ADA-C01 exam dumps

ADA-C01 practice question 102 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 102

Single answer1.6 Set up and manage network and private connectivity.

A financial services company has a Snowflake account on AWS that must be accessed only from resources inside its AWS VPCs. The security team does not want traffic to traverse the public internet, and they also want to prevent users from connecting from home networks even if they have valid Snowflake credentials. The company has already provisioned AWS PrivateLink endpoints for Snowflake in the VPCs used by its analytics applications. Which additional configuration should the Snowflake administrator implement to best meet these requirements?

  1. A

    Create a network policy that allows only the organization’s public NAT gateway IP addresses, and rely on PrivateLink for private routing when available.

  2. B

    Create a network rule containing the AWS VPCE IDs for the approved PrivateLink endpoints, then create a network policy that allows only those VPCE IDs and assign it to the account or relevant users.

  3. C

    Enable Tri-Secret Secure so that only traffic from approved private endpoints can authenticate to Snowflake.

  4. D

    Configure client redirect so users are automatically routed to the nearest Snowflake endpoint, which avoids public internet exposure.

Show answer and explanation

Correct answer: B

Explanation

To satisfy both requirements in the scenario, the administrator must combine private connectivity with access control that explicitly permits only approved private endpoints. On AWS, Snowflake private connectivity is implemented with AWS PrivateLink. However, provisioning PrivateLink alone does not automatically prevent users from connecting over Snowflake’s public endpoint if that endpoint remains reachable and credentials are valid. To enforce the intended restriction, Snowflake administrators should use network rules and network policies that allow only the designated private endpoint identifiers (for AWS, VPCE IDs). This approach is more precise than IP-based allowlisting because it validates the approved private connectivity path itself rather than just the apparent source IP. This aligns with Snowflake best practices for network access management and private connectivity, where network policies are used to restrict client connections and can be configured to work with private connectivity identifiers.

  • A. Incorrect.

    This is not the best solution for the stated requirement. Allowlisting public NAT gateway IP addresses can restrict access by source IP, but it does not enforce that clients use AWS PrivateLink. Traffic could still originate from those public IPs and connect over Snowflake’s public endpoint. The scenario specifically requires access only from resources inside approved VPCs and no public internet path. A common misconception is that IP allowlisting alone guarantees private connectivity; it does not.

  • B. Correct.

    This is correct. For AWS PrivateLink-based restrictions, Snowflake supports network rules and network policies that can evaluate private connectivity identifiers such as AWS VPCE IDs. By defining a network rule with the approved VPC endpoint IDs and then using a network policy to allow only those private endpoints, the administrator can ensure that connections are accepted only when they come through the company’s authorized PrivateLink endpoints. Assigning the policy at the account level or to specific users further enforces that users cannot connect from home networks or other non-approved paths, even with valid credentials.

  • C. Incorrect.

    This is incorrect. Tri-Secret Secure is a key management and encryption feature involving customer-managed keys in addition to Snowflake-managed protections. It does not control network path selection, PrivateLink enforcement, or client source restrictions. Someone might choose this option because it sounds security-related, but it addresses encryption governance rather than network connectivity controls.

  • D. Incorrect.

    This is incorrect. Client redirect helps reroute clients during failover or business continuity scenarios and can abstract connection endpoints for applications, but it does not force use of private connectivity or block public internet access. It is not a network access control mechanism. This distractor targets the misconception that endpoint-routing features also enforce network isolation.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam