
SnowflakeSnowPro Advanced — Architect
Domain 1Objective 3
Implement Data Protection and Encryption ARA-C01 Practice Questions (Page 5)
Part of the Accounts and Security domain, which accounts for 26% of the ARA-C01 exam.
29questions here
6free pages
10concepts
26%of the exam
Questions 21–25
- 21
Which encryption options are available for external stages in Snowflake?
Select an answer first - 22
A multinational company has a Snowflake account with a masking policy on a sensitive column. The policy currently masks data for all roles except the 'ADMIN' role. The compliance team has a new requirement: users in the 'FINANCE' role should also see the actual data, but only when they are connected from the corporate network. Which approach should be used?
Select an answer first - 23
A data analyst needs to unload a query result to an external stage on Azure Blob Storage. The security team requires that the data be encrypted in transit and at rest. Which combination of settings should be used in the COPY INTO <location> command?
Select an answer first - 24
A company is required to use customer-managed keys for Snowflake encryption. They have enabled Tri-Secret Secure with AWS KMS. The security team wants to ensure that if the AWS KMS key is deleted, Snowflake data remains recoverable. What should they do?
Select an answer first - 25
A healthcare organization is required to use customer-managed encryption keys to meet regulatory compliance. They have enabled Tri-Secret Secure with Azure Key Vault. The security team wants to understand what happens if the Azure Key Vault key is temporarily unavailable. Which statement accurately describes the impact on Snowflake data access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Snowflake. “ARA-C01” is a trademark of its owner, used for identification only.