ADA-C01 exam dumps

ADA-C01 practice question 80 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 80

Single answerManage passwords and password policies

A Snowflake administrator needs to tighten local password controls for a group of service users that authenticate with Snowflake usernames and passwords, while leaving federated SSO users unaffected. The security team requires the following for those local users: at least 14 characters, at least 1 uppercase letter, at least 1 lowercase letter, at least 1 number, and passwords must rotate every 60 days. The administrator wants the change to apply only to a specific set of local users without impacting the entire account. Which approach should the administrator take?

  1. A

    Create a custom password policy with the required settings and assign it directly to each affected user.

  2. B

    Modify the account-level password policy because Snowflake password policies can only be applied at the account level.

  3. C

    Create a network policy with the required password settings and assign it to the affected users.

  4. D

    Create a session policy with the required password settings and assign it to the affected users.

Show answer and explanation

Correct answer: A

Explanation

The best solution is to create a custom password policy and assign it directly to the relevant local users. Snowflake supports password policies for managing password-related requirements such as minimum length, character complexity, and password age. These policies can be applied at different scopes, including directly to users, which is important when administrators need targeted enforcement rather than account-wide changes. This approach aligns with least-impact administration and real-world best practice: apply stricter controls only where needed. Network policies and session policies are separate security mechanisms and do not manage password requirements. In Snowflake documentation, password policies are specifically intended for Snowflake-managed password authentication, whereas federated authentication scenarios are governed primarily by the external identity provider.

  • A. Correct.

    Correct. Snowflake password policies can be created with parameters such as minimum password length, required character classes, and password maximum age. To scope the change to only a subset of local users, the administrator should assign the custom password policy directly to those users instead of applying it account-wide. This also avoids affecting federated SSO users who do not authenticate with Snowflake-managed passwords in the same way as local password users.

  • B. Incorrect.

    Incorrect. Snowflake password policies are not limited to account-level application. While an account-level password policy can be used as a default, policies can also be assigned directly to users, which is the better choice when only a subset of local users should be affected. Choosing account-level scope here would unnecessarily broaden the impact.

  • C. Incorrect.

    Incorrect. Network policies control allowed network locations, such as IP address restrictions, not password complexity or rotation requirements. This distractor reflects a common confusion between authentication security controls and network access controls.

  • D. Incorrect.

    Incorrect. Session policies govern session behavior such as idle timeout and related session settings, not password composition or password expiration. This option is plausible because session policies are security-related, but they do not manage password rules.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam