ADA-C01 exam dumps

ADA-C01 practice question 69 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 69

Single answerEstablish federated authentication and Single Sign-on (SSO) to Snowflake

A company is integrating Snowflake with its corporate identity provider (IdP) using SAML 2.0 so employees can sign in through the company portal without managing separate Snowflake passwords. The security team also requires that if a user account is disabled in the IdP, the user must no longer be able to authenticate to Snowflake through SSO. As the Snowflake administrator, which configuration should you implement to meet these requirements with the least operational overhead?

  1. A

    Configure Snowflake for federated authentication with SAML 2.0, set the account to use the external browser authenticator for supported clients, and disable password-based sign-in for federated users by setting their passwords to null/unused values.

  2. B

    Configure key-pair authentication for all users and store private keys in the corporate IdP so Snowflake can validate SSO sessions without SAML.

  3. C

    Enable OAuth between the IdP and Snowflake and require users to authenticate with PAT (personal access token) values generated by Snowflake for worksheet and Snowsight access.

  4. D

    Create Snowflake user passwords that match the users' IdP passwords and enforce password synchronization through a scheduled provisioning script.

Show answer and explanation

Correct answer: A

Explanation

For enterprise SSO to Snowflake, the standard and recommended approach is federated authentication using SAML 2.0 with an external identity provider such as Okta, Microsoft Entra ID, PingFederate, or ADFS. In this model, Snowflake trusts SAML assertions from the IdP, and users authenticate against the IdP rather than with Snowflake-native passwords. Using the external browser authenticator for supported clients is a common implementation pattern because it redirects authentication to the IdP. This design also satisfies the requirement that disabling a user in the IdP prevents further SSO access to Snowflake, since the IdP stops issuing valid assertions for that user. Snowflake documentation and best practices for federated authentication emphasize SAML integration, IdP-managed authentication, and minimizing reliance on Snowflake passwords for federated users.

  • A. Correct.

    Correct. Snowflake supports federated authentication with SAML 2.0 for SSO. Using the external browser authenticator is a standard approach for supported clients so authentication is delegated to the IdP. To avoid separate Snowflake-managed credentials, administrators commonly ensure federated users do not use Snowflake passwords for sign-in, which reduces credential sprawl and aligns with SSO best practices. If a user is disabled in the IdP, authentication through the IdP is blocked, so the user can no longer sign in via SSO.

  • B. Incorrect.

    Incorrect. Key-pair authentication is used primarily for programmatic access and service accounts, not as a replacement for browser-based SAML SSO for human users. The IdP does not act as a repository for Snowflake private keys to provide federated interactive login.

  • C. Incorrect.

    Incorrect. OAuth can be used with Snowflake for delegated authorization patterns, but it is not the standard configuration to establish employee SAML-based SSO to Snowsight and common user login flows. The reference to PATs is also misleading in this context because PAT-based access is not how Snowflake establishes enterprise SSO for interactive user authentication.

  • D. Incorrect.

    Incorrect. Synchronizing passwords between Snowflake and the IdP defeats the purpose of federated authentication and creates additional security and operational risk. Best practice is to delegate authentication to the IdP rather than duplicate or synchronize passwords into Snowflake.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam