Courseiva

COF-C03 Practice Question: Snowflake AI Data Cloud Features and Architecture

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": { "AWS": "arn:aws:iam::123456789:role/snowflake_role" },
      "Action": "sts:AssumeRole",
      "Condition": { "StringEquals": { "sts:ExternalId": "MY_ACCOUNT_SFID_123" } }
    }
  ]
}

Refer to the exhibit. This JSON policy is part of the setup for a Snowflake Storage Integration. What is the architectural purpose of the 'sts:ExternalId' condition in this cross-account IAM trust relationship?

⚠ Common exam trap

Candidates often assume the External ID is for user authentication or encryption. They miss that it is specifically a security mechanism to prevent the 'confused deputy' security vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It prevents the 'confused deputy' problem by ensuring only the correct Snowflake account can assume the role.

The External ID is a security best practice used in cross-account IAM roles to prevent the 'confused deputy' problem. In the Snowflake architecture, it ensures that the cloud provider only allows Snowflake to assume the role if the request includes the specific ID unique to that Snowflake account. This prevents one customer from potentially accessing another customer's cloud resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It identifies the specific S3 bucket that Snowflake is allowed to access.

    Why it's wrong here

    The S3 bucket location is typically defined in the 'Resource' section of an IAM policy or within the 'STORAGE_ALLOWED_LOCATIONS' parameter of the Snowflake Storage Integration object. The External ID is not used to specify data locations but rather to secure the trust relationship between the two separate cloud accounts (Snowflake's and the customer's).

  • ✓

    It prevents the 'confused deputy' problem by ensuring only the correct Snowflake account can assume the role.

    Why this is correct

    In a multi-tenant environment like Snowflake, the External ID ensures that even if another user knows your AWS Role ARN, they cannot use their own Snowflake account to access your data. AWS requires the External ID provided by Snowflake to match the one in the IAM trust policy, creating a unique and secure handshake between accounts.

  • ✗

    It maps Snowflake users to specific AWS IAM users for fine-grained access control.

    Why it's wrong here

    Snowflake Storage Integrations do not map individual Snowflake users to IAM users. Instead, they provide a single secure channel for the Snowflake service to access cloud storage. Fine-grained access control within Snowflake is then managed through Roles and Privileges (RBAC), while the integration handles the underlying infrastructure-level authentication for the entire account.

  • ✗

    It encrypts the data during transit between the cloud provider and Snowflake.

    Why it's wrong here

    The External ID is an authentication and authorization parameter, not an encryption mechanism. Snowflake automatically encrypts all data in transit using TLS and data at rest using AES-256. The IAM policy and its conditions are focused on verifying that the request to access the storage service is coming from a legitimate and authorized source.

About these practice questions

This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.