Courseiva

COF-C03 Data Loading, Unloading, and Connectivity Practice Question

A data engineer is configuring a Snowflake external stage that points to an Amazon S3 bucket. The bucket is in the same region as the Snowflake account. The engineer wants to avoid embedding long-lived AWS credentials in the stage definition and instead use a secure, temporary credential mechanism. Which authentication method should be used for the external stage?

⚠ Common exam trap

The trap here is assuming that embedding AWS keys in the stage definition is acceptable for production or that Snowflake supports AWS IAM database authentication directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a storage integration with an IAM role and external ID.

The secure and recommended way to grant Snowflake access to an external S3 bucket without embedding long-lived credentials is to create a storage integration. This integration establishes a trust relationship between Snowflake and AWS, allowing Snowflake to assume an IAM role and obtain temporary credentials. The other options either embed static keys or confuse AWS IAM features with Snowflake capabilities, failing to meet the security requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Snowflake user with an AWS IAM policy attached directly.

    Why it's wrong here

    Snowflake users are database principals and cannot have AWS IAM policies attached. IAM policies are managed in AWS and apply to AWS identities such as IAM users or roles. This option confuses Snowflake access control with AWS access control and would not provide any authentication mechanism for the external stage.

  • ✗

    Enable AWS IAM database authentication on the Snowflake account.

    Why it's wrong here

    AWS IAM database authentication is a feature for Amazon RDS and Aurora databases, not for Snowflake. Snowflake does not support this mechanism for external stage authentication. It would not grant Snowflake access to S3 objects because the feature is specific to AWS-managed database engines and unrelated to Snowflake's storage integration model.

  • ✗

    Configure the stage with AWS_KEY_ID and AWS_SECRET_KEY parameters.

    Why it's wrong here

    Using AWS_KEY_ID and AWS_SECRET_KEY embeds long-lived credentials directly in the stage definition. This approach is insecure because the keys can be exposed to anyone with access to the stage metadata, and they do not expire. The scenario explicitly requires avoiding long-lived credentials, so this method fails to meet the security requirement.

  • ✓

    Use a storage integration with an IAM role and external ID.

    Why this is correct

    A storage integration creates a trust relationship between Snowflake and AWS IAM, allowing Snowflake to assume an IAM role and obtain temporary credentials. This avoids storing long-lived keys in Snowflake and is the recommended secure method for accessing external cloud storage. It satisfies the requirement to use temporary credentials without embedding secrets.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.