TechNuggets Academy

Governance, Security, and Cost

Free SnowPro Specialty: Gen AI practice — 6 questions on Governance, Security, and Cost, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Governance, Security, and Cost
An account team uses SNOWFLAKE.CORTEX.COMPLETE() extensively and wants an automatic email notification when serverless Cortex LLM function credit consumption exceeds 500 credits in a single day. Which approach correctly implements this?
Cortex LLM functions are serverless and consume credits directly at the account level, independent of any virtual warehouse. Snowflake's Budgets feature is specifically designed to track and alert on this type of serverless/account-level credit consumption, including Cortex, Snowpipe, and other serverless features.
Question 2 of 6 · Governance, Security, and Cost
A table contains a customer NOTES column with embedded PII. Analysts without the PII_VIEWER role should be able to run SNOWFLAKE.CORTEX.COMPLETE() to summarize NOTES, but the LLM must never receive unmasked PII when called by unauthorized roles. Which built-in mechanism achieves this with the least custom engineering?
Dynamic data masking policies are evaluated at query execution time based on the querying role's masking policy condition, and this evaluation happens before the resulting column value is used as an argument to any downstream function, including Cortex LLM functions. This is the native, low-effort governance control for this exact scenario.
Question 3 of 6 · Governance, Security, and Cost
By default, PUBLIC is granted the SNOWFLAKE.CORTEX_USER database role, allowing any role to call Cortex LLM functions. A security team wants to revoke this default and instead explicitly control which custom roles can invoke functions like SNOWFLAKE.CORTEX.COMPLETE(). Which grant statement is required to authorize a specific custom role after revoking PUBLIC access?
Access to Cortex LLM functions is gated specifically by the SNOWFLAKE.CORTEX_USER database role. Once PUBLIC's default grant is revoked, this database role must be explicitly granted to any custom role that needs to invoke Cortex functions.
Question 4 of 6 · Governance, Security, and Cost
A healthcare company operating entirely within Snowflake's Switzerland region must guarantee that prompts sent to Cortex LLM functions are never processed by infrastructure located in another geographic region, even if the requested model is temporarily unavailable locally. Which configuration enforces this?
CORTEX_ENABLED_CROSS_REGION is the account parameter that controls whether Cortex function requests may be routed to a different Snowflake region when the requested model isn't hosted locally. Setting it to 'DISABLED' ensures inference never leaves the account's home region, which is the correct control for this data residency requirement.
Question 5 of 6 · Governance, Security, and Cost
A team wants SNOWFLAKE.CORTEX.COMPLETE() to automatically filter and suppress potentially unsafe or harmful generated content before returning results, using Snowflake's built-in content-safety capability. Which configuration accomplishes this?
Cortex Guard is enabled by passing 'guardrails': true within the options object of a COMPLETE() call. It uses a safety-classification model to screen generated responses for unsafe content and suppresses or flags output accordingly.
Question 6 of 6 · Governance, Security, and Cost
From a data governance standpoint, what is the fundamental difference between invoking SNOWFLAKE.CORTEX.COMPLETE() versus calling a third-party LLM API through an External Network Access Integration?
Cortex LLM functions run within Snowflake-managed infrastructure, so prompt data, including any sensitive content, is processed inside Snowflake's security and governance perimeter and never transmitted to a third-party endpoint. Calling an external LLM API via an External Access Integration sends request data outside that perimeter to a third-party network location, requiring additional governance controls (e.g., network rules, secrets management, contractual data-handling review) to maintain equivalent protection.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →