SnowPro Associate: Platform exam dumps

SnowPro Associate: Platform practice question 299 of 367

SnowPro® Associate: Platform Certification. Associate level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Associate: Platform Question 299

Single answer○ Enable

A Snowflake administrator wants to allow a third-party BI tool to connect to Snowflake using key pair authentication instead of passwords. The security team also requires that analysts continue to use their existing usernames and roles without creating separate service accounts. What should the administrator do to enable this access?

  1. A

    Generate a public-private key pair, assign the public key to each analyst user in Snowflake, and configure the BI tool to authenticate as that user with the corresponding private key

  2. B

    Create a network policy that whitelists the BI tool's IP addresses, because network policies enable key pair authentication for existing users

  3. C

    Enable Tri-Secret Secure for the account, because it allows external tools to authenticate without passwords while keeping existing usernames

  4. D

    Configure SCIM provisioning for the BI tool, because SCIM replaces passwords with key-based authentication for user sign-in

Show answer and explanation

Correct answer: A

Explanation

The best answer is to configure Snowflake key pair authentication for the existing users. In Snowflake, key pair authentication is a supported method for user authentication, commonly used by service integrations, scripts, and external tools that should avoid password-based login. The administrator stores the user's public key in Snowflake and the client presents the matching private key at login. This approach preserves each analyst's existing identity and role assignments. By contrast, network policies control network access only, SCIM handles user lifecycle management, and Tri-Secret Secure addresses encryption key control rather than login authentication. This aligns with Snowflake best practices for stronger authentication and reduced password usage in client connections.

  • A. Correct.

    Correct. Snowflake supports key pair authentication for users. To enable passwordless authentication for existing analyst identities, the administrator can generate a key pair for each user, assign the public key to the corresponding Snowflake user object, and configure the client or BI tool to use the matching private key when connecting as that user. This satisfies the requirement to keep the same usernames and roles rather than creating separate accounts.

  • B. Incorrect.

    Incorrect. Network policies restrict where users can connect from based on allowed or blocked IP addresses, but they do not enable or replace an authentication method. Whitelisting the BI tool's IPs may improve security, but it does not provide key pair authentication.

  • C. Incorrect.

    Incorrect. Tri-Secret Secure is a data protection feature related to encryption key management, not a user authentication mechanism. It does not allow external tools to log in without passwords or configure user-level key pair authentication.

  • D. Incorrect.

    Incorrect. SCIM is used for automated provisioning and deprovisioning of users and groups, typically with identity providers. It does not authenticate users to Snowflake and does not replace passwords with key pair authentication for client connections.

Timed practice exam

Take a SnowPro Associate: Platform practice test under exam conditions

65 questions in 85 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam