COF-C03 Data Loading, Unloading, and Connectivity Practice Question
A data engineer is configuring a Snowflake external stage that points to an Amazon S3 bucket. The bucket is in the same region as the Snowflake account. The engineer wants to avoid embedding long-lived AWS credentials in the stage definition and instead use a secure, temporary credential mechanism. Which authentication method should be used for the external stage?
⚠ Common exam trap
The trap here is assuming that embedding AWS keys in the stage definition is acceptable for production or that Snowflake supports AWS IAM database authentication directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a storage integration with an IAM role and external ID.
The secure and recommended way to grant Snowflake access to an external S3 bucket without embedding long-lived credentials is to create a storage integration. This integration establishes a trust relationship between Snowflake and AWS, allowing Snowflake to assume an IAM role and obtain temporary credentials. The other options either embed static keys or confuse AWS IAM features with Snowflake capabilities, failing to meet the security requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Snowflake user with an AWS IAM policy attached directly.
Why it's wrong here
Snowflake users are database principals and cannot have AWS IAM policies attached. IAM policies are managed in AWS and apply to AWS identities such as IAM users or roles. This option confuses Snowflake access control with AWS access control and would not provide any authentication mechanism for the external stage.
- ✗
Enable AWS IAM database authentication on the Snowflake account.
Why it's wrong here
AWS IAM database authentication is a feature for Amazon RDS and Aurora databases, not for Snowflake. Snowflake does not support this mechanism for external stage authentication. It would not grant Snowflake access to S3 objects because the feature is specific to AWS-managed database engines and unrelated to Snowflake's storage integration model.
- ✗
Configure the stage with AWS_KEY_ID and AWS_SECRET_KEY parameters.
Why it's wrong here
Using AWS_KEY_ID and AWS_SECRET_KEY embeds long-lived credentials directly in the stage definition. This approach is insecure because the keys can be exposed to anyone with access to the stage metadata, and they do not expire. The scenario explicitly requires avoiding long-lived credentials, so this method fails to meet the security requirement.
- ✓
Use a storage integration with an IAM role and external ID.
Why this is correct
A storage integration creates a trust relationship between Snowflake and AWS IAM, allowing Snowflake to assume an IAM role and obtain temporary credentials. This avoids storing long-lived keys in Snowflake and is the recommended secure method for accessing external cloud storage. It satisfies the requirement to use temporary credentials without embedding secrets.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.