ARA-C01 exam dumps

ARA-C01 practice question 98 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 98

Select 2Google Cloud Private Service Connect

A company runs Snowflake on Google Cloud and must ensure that analytics users in several GCP projects connect to Snowflake without traversing the public internet. The security team also wants to avoid broad VPC peering and prefers a service-consumer model where each consuming VPC can expose a private endpoint locally. The architect plans to use Google Cloud Private Service Connect (PSC) for inbound client connectivity to Snowflake. Which TWO actions are required to implement this design correctly?

  1. A

    Create a PSC endpoint in each consumer VPC and configure private DNS so the Snowflake account URL resolves to the PSC endpoint IP address.

  2. B

    Configure VPC Network Peering between each consumer VPC and Snowflake's VPC, because PSC requires peering before endpoints can be used.

  3. C

    Authorize the Google Cloud PSC endpoint(s) in Snowflake so that Snowflake accepts connections from those endpoint attachments.

  4. D

    Use a Google Cloud external HTTP(S) Load Balancer in front of Snowflake and publish its public IP in DNS, because PSC only supports outbound private connectivity from Snowflake.

  5. E

    Create a single PSC endpoint in one shared VPC and rely on transitive routing so all other peered VPCs can automatically use that endpoint without additional configuration.

Show answer and explanation

Correct answers: A, C

Explanation

The best answer is to create PSC endpoints in the consuming VPCs and configure DNS appropriately, then authorize those PSC endpoints in Snowflake. This aligns with Google Cloud Private Service Connect's consumer-producer model and Snowflake's private connectivity process on GCP. PSC is used to expose a private endpoint inside the consumer VPC for access to a published service, avoiding the need for broad VPC peering. In practice, architects must handle both sides of the configuration: the GCP networking objects and the Snowflake-side approval/authorization of the endpoint. Private DNS is also essential so client applications resolve the Snowflake account URL to the private PSC endpoint rather than a public address. These behaviors are consistent with Snowflake private connectivity guidance for Google Cloud and Google Cloud documentation for Private Service Connect.

  • A. Correct.

    Correct. For inbound private connectivity with Google Cloud PSC, the consumer creates a PSC endpoint in its own VPC. Clients then need DNS configured so the Snowflake hostname they use resolves privately to that endpoint address rather than to a public endpoint. This is a core implementation step; without the private DNS mapping, clients may continue to resolve Snowflake to public addresses.

  • B. Incorrect.

    Incorrect. PSC is specifically designed to provide private service access without requiring full VPC Network Peering. Choosing peering here reflects a common misconception that all private cross-network connectivity in GCP requires peering. One of PSC's advantages is reducing the blast radius and routing complexity associated with broad peering.

  • C. Correct.

    Correct. In addition to creating the endpoint on the GCP side, the endpoint must be authorized/associated on the Snowflake side so Snowflake will accept traffic from that PSC attachment. Creating the GCP endpoint alone is not sufficient; Snowflake must recognize and allow the private endpoint connection.

  • D. Incorrect.

    Incorrect. Snowflake inbound private connectivity on GCP does not require customers to front Snowflake with their own external load balancer, and doing so would reintroduce public exposure. PSC supports private connectivity to published services, so this option misunderstands both the purpose of PSC and Snowflake's supported private connectivity model.

  • E. Incorrect.

    Incorrect. PSC connectivity is not something you typically create once and then consume transitively across all peered VPCs as if it were a shared routed service. Relying on transitive routing is a common networking mistake in GCP designs. Access patterns, DNS, and endpoint placement must be designed explicitly, and automatic transitive usage across peered networks is not the correct assumption for Snowflake PSC connectivity.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam