ADA-C01 exam dumps

ADA-C01 practice question 74 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 74

Single answerConfigure, use, and manage federated authentication with Snowflake

A company uses Okta as its corporate identity provider and wants Snowflake users to authenticate with SSO from the Snowsight login page. During rollout, administrators notice that users are still seeing the default Snowflake username/password sign-in experience instead of being redirected to Okta. Security policy requires that federated users authenticate through the corporate IdP, but the company also wants to keep a small set of break-glass administrators able to sign in if the IdP is unavailable. Which action should the Snowflake administrator take to meet these requirements?

  1. A

    Set the account-level SAML_IDENTITY_PROVIDER object and configure SSO with a custom client redirect URL so that federated users can use the IdP, while excluding designated emergency admin users from federation.

  2. B

    Enable SCIM provisioning for all users because SCIM automatically enforces SAML SSO for Snowsight and preserves local password access for emergency administrators.

  3. C

    Create a network policy that allows only the IdP IP addresses to access Snowflake, because this forces all interactive logins to be redirected to Okta while still allowing password login for admins.

  4. D

    Rotate the RSA public key on all Snowflake users, because key-pair authentication takes precedence over password authentication and therefore causes Snowsight to redirect to the IdP.

Show answer and explanation

Correct answer: A

Explanation

The core issue is that Snowflake must be explicitly configured for federated authentication before Snowsight will use the external SAML identity provider. In Snowflake, this is done by creating and configuring a SAML2 security integration and setting the account to use the external IdP for federated login. A common best practice is to exclude a limited number of break-glass administrators from federation so they can still authenticate directly if the IdP is unavailable. This aligns with Snowflake guidance for managing federated authentication operationally and securely. By contrast, SCIM handles provisioning, network policies handle source IP restrictions, and key-pair authentication is a separate authentication mechanism mainly for non-browser clients. Relevant Snowflake documentation includes topics on federated authentication, SAML 2.0 security integrations, and user-level exclusion from SSO for emergency access.

  • A. Correct.

    Correct. To enable federated authentication for a Snowflake account, the administrator must configure the account-level security integration for SAML 2.0 and associate the identity provider settings with the account so Snowflake knows to use the external IdP for SSO. In practice, this is what allows users to sign in through the IdP instead of relying on native Snowflake passwords from the Snowsight flow. At the same time, Snowflake supports excluding specific users from federation, which is a recommended break-glass design for emergency administrative access if the IdP is unavailable. This directly addresses both the SSO requirement and the operational resilience requirement.

  • B. Incorrect.

    Incorrect. SCIM is used for automated provisioning and deprovisioning of users and groups; it does not itself enforce SAML-based authentication. An administrator might choose this option because SCIM is commonly deployed alongside SSO, but SCIM manages identity lifecycle, not the authentication redirect behavior in Snowsight.

  • C. Incorrect.

    Incorrect. Network policies control which client IP addresses can connect to Snowflake, but they do not configure SAML federation or browser-based SSO redirection. This is a plausible misconception because administrators sometimes combine network restrictions with authentication controls, but an IP allowlist cannot substitute for federated authentication setup.

  • D. Incorrect.

    Incorrect. RSA public key rotation is related to key-pair authentication, typically for programmatic access such as SnowSQL, connectors, or drivers. It has nothing to do with Snowsight SAML redirection behavior. Someone might pick this option if they confuse different Snowflake authentication methods, but key-pair authentication does not cause browser users to be redirected to an external IdP.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam