Courseiva

COF-C03 Data Loading, Unloading, and Connectivity Practice Question

A data engineer is using the COPY INTO command to unload data from a Snowflake table to an external stage (Amazon S3). The engineer wants to ensure the unloaded files are encrypted and can be decrypted by the target system. Which TWO statements are true regarding the encryption of unloaded files? (Choose two.)

⚠ Common exam trap

The trap here is assuming that unloaded files are unencrypted by default or that a single encryption method always applies, when Snowflake enforces encryption and offers multiple configurable options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client-side encryption with a master key requires the target system to use the same master key to decrypt the files.

For unloading to an external stage, Snowflake supports both server-side encryption (e.g., SSE-S3, SSE-KMS) and client-side encryption with a master key. Server-side encryption relies on the cloud provider's encryption, while client-side encryption encrypts data before upload, requiring the target system to have the master key. Both methods ensure data is encrypted at rest and can be decrypted by authorized parties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Client-side encryption with a master key requires the target system to use the same master key to decrypt the files.

    Why this is correct

    With client-side encryption, Snowflake encrypts the files before uploading them to the external stage using a master key you provide. The target system must possess the same master key to decrypt the files. This provides end-to-end encryption but requires secure key management and distribution to the consuming system.

  • ✓

    Snowflake supports server-side encryption with Amazon S3-managed keys (SSE-S3) for unloaded files when the external stage is configured accordingly.

    Why this is correct

    When unloading to an external stage, you can specify server-side encryption using SSE-S3 or SSE-KMS. If the stage is configured with these options, Snowflake will request S3 to encrypt the files upon write. This allows the target system to decrypt using the appropriate S3 permissions and keys, ensuring secure data at rest.

  • ✗

    Unloaded files are always encrypted with AES-256 regardless of the encryption settings on the external stage.

    Why it's wrong here

    The encryption method and key size depend on the stage's encryption settings. While Snowflake may use strong encryption, it is not always AES-256. For example, client-side encryption uses a 128-bit key by default. Server-side encryption options vary. The statement that files are always encrypted with AES-256 is incorrect.

  • ✗

    By default, Snowflake uses client-side encryption with a 128-bit key to encrypt unloaded files.

    Why it's wrong here

    Snowflake does not use client-side encryption by default for unloaded files. By default, files are encrypted using server-side encryption with Snowflake-managed keys if the external stage does not specify encryption. Client-side encryption requires explicit configuration with a master key, and the default key size is 128-bit, but it is not the default behavior.

  • ✗

    If no encryption is specified for the external stage, unloaded files are not encrypted and are stored in plaintext.

    Why it's wrong here

    Snowflake automatically encrypts unloaded files even if no encryption is specified on the external stage. By default, it uses server-side encryption with Snowflake-managed keys. Files are never stored in plaintext. However, to use your own keys or client-side encryption, you must explicitly configure the stage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.