COF-C03 exam dumps

COF-C03 practice question 144 of 350

SnowPro® Core Certification (COF-C03). Associate level, Snowflake. Free question with the correct answer and a full explanation.

COF-C03 Question 144

Single answerNetwork Policies

A security administrator needs to restrict Snowflake access so that employees can connect only from the corporate office public IP range, while a specific contractor must be able to connect from a home office IP that is outside the corporate range. The company wants the contractor exception to apply only to that user without widening access for everyone else. Which approach should the administrator use?

  1. A

    Create an account-level network policy that includes both the corporate IP range and the contractor's home IP address, then assign it to the account.

  2. B

    Create an account-level network policy for the corporate IP range, create a separate user-level network policy for the contractor's home IP address, and assign the user-level policy to the contractor.

  3. C

    Create a user-level network policy for the contractor and a second user-level network policy for all employees, because user-level policies are the only supported way to control Snowflake sign-in locations.

  4. D

    Create a network rule for the contractor IP and attach it directly to the contractor role so that the role overrides the account network policy during login.

Show answer and explanation

Correct answer: B

Explanation

The best solution is to use layered assignment: an account-level network policy for the standard corporate IP range and a user-level network policy for the contractor. In Snowflake, when both exist, the user-level network policy applies to that specific user, making it the correct mechanism for handling exceptions without broadening access for the entire account. This matches Snowflake security best practices of least privilege and minimizing exposure. Snowflake documentation on network policies describes using allowed and blocked IP lists and supports assigning policies at both the account and user levels, with the user-level assignment taking precedence for that user.

  • A. Incorrect.

    Incorrect. This would technically allow the contractor to connect, but it also expands the account-wide allowed IP list to include the contractor's home IP for all users. That violates the requirement to keep the exception limited to one user. A common mistake is assuming account-level policies are suitable for user-specific exceptions; in practice, they affect the entire account when assigned at the account level.

  • B. Correct.

    Correct. This is the appropriate design for the stated requirement. In Snowflake, a network policy can be assigned at the account level and also at the user level. A user-level network policy takes precedence for that user, allowing the administrator to keep the corporate IP restriction in place for the account while granting a narrower exception to the contractor only.

  • C. Incorrect.

    Incorrect. Snowflake supports both account-level and user-level network policies. Saying user-level policies are the only supported mechanism is factually wrong. Also, assigning user-level policies to all employees would be less maintainable than using a single account-level policy for the common corporate range.

  • D. Incorrect.

    Incorrect. Network policies are not attached to roles for login control. Authentication network restrictions are applied through network policies assigned to the account or to individual users. This option confuses network access control with role-based object access control.

Timed practice exam

Take a COF-C03 practice test under exam conditions

100 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam