ARA-C01 exam dumps

ARA-C01 practice question 107 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 107

Single answerSingle Sign-On (SSO)

A global company uses Microsoft Entra ID as its enterprise identity provider and is rolling out Snowflake to several business units. Security requirements state that interactive users must authenticate through the corporate IdP using SSO, while service accounts used by ETL tools must continue to authenticate non-interactively. The architecture team wants to minimize administrative overhead and avoid creating duplicate Snowflake users where possible. Which approach best meets these requirements?

  1. A

    Configure federated authentication with Entra ID for Snowflake user sign-ins, and keep separate Snowflake-native service users with key pair authentication for ETL processes.

  2. B

    Enable SSO for all Snowflake users, including service accounts, and have ETL tools complete browser-based SAML authentication through Entra ID.

  3. C

    Create all users directly in Snowflake with passwords, then use Entra ID only to provision roles after login.

  4. D

    Use Entra ID SCIM provisioning only, without configuring federated authentication, because SCIM alone provides SSO into Snowflake.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use federated SSO for human users and a separate non-interactive authentication method for service accounts. In Snowflake, SSO for workforce users is commonly implemented with a supported external IdP such as Microsoft Entra ID using SAML 2.0 federation. This allows organizations to centralize authentication, enforce enterprise security controls, and reduce password management in Snowflake. For automated workloads, Snowflake best practices favor programmatic authentication methods such as key pair authentication rather than interactive browser-based SSO. SCIM, when used, can complement SSO by automating user and group provisioning, but it does not replace authentication federation. This distinction between interactive and non-interactive identities is a common architectural consideration in Snowflake deployments and is consistent with Snowflake documentation on federated authentication, key pair authentication, and SCIM-based user lifecycle management.

  • A. Correct.

    Correct. This design aligns with Snowflake best practices for mixed human and machine access. Interactive users can authenticate with the corporate IdP through federated SSO, which centralizes identity and access control. Non-interactive service accounts generally should not rely on browser-based SSO flows; instead, they should use Snowflake-supported programmatic authentication such as key pair authentication. This approach also avoids unnecessary duplicate identities because human users can be represented as federated Snowflake users while service identities remain distinct for automation.

  • B. Incorrect.

    Incorrect. Service accounts and ETL tools typically require non-interactive authentication. Browser-based SAML flows are designed for human interactive sign-in and are not an appropriate general solution for unattended workloads. Choosing this option reflects the common misconception that all identities should be forced through the same SSO mechanism regardless of workload type.

  • C. Incorrect.

    Incorrect. This approach does not satisfy the requirement that interactive users authenticate through the corporate IdP using SSO. Snowflake-native passwords for human users bypass centralized enterprise authentication policies such as conditional access and MFA enforcement at the IdP. Entra ID is not used merely for role assignment after a Snowflake password login in a standard SSO design.

  • D. Incorrect.

    Incorrect. SCIM provisioning and federated authentication solve different problems. SCIM can automate user and group lifecycle management, but by itself it does not authenticate users into Snowflake. SSO requires a supported federation setup, such as SAML 2.0 with the external IdP. This option reflects the misconception that identity provisioning and authentication are the same capability.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam