COF-C03 exam dumps

COF-C03 practice question 345 of 350

SnowPro® Core Certification (COF-C03). Associate level, Snowflake. Free question with the correct answer and a full explanation.

COF-C03 Question 345

Single answerPrivate

A financial services company uses Snowflake Business Critical Edition and must ensure that all traffic between its AWS-hosted applications and Snowflake does not traverse the public internet. The security team also wants to reduce the risk of users connecting from unmanaged networks. Which solution best meets these requirements?

  1. A

    Configure AWS PrivateLink for the Snowflake account and restrict access using network policies that allow only approved private connectivity paths

  2. B

    Enable Tri-Secret Secure and require key rotation, because this prevents public internet access to Snowflake endpoints

  3. C

    Create reader accounts for application users, because reader accounts isolate traffic from the public internet

  4. D

    Use a larger virtual warehouse and disable result caching, because this keeps query processing inside Snowflake and avoids public endpoints

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use private connectivity with the cloud provider's private networking service, in AWS, that is AWS PrivateLink. For SnowPro Core, candidates should understand that private connectivity is a network architecture feature used to keep traffic off the public internet when connecting to Snowflake. This capability is commonly associated with higher security and compliance requirements and is available for editions such as Business Critical. Network policies complement private connectivity by restricting allowed source locations and reducing the risk of access from unmanaged networks. By contrast, Tri-Secret Secure addresses encryption and key management, reader accounts address data sharing scenarios, and warehouse or cache settings affect compute behavior rather than connectivity. This aligns with Snowflake documentation and best practices around private connectivity and network policies.

  • A. Correct.

    Correct. For Snowflake on AWS, AWS PrivateLink provides private connectivity between customer-managed AWS environments and Snowflake without routing traffic over the public internet. In addition, network policies can restrict which IP addresses or endpoints may connect, helping enforce access only from approved managed networks. This is the standard approach for organizations that require private connectivity to Snowflake.

  • B. Incorrect.

    Incorrect. Tri-Secret Secure is related to encryption key management and adds customer-managed key control in addition to Snowflake-managed protections, but it does not change the network path used to access Snowflake. It does not provide private network connectivity or prevent use of public endpoints.

  • C. Incorrect.

    Incorrect. Reader accounts are used to share data with consumers who do not have their own Snowflake account. They are not a networking feature and do not ensure private connectivity between applications and Snowflake.

  • D. Incorrect.

    Incorrect. Warehouse size and result caching affect compute performance and query behavior, not network routing. These settings do nothing to prevent traffic from traversing the public internet or to restrict client connectivity paths.

Timed practice exam

Take a COF-C03 practice test under exam conditions

100 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam