SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 66 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 66

Single answerConfigure and troubleshoot private connectivity and storage integrations:

A security engineer is configuring an external stage in Snowflake to load sensitive files from an Amazon S3 bucket through private connectivity. The company has a policy that traffic to the bucket must not traverse the public internet. The engineer creates a storage integration and points the stage to an S3 URL, but test queries fail with an access error. Review of the cloud environment shows that the S3 bucket policy only allows requests that originate from a specific AWS VPC endpoint. Which action should the engineer take to make the integration work while keeping traffic private?

  1. A

    Update the S3 bucket policy to allow the AWS IAM user or role generated for the Snowflake storage integration, and use Snowflake's S3 private connectivity configuration for the account so Snowflake accesses S3 through the configured private endpoint path.

  2. B

    Replace the storage integration with direct AWS access keys in the stage definition, because private connectivity is only supported for key-based authentication to S3.

  3. C

    Create a network policy in Snowflake that allows only the corporate CIDR ranges, because external stage traffic to S3 inherits Snowflake client network policies.

  4. D

    Configure the stage to use an internal named stage first, then copy the files from the internal stage to S3 so that Snowflake can reuse internal private links automatically.

Show answer and explanation

Correct answer: A

Explanation

This scenario tests both storage integration troubleshooting and private connectivity design. In Snowflake, an S3 storage integration relies on a Snowflake-generated AWS IAM principal that must be granted access in the S3 bucket policy. If an organization also requires private connectivity, the Snowflake account must be configured for supported private connectivity to S3 so that data plane traffic does not use the public internet. A common mistake is assuming Snowflake outbound access to S3 is controlled by Snowflake network policies or that direct access keys are required for private access; neither is true. Best practice is to use storage integrations instead of embedded credentials, validate the generated IAM role/user details from the integration, and align the S3 bucket policy and private connectivity configuration accordingly. Candidates should be familiar with Snowflake documentation on storage integrations for Amazon S3 and account-level private connectivity options for cloud storage access.

  • A. Correct.

    Correct. For S3 storage integrations, Snowflake uses an AWS IAM principal that must be authorized in the bucket policy. In addition, if the requirement is to keep traffic off the public internet, the account must be configured to use Snowflake-supported private connectivity for accessing S3. A bucket policy that only allows a customer-managed VPC endpoint without also permitting the Snowflake-authorized principal and private connectivity path will block access. The practical fix is to align the S3 bucket policy with the storage integration's IAM trust model and ensure Snowflake private connectivity to S3 is configured for the account.

  • B. Incorrect.

    Incorrect. Storage integrations are the recommended and more secure approach for external stages because they avoid embedded long-lived cloud credentials. Private connectivity to S3 is not limited to key-based authentication. Reverting to access keys would reduce security and would not by itself satisfy the private routing requirement.

  • C. Incorrect.

    Incorrect. Snowflake network policies control client access to Snowflake endpoints, not Snowflake's outbound access from an external stage to cloud storage. Restricting corporate CIDR ranges may be useful for user access hardening, but it does not fix S3 access errors for storage integrations or enforce private connectivity between Snowflake and S3.

  • D. Incorrect.

    Incorrect. Internal stages are Snowflake-managed storage and are unrelated to how Snowflake connects to an external S3 bucket for an external stage. There is no mechanism where using an internal stage causes Snowflake to "reuse" private connectivity to the customer's S3 bucket. This option confuses internal stage architecture with external stage private networking.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam