ADA-C01 exam dumps

ADA-C01 practice question 112 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 112

Single answerImplement and manage cloud provider interfaces and private endpoints for internal stages

A financial services company uses an Amazon S3 bucket as the backing storage location for a Snowflake internal stage used by multiple business units. The security team requires that all traffic between Snowflake and the S3 bucket remain on the AWS private network and not traverse the public internet. An administrator has already created the necessary AWS PrivateLink endpoint and associated DNS configuration. Which additional Snowflake action is required so the internal stage uses the private connectivity path?

  1. A

    Create or alter the internal stage to specify the AWS_VPCE_ID parameter that matches the AWS PrivateLink endpoint ID.

  2. B

    Create a network policy that restricts user access to the S3 bucket hostname so Snowflake automatically switches to the private route.

  3. C

    Create a storage integration for the internal stage and set ENABLED = TRUE so Snowflake can use the VPC endpoint for internal stage traffic.

  4. D

    Alter the account and set PRIVATELINK = TRUE for all stages so Snowflake routes internal stage traffic over the private endpoint.

Show answer and explanation

Correct answer: A

Explanation

The key requirement is to ensure that traffic between Snowflake and the cloud storage backing an internal stage stays on the cloud provider's private network. On AWS, after the AWS PrivateLink endpoint and DNS are established, Snowflake must be told which private endpoint to use for the relevant internal stage by specifying the VPC endpoint identifier in the stage configuration. Candidates often confuse this with external-stage features such as storage integrations, or with Snowflake client connectivity controls such as network policies and account-level PrivateLink settings. Snowflake documentation for internal stages and private connectivity to cloud storage explains that both the cloud-provider-side private endpoint configuration and the Snowflake stage configuration are required.

  • A. Correct.

    Correct. For internal stages backed by Amazon S3, Snowflake can be configured to use private connectivity by associating the stage with the AWS VPC endpoint identifier. This is done through the stage definition so Snowflake knows which private endpoint to use for traffic to the backing storage. The AWS networking components and DNS must already exist, but Snowflake still needs the stage-level configuration that references the endpoint.

  • B. Incorrect.

    Incorrect. Network policies in Snowflake control client access to Snowflake based on IP rules; they do not control how Snowflake reaches cloud storage for stage operations. Restricting user access to an S3 hostname would not cause Snowflake's internal stage traffic to use PrivateLink.

  • C. Incorrect.

    Incorrect. Storage integrations are used for external stages, not internal stages. Internal stages are managed by Snowflake, and their private connectivity configuration is not enabled by creating a storage integration. This option reflects a common confusion between external stage authentication/authorization and internal stage private networking.

  • D. Incorrect.

    Incorrect. There is no account-level setting that globally enables private endpoint routing for all internal stages in this manner. Private connectivity for internal stage backing storage requires the appropriate stage configuration rather than a blanket account parameter.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam