SnowPro Advanced: Security Engineer exam dumps

SnowPro Advanced: Security Engineer practice question 70 of 431

SnowPro® Advanced: Security Engineer. Professional level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Advanced: Security Engineer Question 70

Single answerTroubleshoot private connectivity issues

A security engineer has configured private connectivity between an AWS VPC and a Snowflake account using AWS PrivateLink. Users report that connections fail only when they use the account URL that was provided for private access, while the standard Snowflake public URL still works from the same client machines. The network team confirms that the interface VPC endpoint is in the Available state and the security group allows outbound TCP 443. Which action is the most likely to resolve the issue?

  1. A

    Update DNS so the Snowflake account hostname used for private access resolves to the AWS PrivateLink interface endpoint instead of the public Snowflake service address

  2. B

    Grant the SECURITYADMIN role to all affected users so they can authenticate over the private endpoint

  3. C

    Recreate the Snowflake account in the same cloud region so the private endpoint and account are guaranteed to align

  4. D

    Disable OCSP checks in all Snowflake clients because certificate validation blocks private connectivity

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical troubleshooting of Snowflake private connectivity. In AWS PrivateLink deployments, a frequent root cause is that the client resolves the Snowflake hostname to a public IP or public service address instead of the interface VPC endpoint's private address. Even when the VPC endpoint is healthy and security groups permit traffic, private access will fail if DNS is not configured correctly. Snowflake documentation for private connectivity emphasizes validating provider-side endpoint status, approved endpoint configuration, and especially DNS resolution for the account URL used over private connectivity. Best practice is to verify that the exact Snowflake account hostname for private access resolves internally to the provider-specific private endpoint and that clients use that hostname consistently.

  • A. Correct.

    Correct. A common cause of private connectivity failure is incomplete or incorrect DNS configuration. With AWS PrivateLink, clients must resolve the Snowflake account URL intended for private access to the private interface endpoint rather than to Snowflake's public endpoint. If the public URL still works but the private URL does not, and the VPC endpoint itself is healthy, DNS resolution is one of the first things to validate. Snowflake private connectivity setups rely on provider-specific DNS mapping so traffic stays on the private network path.

  • B. Incorrect.

    Incorrect. Snowflake roles such as SECURITYADMIN control privileges inside Snowflake, not network path selection or endpoint routing. Authentication and authorization problems would typically produce login or access errors, not a failure specific to the private URL while the public URL continues to work from the same machines.

  • C. Incorrect.

    Incorrect. Recreating the account is unnecessary and not a standard troubleshooting step for PrivateLink issues. Private connectivity requires the Snowflake account and the private connectivity configuration to be supported in the relevant cloud region, but if the public URL works and the private endpoint is already provisioned, the more likely issue is DNS or endpoint configuration rather than the need to recreate the account.

  • D. Incorrect.

    Incorrect. OCSP behavior can affect connectivity in some environments, but it would not typically explain why only the private account URL fails while the public URL works from the same client machines. Also, disabling OCSP is not the primary or recommended troubleshooting action for a PrivateLink routing issue. The symptom points more directly to name resolution or endpoint targeting.

Timed practice exam

Take a SnowPro Advanced: Security Engineer practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam