ARA-C01 exam dumps

ARA-C01 practice question 81 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 81

Single answerNetwork security

A financial services company uses Snowflake on AWS and must ensure that users can connect only from corporate networks and approved application subnets. The company also wants to prevent any access from the public internet, including users who know valid credentials. An architect is asked to design the most appropriate network-level control strategy with minimal impact to existing authentication methods. Which solution should the architect recommend?

  1. A

    Configure a network policy that allows only the company’s corporate egress IP ranges and approved application subnet IP ranges, then apply it at the account level

  2. B

    Enable Tri-Secret Secure so that only clients from approved networks can decrypt data and connect to Snowflake

  3. C

    Create masking policies on sensitive columns so unauthorized network locations cannot query protected data

  4. D

    Use SCIM provisioning with the identity provider so only users from approved networks can sign in to Snowflake

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use a Snowflake network policy with approved IP allowlists and apply it at the account level. Network policies are designed specifically to control access to Snowflake based on client IP addresses. This is the appropriate solution when the requirement is to prevent access from the public internet, even for users with valid credentials, while keeping the existing authentication approach largely unchanged.

In Snowflake, network policies can define allowed and blocked IP lists, and they can be associated at the account or user level. For broad enforcement across the environment, account-level application is the standard design choice. This aligns with Snowflake security best practices of layering identity controls, such as SSO and MFA, with network-based restrictions for stronger defense in depth.

The distractors represent common misunderstandings: encryption features such as Tri-Secret Secure protect data confidentiality but do not control network origin; masking policies govern data exposure after access is established, not whether a connection is allowed; and SCIM handles provisioning, not runtime network validation. Snowflake documentation on network policies and security best practices supports using network policies for IP-based access control.

  • A. Correct.

    Correct. Snowflake network policies are the native network-level control used to restrict login access based on client IP addresses. Applying a network policy at the account level is the most direct way to enforce that only approved corporate egress IPs and application subnets can connect. This satisfies the requirement to block public internet access even if someone has valid credentials, because authentication attempts from non-approved IP addresses are denied before access is granted.

  • B. Incorrect.

    Incorrect. Tri-Secret Secure is a key management and encryption control, not a network access control. It adds customer-managed key involvement to data protection, but it does not restrict which source IPs can establish sessions or authenticate to Snowflake.

  • C. Incorrect.

    Incorrect. Masking policies protect the visibility of data at query time based on role or context, but they do not prevent account login or network connectivity. Someone connecting from an unapproved network could still attempt authentication unless a separate network restriction is configured.

  • D. Incorrect.

    Incorrect. SCIM provisioning automates user and group lifecycle management between an identity provider and Snowflake. It does not enforce source network restrictions during sign-in. Identity management and network access control address different security requirements.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam