ADA-C01 exam dumps

ADA-C01 practice question 75 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 75

Select 2Implement and manage passwords and multi-factor authentication (MFA)

A Snowflake administrator is reviewing authentication controls for a set of contractor accounts that use Snowflake native authentication (username/password, not federated SSO). The security team requires the following: contractors must change their password regularly, users must not be able to reuse recent passwords, and MFA must be enforced for interactive logins to Snowsight and the Classic Console. Which actions should the administrator take to meet these requirements?

  1. A

    Create or alter a password policy to set PASSWORD_MAX_AGE_DAYS and PASSWORD_HISTORY, then assign that policy to the contractor users or their account.

  2. B

    Enable MFA for the account and require the contractor users to enroll so MFA is used with Snowflake native authentication for supported interactive clients.

  3. C

    Set RSA_PUBLIC_KEY on each contractor user so MFA is enforced whenever they connect using any client, including programmatic connections.

  4. D

    Configure a session policy with SESSION_IDLE_TIMEOUT_MINS to force password rotation and prevent password reuse.

  5. E

    Disable password login for contractor users and rely on network policies to prompt for MFA only when they connect from untrusted IP addresses.

Show answer and explanation

Correct answers: A, B

Explanation

To satisfy these requirements for Snowflake native users, the administrator should use two distinct control families: password policies and MFA. Password policies provide the supported settings for password aging and password history, which map directly to regular password changes and prevention of recent password reuse. MFA for Snowflake native authentication is the correct control for requiring an additional factor during supported interactive logins such as Snowsight and the Classic Console. Session policies and network policies are important security features, but they do not replace password policies or enforce MFA logic. Likewise, RSA key-pair authentication is a separate authentication method, not a way to mandate MFA for all connection types. These practices align with Snowflake documentation on password policies, MFA for native authentication, and the distinction between authentication methods versus session/network controls.

  • A. Correct.

    Correct. Snowflake password policies are the native control for password lifecycle and reuse restrictions. PASSWORD_MAX_AGE_DAYS enforces password expiration/rotation, and PASSWORD_HISTORY prevents reuse of recently used passwords. A password policy can be assigned at the account level or to individual users, making it the right mechanism for this requirement.

  • B. Correct.

    Correct. For users authenticating directly with Snowflake credentials, account-level MFA can be enabled so users must enroll and use MFA for supported interactive sign-ins such as Snowsight and the Classic Console. This directly addresses the requirement to enforce MFA for interactive logins using native authentication.

  • C. Incorrect.

    Incorrect. RSA key-pair authentication is a different authentication mechanism commonly used for clients such as SnowSQL or drivers; it does not enforce MFA for all clients. In fact, many programmatic authentication methods are not interactive and do not use MFA in the same way as console logins. This option confuses key-pair authentication with MFA enforcement.

  • D. Incorrect.

    Incorrect. Session policies control session behavior such as idle timeout and session duration; they do not manage password expiration or password history. Someone might choose this because session controls are security-related, but they are not the correct feature for password rotation or reuse prevention.

  • E. Incorrect.

    Incorrect. Network policies restrict access based on allowed IP addresses or network rules; they do not trigger MFA conditionally. Disabling password login would also conflict with the stated requirement that these users use Snowflake native authentication with username/password. This option mixes separate controls and misstates how MFA is applied in Snowflake.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam