ARA-C01 exam dumps

ARA-C01 practice question 103 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 103

Single answerAuthentication policies

A financial services company uses Snowflake with federated SSO for employees and username/password for a small number of service accounts. The security architect must reduce the risk of password-based compromise without disrupting existing SSO access. The company wants to enforce stricter controls only for users who authenticate with Snowflake-managed passwords, while allowing federated users to continue signing in through the identity provider. Which action should the architect take?

  1. A

    Create an authentication policy that restricts allowed authentication methods to password-based authentication, and assign it at the account level.

  2. B

    Create an authentication policy that allows SAML and password authentication, require MFA for password authentication, and assign the policy to only the service users or their dedicated role/user scope.

  3. C

    Create a network policy that limits login locations for service accounts, because network policies are the only way to enforce stronger authentication for password users.

  4. D

    Modify the password policy to require MFA, and assign the password policy to the service accounts.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use an authentication policy, because authentication policies in Snowflake are intended to manage sign-in behavior such as permitted authentication methods and MFA requirements. In this scenario, the key design requirement is selective hardening: federated SSO users must continue authenticating through the identity provider, while password-based Snowflake users need stronger protection. Applying a narrowly scoped authentication policy meets that requirement more precisely than changing account-wide settings.

This is also aligned with Snowflake security best practices: use federated authentication for workforce users where possible, minimize the use of Snowflake-managed passwords, and apply stronger authentication controls to any remaining password-based accounts. Network policies and password policies are complementary controls, but they solve different problems. Network policies restrict source network locations; password policies regulate password attributes. Neither is the primary mechanism for enforcing MFA or selectively allowing specific authentication methods.

Relevant Snowflake documentation areas include authentication policies, MFA/authentication methods, password policies, and network policies. Candidates should recognize the difference between these control types and choose the one that directly addresses authentication-path governance with minimal operational disruption.

  • A. Incorrect.

    Incorrect. Restricting the account to password-only authentication would block federated SSO users from authenticating with SAML, directly conflicting with the requirement to preserve existing SSO access. This is a common mistake when administrators confuse 'tightening authentication' with 'reducing supported methods globally.' Authentication policies can control allowed authentication methods, but applying a password-only rule at the account level would be overly broad and disruptive.

  • B. Correct.

    Correct. Authentication policies are designed to control how users authenticate, including allowed client authentication methods and MFA requirements for supported sign-in paths. In this scenario, the architect should create an authentication policy that continues to permit SAML for federated employees while enforcing stronger controls, such as MFA, for users who authenticate with Snowflake-managed passwords. Scoping the policy to the service users (rather than broadly at the account level) satisfies the requirement to harden password-based access without impacting the federated SSO population.

  • C. Incorrect.

    Incorrect. Network policies control where users can connect from, based on allowed or blocked IP addresses, but they do not replace authentication policies and are not the only mechanism for strengthening access controls. They can complement authentication controls, but they do not directly satisfy the requirement to enforce stricter authentication behavior specifically for password-based logins while preserving SSO behavior.

  • D. Incorrect.

    Incorrect. Password policies govern password complexity, rotation, lockout, and related password characteristics, but they do not require MFA. MFA enforcement is handled through authentication controls, not password policy settings. This option reflects a common misconception that all login security settings belong to password policies.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam