ADA-C01 exam dumps

ADA-C01 practice question 96 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 96

Select 3Compare Snowflake OAuth to External OAuth

A company is standardizing authentication for analytics tools and custom applications that access Snowflake. The security team requires that employees sign in through the corporate identity provider (IdP), and they want Snowflake access tokens to be issued and governed by that external IdP. At the same time, the data engineering team has an internal service that needs OAuth-based access to Snowflake without relying on the corporate IdP. As the Snowflake administrator, which TWO statements correctly compare Snowflake OAuth and External OAuth for this design?

  1. A

    External OAuth is designed for scenarios where an external authorization server or IdP issues the OAuth access token that Snowflake validates.

  2. B

    Snowflake OAuth is intended for cases where Snowflake itself acts as the authorization server and issues the OAuth access token.

  3. C

    External OAuth requires Snowflake to store and manage user passwords because the external IdP cannot provide identity context to Snowflake.

  4. D

    Snowflake OAuth can only be used for interactive Snowsight logins and cannot be used by client applications or programmatic workloads.

  5. E

    When using External OAuth, Snowflake can be configured to trust tokens from supported external providers such as Okta, Microsoft Entra ID, or a custom OAuth 2.0 authorization server.

Show answer and explanation

Correct answers: A, B, E

Explanation

The key distinction is who issues the OAuth access token. With Snowflake OAuth, Snowflake acts as the authorization server and issues tokens for Snowflake access. With External OAuth, an external authorization server or corporate IdP issues the token, and Snowflake validates it using a configured security integration. In this scenario, the employee-facing requirement to use the corporate IdP for token issuance aligns with External OAuth, while the internal service that does not need the corporate IdP could use Snowflake OAuth if that fits the organization's design.

This reflects Snowflake best practices for choosing the model based on identity ownership and token governance requirements. Administrators should evaluate whether the organization wants Snowflake-managed OAuth or enterprise-managed OAuth through an external provider. Relevant Snowflake documentation includes the sections on Snowflake OAuth, External OAuth, and CREATE SECURITY INTEGRATION for External OAuth configuration.

  • A. Correct.

    Correct. External OAuth is specifically used when an external OAuth 2.0 authorization server issues the access token and Snowflake validates that token. This aligns with organizations that want centralized token issuance and policy enforcement in their corporate IdP or authorization platform.

  • B. Correct.

    Correct. In Snowflake OAuth, Snowflake acts as both the resource server and the authorization server for Snowflake access. This is appropriate when applications need OAuth access to Snowflake but the organization does not require an external IdP to issue Snowflake access tokens.

  • C. Incorrect.

    Incorrect. External OAuth does not require Snowflake to store or manage user passwords. The purpose of External OAuth is to delegate authentication and token issuance to an external identity provider or authorization server. Snowflake validates the token and maps the identity according to the External OAuth configuration.

  • D. Incorrect.

    Incorrect. Snowflake OAuth is not limited to interactive Snowsight logins. It is used by client applications to obtain OAuth tokens for accessing Snowflake, including programmatic access patterns. The misconception is confusing OAuth for application access with browser-based UI authentication methods.

  • E. Correct.

    Correct. External OAuth supports integration with external identity platforms that can act as OAuth authorization servers, including common enterprise providers such as Okta and Microsoft Entra ID, as well as custom OAuth 2.0-compliant authorization servers, provided the Snowflake integration is configured correctly.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam