SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 68 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 68

Select 3AWS PrivateLink, Azure Private Link, and GCP Private Service Connect

A financial services company uses Snowflake in three separate cloud deployments: AWS for its main data platform, Azure for a regional analytics environment, and GCP for a recently acquired business unit. The security team must ensure that users and applications connect to Snowflake over private network paths only, without traversing the public internet, and wants an approach that aligns with each cloud provider's native private connectivity service. Which combination of actions should the security engineer implement?

  1. A

    On AWS, configure AWS PrivateLink endpoints for Snowflake and use the account's private connectivity URL for client access.

  2. B

    On Azure, configure Azure Private Link for Snowflake so clients connect through a private endpoint instead of the public Snowflake service endpoint.

  3. C

    On GCP, configure Private Service Connect to expose Snowflake service attachments privately to consumer VPCs and use the PSC endpoint for access.

  4. D

    On AWS, configure a site-to-site VPN to Snowflake because Snowflake does not support private endpoint-based connectivity on AWS.

  5. E

    On Azure and GCP, use network policies only; private connectivity is not supported for Snowflake, so access must still use public endpoints with IP allowlists.

Show answer and explanation

Correct answers: A, B, C

Explanation

The correct solution is to use each cloud provider's native private connectivity service that Snowflake supports: AWS PrivateLink on AWS, Azure Private Link on Azure, and GCP Private Service Connect on GCP. These services allow client traffic to stay on the cloud provider's private backbone instead of traversing the public internet. This is aligned with Snowflake best practices for organizations with strict network security or regulatory requirements. A key exam distinction is understanding that network policies, IP allowlists, VPNs, or public endpoints may restrict access patterns but do not inherently provide the same private endpoint-based connectivity model as PrivateLink, Private Link, or PSC. Candidates should also recognize that Snowflake uses private connectivity URLs/endpoints specific to these configurations. Refer to Snowflake documentation for private connectivity on AWS, Azure, and GCP, including the sections covering AWS PrivateLink, Azure Private Link, and Google Cloud Private Service Connect.

  • A. Correct.

    Correct. Snowflake supports AWS PrivateLink for private connectivity between customer VPCs and Snowflake services on AWS. In practice, customers create interface VPC endpoints and use Snowflake-provided private connectivity URLs so traffic remains on the AWS backbone rather than using public internet routing. This is the appropriate native AWS solution for private access to Snowflake.

  • B. Correct.

    Correct. Snowflake supports Azure Private Link, which allows clients in Azure VNets to reach Snowflake through private endpoints. This replaces use of the public service endpoint for those private connections and is the correct Azure-native approach when the requirement is to keep Snowflake access off the public internet.

  • C. Correct.

    Correct. On GCP, Snowflake supports private connectivity using Private Service Connect. Customers create PSC endpoints in their VPCs that connect to Snowflake service attachments, enabling private access over Google's network. This is the correct cloud-native design for GCP when private-only connectivity is required.

  • D. Incorrect.

    Incorrect. This distractor reflects a common misconception that private connectivity to Snowflake on AWS requires VPN or Direct Connect only. Snowflake does support AWS PrivateLink, which is specifically designed for private service access using endpoint-based connectivity. A VPN may be used for broader network connectivity use cases, but it is not the Snowflake-native private endpoint mechanism described in the scenario.

  • E. Incorrect.

    Incorrect. Snowflake supports private connectivity on both Azure and GCP using Azure Private Link and GCP Private Service Connect, respectively. Network policies and IP allowlists can help restrict who may connect, but they do not by themselves provide private network transport. The scenario explicitly requires private paths without public internet exposure, so relying on public endpoints with allowlists does not meet the requirement.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam