SnowPro Specialty: Gen AI exam dumps

SnowPro Specialty: Gen AI practice question 219 of 287

SnowPro® Specialty: Gen AI. Expert level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Specialty: Gen AI Question 219

Single answerRestrict access to specific models

A Snowflake administrator is enabling Cortex AISQL for multiple business units. The legal team requires that analysts in the FINANCE role can use only an approved set of models for text generation and must not be able to invoke other available models. The administrator wants a control that enforces this at the model level rather than relying on application-side checks. Which action should the administrator take?

  1. A

    Grant the FINANCE role access only to the specific Cortex models it is allowed to use, and do not grant access to other models

  2. B

    Create a network policy for the FINANCE role so users can call only approved models from trusted IP addresses

  3. C

    Restrict the warehouse used by FINANCE so it can execute prompts only against approved models

  4. D

    Use masking policies on prompt columns so unapproved model names are hidden from FINANCE users

Show answer and explanation

Correct answer: A

Explanation

The key requirement is to enforce access at the model level, not through client logic or indirect controls. In Snowflake Cortex, access to specific models is managed with privileges granted to roles, allowing administrators to permit only approved models for particular users or teams. This follows the principle of least privilege and is the appropriate governance mechanism when different business units must be limited to different model sets. Network policies, warehouses, and masking policies address other security or data-governance concerns, but they do not provide model-level authorization. Candidates should recognize that restricting access to specific models is done through Snowflake role-based access control on the models themselves, consistent with Snowflake documentation and best practices for Cortex governance.

  • A. Correct.

    Correct. To restrict access to specific Cortex models, Snowflake supports model-level access control. The administrator should grant the FINANCE role privileges only on the approved models and withhold access to other models. This is the direct, enforceable control for limiting which models a role can invoke.

  • B. Incorrect.

    Incorrect. Network policies control where users can connect from, not which Cortex models they are allowed to use. While IP restrictions may improve security, they do not satisfy the requirement to restrict access to specific models.

  • C. Incorrect.

    Incorrect. Warehouses provide compute resources for workloads, but they do not determine which Cortex models a role can call. Model authorization is not enforced through warehouse assignment.

  • D. Incorrect.

    Incorrect. Masking policies protect sensitive data values in query results or columns, but they do not enforce authorization on model usage. Hiding model names in data does not prevent a user from invoking a model if the role still has access.

Timed practice exam

Take a SnowPro Specialty: Gen AI practice test under exam conditions

55 questions in 85 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam