ARA-C01 exam dumps

ARA-C01 practice question 104 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 104

Single answerFederated authentication

A global company uses Snowflake with Okta as its identity provider for SAML 2.0 federated authentication. The security team is rolling out a new policy that requires users to authenticate through the corporate IdP for all interactive logins, while still allowing existing service accounts used by ETL jobs to connect with key-pair authentication. During testing, several analysts can still sign in with their Snowflake passwords through the web interface, bypassing the IdP. Which configuration change should the architect implement to meet the requirement with the least impact to service accounts?

  1. A

    Set the account-level SSO parameter so the IdP is enforced for interactive sign-ins, and ensure service users continue to use non-password authentication such as key-pair authentication.

  2. B

    Disable all user passwords in Snowflake, including for service accounts, because federated authentication requires passwordless access for every user type.

  3. C

    Configure SCIM provisioning from Okta to Snowflake, because SCIM automatically prevents direct Snowflake password logins.

  4. D

    Create a network policy that only allows connections from the corporate office IP range, because network restrictions force web users to authenticate with the IdP.

  5. E

    Convert the ETL service accounts to browser-based SAML users so they can inherit the same interactive sign-in policy as analysts.

Show answer and explanation

Correct answer: A

Explanation

The key architectural decision is to enforce federated authentication for human interactive access while preserving non-interactive authentication for service accounts. In Snowflake, SAML 2.0 federated authentication integrates with IdPs such as Okta for SSO. Architects should ensure users cannot bypass the IdP with native Snowflake password login when the organization's policy requires centralized authentication controls like MFA and conditional access at the IdP. At the same time, ETL or application service accounts should typically use supported non-interactive methods such as key-pair authentication rather than browser-based SSO. SCIM is relevant for identity lifecycle management, not for enforcing authentication paths. Network policies are also separate; they limit allowed client networks but do not enforce SAML. This aligns with Snowflake best practices for separating human and machine identities and using federated authentication appropriately for workforce users.

  • A. Correct.

    Correct. In Snowflake, federated authentication with SAML can be configured so that users must authenticate through the identity provider for interactive logins rather than using native Snowflake passwords. This is the appropriate control when the goal is to prevent analysts from bypassing SSO in the web interface. At the same time, service accounts used for automation typically should not use interactive SSO; they commonly use key-pair authentication or other non-interactive methods. This approach meets the requirement while minimizing disruption to ETL jobs.

  • B. Incorrect.

    Incorrect. Disabling passwords for every user is broader than required and can create unnecessary operational risk. Snowflake service accounts often use key-pair authentication and do not need interactive SSO, but the requirement is specifically about enforcing IdP-based authentication for interactive users. Also, federated authentication does not mean every possible login path for every user type must be passwordless in the same way; the architect should distinguish between human interactive access and programmatic service access.

  • C. Incorrect.

    Incorrect. SCIM is used for automated user and group lifecycle management, such as provisioning and deprovisioning identities and group memberships. It does not itself enforce SSO usage or block direct Snowflake password authentication. A candidate might choose this if they confuse identity provisioning with authentication enforcement, but they are separate controls.

  • D. Incorrect.

    Incorrect. Network policies restrict where users can connect from based on IP addresses, but they do not determine whether a user authenticates through SAML SSO versus a Snowflake username/password. Restricting source IPs can complement security posture, but it will not solve the bypass problem described in the scenario.

  • E. Incorrect.

    Incorrect. Browser-based SAML authentication is designed for human interactive users, not unattended ETL service accounts. Converting service accounts to browser-based SAML would likely break automation because scheduled jobs cannot generally complete interactive browser SSO flows. Best practice is to keep service principals on non-interactive authentication methods such as key-pair authentication.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam