ADA-C01 exam dumps

ADA-C01 practice question 110 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 110

Single answerEstablish private connectivity to Snowflake internal stages and the Snowflake service

A financial services company must ensure that users in its AWS VPC access both the Snowflake service endpoint and files in Snowflake-managed internal stages without traversing the public internet. The account is Business Critical edition, and the network team wants traffic to remain on private AWS networking. Which action should the Snowflake administrator take to meet this requirement?

  1. A

    Configure AWS PrivateLink for the Snowflake account and enable private connectivity for internal stages so both the Snowflake service and Snowflake-managed stage access use private endpoints.

  2. B

    Create a storage integration that points to the internal stage and attach it to an AWS Interface VPC Endpoint so stage traffic is routed privately.

  3. C

    Restrict access with a network policy that allows only the corporate NAT gateway IPs; this guarantees that internal stage traffic does not use the public internet.

  4. D

    Use direct secure access to the organization account URL and configure client redirect so queries and internal stage file transfers automatically use private connectivity.

  5. E

    Replicate the internal stage contents to an external S3 bucket and access that bucket through a gateway endpoint; this provides private connectivity to Snowflake internal stages.

Show answer and explanation

Correct answer: A

Explanation

The key requirement is private access to both the Snowflake service endpoint and Snowflake-managed internal stages. In AWS, the correct approach is AWS PrivateLink, used with a Snowflake Business Critical (or higher) account. Snowflake documents private connectivity for the service itself and separate support for private connectivity to internal stages, which is necessary because stage file transfer endpoints are distinct from the core service endpoint. A common misconception is that IP allowlisting via network policies makes traffic private; it does not. Another common error is confusing internal stages with external stages and trying to use storage integrations, which apply only to customer-managed cloud storage. Best practice is to configure the Snowflake private endpoint(s) required for the account and enable private connectivity for internal stages so both SQL/API access and stage file transfers stay on cloud-provider private networking.

  • A. Correct.

    Correct. On AWS, private connectivity to Snowflake is established with AWS PrivateLink. For Business Critical (or higher) accounts, Snowflake supports private connectivity to the Snowflake service, and private connectivity can also be enabled for Snowflake-managed internal stages so file transfers to internal stages do not traverse the public internet. This is the direct solution to the stated requirement.

  • B. Incorrect.

    Incorrect. Storage integrations are used for external cloud storage such as customer-managed S3, GCS, or Azure Blob/ADLS locations, not for Snowflake internal stages. Internal stages are Snowflake-managed storage, so there is no storage integration to 'point' at them. Also, attaching a storage integration to an AWS Interface VPC Endpoint is not how Snowflake private stage connectivity is configured.

  • C. Incorrect.

    Incorrect. A network policy can restrict which source IP addresses may connect to Snowflake, but it does not change the transport path to private networking. Traffic can still traverse public internet paths before reaching Snowflake. Network policies are an access-control mechanism, not a private connectivity mechanism.

  • D. Incorrect.

    Incorrect. Organization URLs and client redirect help with account URL management and failover/business continuity patterns, but they do not by themselves establish private connectivity. Private networking still requires configuring the cloud provider private endpoint service and Snowflake private connectivity features.

  • E. Incorrect.

    Incorrect. Moving data to an external S3 bucket changes the architecture and does not provide private connectivity to Snowflake internal stages. Gateway endpoints are for S3 access within AWS, but the requirement specifically calls for Snowflake-managed internal stages and the Snowflake service to remain on private networking.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam