COF-C03 Data Loading, Unloading, and Connectivity Practice Question
A data engineer is using the COPY INTO command to unload data from a Snowflake table to an external stage (Amazon S3). The engineer wants to ensure the unloaded files are encrypted and can be decrypted by the target system. Which TWO statements are true regarding the encryption of unloaded files? (Choose two.)
⚠ Common exam trap
The trap here is assuming that unloaded files are unencrypted by default or that a single encryption method always applies, when Snowflake enforces encryption and offers multiple configurable options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client-side encryption with a master key requires the target system to use the same master key to decrypt the files.
For unloading to an external stage, Snowflake supports both server-side encryption (e.g., SSE-S3, SSE-KMS) and client-side encryption with a master key. Server-side encryption relies on the cloud provider's encryption, while client-side encryption encrypts data before upload, requiring the target system to have the master key. Both methods ensure data is encrypted at rest and can be decrypted by authorized parties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Client-side encryption with a master key requires the target system to use the same master key to decrypt the files.
Why this is correct
With client-side encryption, Snowflake encrypts the files before uploading them to the external stage using a master key you provide. The target system must possess the same master key to decrypt the files. This provides end-to-end encryption but requires secure key management and distribution to the consuming system.
- ✓
Snowflake supports server-side encryption with Amazon S3-managed keys (SSE-S3) for unloaded files when the external stage is configured accordingly.
Why this is correct
When unloading to an external stage, you can specify server-side encryption using SSE-S3 or SSE-KMS. If the stage is configured with these options, Snowflake will request S3 to encrypt the files upon write. This allows the target system to decrypt using the appropriate S3 permissions and keys, ensuring secure data at rest.
- ✗
Unloaded files are always encrypted with AES-256 regardless of the encryption settings on the external stage.
Why it's wrong here
The encryption method and key size depend on the stage's encryption settings. While Snowflake may use strong encryption, it is not always AES-256. For example, client-side encryption uses a 128-bit key by default. Server-side encryption options vary. The statement that files are always encrypted with AES-256 is incorrect.
- ✗
By default, Snowflake uses client-side encryption with a 128-bit key to encrypt unloaded files.
Why it's wrong here
Snowflake does not use client-side encryption by default for unloaded files. By default, files are encrypted using server-side encryption with Snowflake-managed keys if the external stage does not specify encryption. Client-side encryption requires explicit configuration with a master key, and the default key size is 128-bit, but it is not the default behavior.
- ✗
If no encryption is specified for the external stage, unloaded files are not encrypted and are stored in plaintext.
Why it's wrong here
Snowflake automatically encrypts unloaded files even if no encryption is specified on the external stage. By default, it uses server-side encryption with Snowflake-managed keys. Files are never stored in plaintext. However, to use your own keys or client-side encryption, you must explicitly configure the stage.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.