflake-managed data at rest. It also does not replace Snowflake's internal encryption hierarchy or provide the account-wide cryptographic governance model that Tri-Secret Secure is intended to deliver.

  • D. Incorrect.

    Incorrect. Strong authentication is an important administrative security best practice, but MFA and password policies govern user access, not the cryptographic dependency required by Tri-Secret Secure. They do not allow a customer to revoke Snowflake's ability to decrypt account data by changing the status or policy of a customer-managed KMS key.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam