SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 69 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 69

Single answerAWS PrivateLink, Azure Private Link, and GCP Private Service Connect

A security engineer must ensure that users and applications connect to Snowflake only through private network paths from three different cloud environments: AWS, Azure, and GCP. The company wants to eliminate exposure to the public internet for client connectivity wherever Snowflake supports it, while preserving standard Snowflake authentication and authorization controls. Which approach should the engineer implement?

  1. A

    Configure AWS PrivateLink, Azure Private Link, and GCP Private Service Connect for Snowflake, and have clients use the corresponding private connectivity endpoints and private DNS names for each cloud.

  2. B

    Use AWS Direct Connect, Azure ExpressRoute, and GCP Cloud Interconnect only, because these services automatically provide private application-layer connectivity to Snowflake without any Snowflake-specific private endpoint configuration.

  3. C

    Restrict access with Snowflake network policies that allow only the company NAT gateway public IPs, because network policies alone guarantee that traffic never traverses the public internet.

  4. D

    Deploy a self-managed reverse proxy in each cloud VPC/VNet and publish Snowflake through the proxy, because Snowflake does not support native private connectivity services across major cloud providers.

Show answer and explanation

Correct answer: A

Explanation

The best solution is to use Snowflake's supported private connectivity mechanisms in each cloud: AWS PrivateLink, Azure Private Link, and GCP Private Service Connect. These services provide private access to Snowflake endpoints so client traffic does not traverse the public internet. This is the appropriate control when the requirement is about network path isolation rather than just source-IP restriction. Snowflake network policies remain useful as an additional layer of control, but they do not provide private transport by themselves. Likewise, provider transport services such as AWS Direct Connect, Azure ExpressRoute, and Google Cloud Interconnect may be part of an enterprise network architecture, but they do not replace Snowflake's private endpoint configuration. This aligns with Snowflake guidance on private connectivity and business-critical security architectures across AWS, Azure, and GCP.

  • A. Correct.

    Correct. Snowflake supports private client connectivity using the cloud-native private endpoint services: AWS PrivateLink, Azure Private Link, and GCP Private Service Connect. In a multi-cloud enterprise, the secure design is to provision the appropriate private connectivity integration per cloud and route client traffic to Snowflake using the private endpoints and associated private DNS configuration. This keeps client traffic off the public internet while leaving Snowflake authentication, RBAC, MFA, SSO, and other account-level controls unchanged.

  • B. Incorrect.

    Incorrect. Direct Connect, ExpressRoute, and Cloud Interconnect provide private or dedicated network transport into the cloud provider, but they do not by themselves create the private application endpoint to Snowflake. Snowflake private connectivity still requires the cloud-specific private endpoint service configuration. A common misconception is treating backbone connectivity services as equivalent to PrivateLink/Private Link/PSC; they solve different layers of the problem.

  • C. Incorrect.

    Incorrect. Network policies can restrict which source IP addresses may connect to Snowflake, but they do not change the path of the traffic. If users connect to Snowflake public endpoints from allowed public IPs, the traffic can still traverse the public internet. Network policies are complementary access controls, not a substitute for private connectivity.

  • D. Incorrect.

    Incorrect. Snowflake does support native private connectivity through AWS PrivateLink, Azure Private Link, and GCP Private Service Connect. Introducing customer-managed reverse proxies adds unnecessary complexity, operational risk, certificate management burden, and potential security issues. It is not the recommended architecture when Snowflake-supported private endpoint services are available.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam