CertKeen

SnowPro Advanced: Architect · Free practice question 7 of 10

Network security

A financial-services company's security team requires that all Snowflake traffic from their VPC in AWS travel over private connectivity (no public internet) AND that Snowflake accept connections only from that VPC. Which two Snowflake features together implement this? (Choose two.)

  1. A.AWS PrivateLink for private connectivity between the VPC and Snowflake.
  2. B.A network policy restricting the account to the VPC's PrivateLink endpoint IDs / IP ranges.
  3. C.A row access policy applied to every base table.
  4. D.A masking policy on every sensitive column.
  5. E.Enabling public endpoint SSL with a custom TLS certificate.
Show answer and explanation

Correct answers: A. AWS PrivateLink for private connectivity between the VPC and Snowflake. · B. A network policy restricting the account to the VPC's PrivateLink endpoint IDs / IP ranges.

Why: PrivateLink establishes a private route between the VPC and Snowflake; a network policy enforces that only the PrivateLink endpoint IDs (or the VPC's private IPs) are allowed to connect. Row access and masking policies control data visibility, not network access. Public endpoints with SSL still traverse the internet.

More free SnowPro Advanced: Architect questions