ARA-C01 exam dumps

ARA-C01 practice question 110 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 110

Select 2Multi-Factor Authentication (MFA)

A global enterprise uses Snowflake with both human users and service accounts. The security team must strengthen authentication for interactive access to Snowflake while avoiding disruptions to automated ETL jobs that run overnight. They want a solution that aligns with Snowflake security best practices and minimizes operational risk during rollout. Which TWO actions should the architect recommend?

  1. A

    Require MFA enrollment and usage for all interactive users, while keeping non-interactive service accounts on key pair authentication or another supported non-MFA method appropriate for automation.

  2. B

    Enable MFA for every Snowflake user, including service accounts used by unattended pipelines, so all identities are protected consistently.

  3. C

    Federate interactive users through a supported SSO identity provider and enforce MFA at the IdP, while using separate non-human accounts for automation.

  4. D

    Store a shared MFA device seed for each service account in the orchestration platform so scheduled jobs can generate one-time passcodes automatically.

  5. E

    Convert scheduled ETL jobs to use personal user accounts so the same MFA policy can be applied uniformly across both people and automation.

Show answer and explanation

Correct answers: A, C

Explanation

The best answer is to enforce MFA for human interactive access while using appropriate non-interactive authentication methods for automation. In Snowflake, MFA is designed for users signing in interactively, whereas service accounts for unattended processes should use mechanisms such as key pair authentication. In enterprise environments, a common best practice is to federate workforce users through an SSO identity provider and enforce MFA there, giving centralized control over authentication policies and user lifecycle. Architects should avoid designs that force unattended jobs through interactive MFA or that store MFA secrets in automation platforms, because these approaches create reliability and security issues. This aligns with Snowflake guidance around MFA, federated authentication/SSO, and key pair authentication for service users.

  • A. Correct.

    Correct. MFA is intended for human, interactive authentication flows. For unattended workloads, Snowflake best practice is to use non-human service accounts with supported programmatic authentication methods such as key pair authentication rather than interactive MFA prompts. This approach improves security without breaking automation.

  • B. Incorrect.

    Incorrect. Applying MFA uniformly to service accounts used by unattended jobs is operationally problematic because those jobs cannot respond to an interactive second-factor challenge. This commonly leads to failed pipelines or insecure workarounds. The misconception is that identical controls must be applied to all identities, when in practice controls should fit the access pattern.

  • C. Correct.

    Correct. For workforce users, federated authentication with a supported SSO/IdP and MFA enforced at the identity provider is a strong enterprise pattern. It centralizes policy, improves user lifecycle management, and allows Snowflake interactive access to inherit the organization's MFA controls. Separating automation into dedicated non-human accounts avoids mixing interactive and non-interactive authentication requirements.

  • D. Incorrect.

    Incorrect. Sharing or storing MFA seeds for service accounts undermines the purpose of MFA and creates a high-risk secret management issue. It effectively turns the second factor into another stored credential and is not an appropriate architecture pattern for Snowflake automation.

  • E. Incorrect.

    Incorrect. Personal user accounts should not be repurposed for scheduled jobs. This weakens accountability, complicates user lifecycle management, and can cause outages when personnel change roles or leave the company. It also conflicts with best practices to separate human identities from service principals.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam