ARA-C01 exam dumps

ARA-C01 practice question 322 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 322

Single answerUse of system$allowlist

A security architect is enabling AWS PrivateLink for a Snowflake account so that a data ingestion application can connect to Snowflake without traversing the public internet. The network team asks for the exact endpoint information they must permit and configure for the account before creating the private connectivity path. Which Snowflake capability should the architect use to retrieve the required account-specific values?

  1. A

    Run the SYSTEM$ALLOWLIST function for the Snowflake account and use the returned account-specific endpoint details for private connectivity planning

  2. B

    Query ACCOUNT_USAGE views to retrieve all private endpoint DNS names and cloud-provider service identifiers for the account

  3. C

    Use SHOW NETWORK POLICIES to list the private connectivity endpoints that Snowflake has assigned to the account

  4. D

    Describe the virtual warehouse used by the application to obtain the account's PrivateLink endpoint and region mapping

Show answer and explanation

Correct answer: A

Explanation

The correct answer is to use SYSTEM$ALLOWLIST. In Snowflake, this system function returns account-specific allowlist information that is used by clients and network/security teams when they need to configure connectivity to Snowflake services. In architectures using private connectivity such as AWS PrivateLink, relying on account-specific values is important because endpoint details are not derived from warehouse settings or general metadata views. From an exam perspective, candidates should distinguish between: (1) discovering account connectivity endpoints via SYSTEM$ALLOWLIST, (2) enforcing source access restrictions with network policies, and (3) analyzing usage or object metadata with ACCOUNT_USAGE. Snowflake documentation for private connectivity and network allowlisting describes using system functions like SYSTEM$ALLOWLIST to obtain the required endpoint information for a given account.

  • A. Correct.

    Correct. SYSTEM$ALLOWLIST is used to return account-specific network allowlist information that clients or network teams may need when configuring connectivity. In private connectivity scenarios such as AWS PrivateLink, architects use this Snowflake-provided function to obtain the relevant hostnames/endpoints that must be allowed or referenced for the specific account. This is the practical, documented mechanism for retrieving account-specific connectivity details rather than trying to infer them from metadata views.

  • B. Incorrect.

    Incorrect. ACCOUNT_USAGE views provide governance and usage metadata, but they are not the mechanism for retrieving the account-specific allowlist or private connectivity endpoint information needed by a network team. A common misconception is that all account metadata is exposed through views; however, connectivity configuration details for allowlisting are provided through system functions such as SYSTEM$ALLOWLIST.

  • C. Incorrect.

    Incorrect. SHOW NETWORK POLICIES displays Snowflake network policy objects that control allowed IP addresses and related access restrictions. It does not return the account-specific endpoint values required to configure AWS PrivateLink or other private connectivity. This distractor targets the common confusion between inbound access control policies and outbound/account endpoint discovery.

  • D. Incorrect.

    Incorrect. Virtual warehouses are compute resources and have no role in exposing account-level private connectivity endpoint information. Describing a warehouse returns warehouse configuration, not network endpoint data. This option is plausible only if someone incorrectly assumes connectivity settings are tied to compute resources rather than the Snowflake account and its service endpoints.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam