CertSafari
    Snowflake SnowPro Specialty: Gen AI (GES-C02)· Lessons

    Domain 3 · Lesson 8/15

    Cortex Data Safety: Cross-Region Inference, Guardrails, AI_REDACT and REST Auth

    Set up model access controls.

    8 min read
    7.25% of exam
    5 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Choose a CORTEX_ENABLED_CROSS_REGION value that matches a data-residency requirement
    • Enable Cortex AI Guardrails and know which accounts and clients they apply to
    • Use AI_REDACT in redact or detect mode and know its limits
    • Use RAG grounding with Cortex Search to cut down fabricated answers
    • Authenticate Cortex REST API calls and choose the right role for them

    1.Cross-region inference: where prompts are processed

    Controlling model access settles who can call which model. A separate account parameter, CORTEX_ENABLED_CROSS_REGION, settles where the processing happens. When it is enabled, Snowflake can send an inference request to available capacity in another region, within limits you choose. Your stored data stays in your account's region. Only the request payload, meaning the prompt and the response, travels temporarily to the processing region, and nothing is kept there. Credits are charged in your requesting region, and there are no data egress charges.

    Routing options, from most flexible to most restrictive
    TypeParameter valueRouting behavior
    GlobalANY_REGIONAny Snowflake-supported region, any cloud provider
    Cloud-specificAWS_GLOBAL, AZURE_GLOBAL, GCP_GLOBALStays within a designated cloud provider
    RegionalAWS_US, AWS_EU, AWS_APJ, AWS_JP, AWS_AU, AZURE_US, AZURE_EU, GCP_USStays within designated cloud provider regions
    DisabledDISABLEDOnly your account's home region

    Only ACCOUNTADMIN can set this parameter, and only at the account level. ORGADMIN cannot set it. DISABLED gives the strictest residency, but you can then use only the models and features deployed in your own region. Data in transit is always encrypted. Traffic within one cloud provider stays on that provider's private backbone. Traffic between cloud providers crosses the public internet over mTLS.

    Checkpoint 1 of 6· Fill the gap

    A regulator requires all inference to stay in the account's home region. Complete the statement.

    ALTER ACCOUNT SET CORTEX_ENABLED_CROSS_REGION = ' ? ';

    Sources1

    2.Cortex AI Guardrails against prompt injection

    Cortex AI Guardrails protect CoCo, Snowflake CoWork and Cortex Agents at run time. They detect prompt injection by scanning the outputs of each tool for indirect injections, they detect jailbreak attempts, and they look for previously unknown attack patterns. ACCOUNTADMIN turns them on for the whole account with the AI_SETTINGS parameter.

    Guardrails depend on the previous section. They are available only on Commercial accounts with cross-region inference enabled to one of a specific set of values. An account with DISABLED does not get them.

    Enable guardrails account-widesql
    ALTER ACCOUNT SET AI_SETTINGS = $$
      guardrails:
        advanced_prompt_injection:
          - enabled: true
    $$;

    Scans cost credits, based on the number of tokens scanned. They are recorded in SNOWFLAKE.ACCOUNT_USAGE.CORTEX_AI_GUARDRAILS_USAGE_HISTORY, where GUARDRAILS_SIGNAL = TRUE marks flagged requests. Legitimate prompts are sometimes flagged, so review the logs regularly.

    Checkpoint 2 of 6· Check yourself

    An account has CORTEX_ENABLED_CROSS_REGION = 'DISABLED' and wants to turn on Cortex AI Guardrails for its Cortex Agents. What is the result?

    Sources2

    3.Sensitive data management with AI_REDACT

    Guardrails defend against malicious prompts. AI_REDACT deals with a different risk: personal data in the text you send to a model or store afterwards. It uses an LLM to find PII and works in two modes. In redact mode, the default, it replaces each PII value with a placeholder such as [NAME]. In detect mode, it returns a spans array with the category, start, end and text of each match, so your code can decide what to redact. For example, you could keep known employee names that appear on an allowlist. An optional categories array limits redaction to specific types, such as EMAIL or PAYMENT_CARD_DATA.

    The function needs the SNOWFLAKE.CORTEX_USER database role. Its results are best-effort, so a person still has to review the output. It supports US PII plus some UK and Canadian PII. Input and output together are limited to 4,096 tokens, so split longer text into chunks first.

    Checkpoint 3 of 6· Match them up

    Match each AI_REDACT feature to what it does

    Tap a term, then the definition that fits it.

    Sources3

    4.Reducing hallucinations: ground the model in your data

    The documentation provided for this lesson offers one main technique against hallucination: retrieval augmented generation (RAG). In RAG, you fetch relevant passages from a knowledge base and give them to the model, so it answers from your content instead of from memory alone. Cortex Search is a hybrid vector and keyword search engine that can serve as the RAG engine for chat applications or as the retrieval layer for Cortex Agents.

    The theme from the earlier sections still applies: AI output is best-effort and needs review, which AI_REDACT's documentation states directly. These sources do not cover specific bias-mitigation techniques or prompt and parameter tuning, so this lesson does not assert any.

    Checkpoint 4 of 6· Check yourself

    A support assistant invents product details that are not in the company's documentation. Based on these sources, which change most directly addresses this?

    Checkpoint 5 of 6· Exam question

    A role has been granted the SNOWFLAKE."CORTEX-MODEL-ROLE-MISTRAL-LARGE2" application role, but the account's CORTEX_MODELS_ALLOWLIST parameter is set to a list that does not include mistral-large2. When a user under this role calls a Cortex function targeting mistral-large2, what happens?

    Sources43

    5.Authenticating to the Cortex REST API

    Applications outside SQL call Cortex through its REST API. You send a token in the Authorization header. The token can be a JSON web token (JWT, from key-pair authentication), an OAuth token, or a programmatic access token (PAT). Snowflake suggests creating a dedicated user for these calls.

    Authorization works differently here: a REST request runs under the user's default role. That role needs either SNOWFLAKE.CORTEX_USER, which covers all Covered AI features, or SNOWFLAKE.CORTEX_REST_API_USER, which covers only the REST API.

    Point the REST user at a role that holds Cortex accesssql
    ALTER USER my_user SET DEFAULT_ROLE=my_role

    Checkpoint 6 of 6· Check yourself

    A service user authenticates with a valid PAT but gets permission errors from the Cortex REST API. Its default role is REPORTING, and CORTEX_USER was granted to a different role, ANALYST. What is the fix?

    Sources5

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.With cross-region inference enabled, your data is stored in the processing region and billed there.Why is that wrong?

      Only the prompt and response travel temporarily to the processing region, and nothing is kept there. Credits are charged in the requesting region.

      Covered in Cross-region inference: where prompts are processed

    2. 2.AI_REDACT guarantees that all PII is removed, so its output needs no review.Why is that wrong?

      AI_REDACT is best-effort and model-based, and Snowflake says to review its output.

      Covered in Sensitive data management with AI_REDACT

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Your customer data remains stored only in the region where your account is located.”
      ↩︎ Cross-region inference: where prompts are processed
      “This parameter cannot be set by the ORGADMIN role.”
      ↩︎ Cross-region inference: where prompts are processed
      “You do not incur data egress charges for cross-region inference.”
      ↩︎ Cross-region inference: where prompts are processed
      “Credits are consumed in your requesting region, regardless of where the request is processed.”
      ↩︎ Exam trap 1
    2. 2.
      “provide run-time protection against prompt injection and jailbreak attacks on CoCo, Snowflake CoWork, and Cortex Agents.”
      ↩︎ Cortex AI Guardrails against prompt injection
      “Usage is measured based on the number of tokens scanned.”
      ↩︎ Cortex AI Guardrails against prompt injection
      “some legitimate prompts may occasionally be flagged.”
      ↩︎ Cortex AI Guardrails against prompt injection
      “The account parameter CORTEX_ENABLED_CROSS_REGION must be set to ANY_REGION, AWS_US, AWS_EU, AWS_JP, AWS_APJ, or AWS_GLOBAL.”
      ↩︎ Checkpoint
    3. 3.
      “Users must use a role that has been granted the SNOWFLAKE.CORTEX_USER database role.”
      ↩︎ Sensitive data management with AI_REDACT
      “Input and output together can be up to 4,096 tokens. Output is limited to 1,024 tokens.”
      ↩︎ Sensitive data management with AI_REDACT
      “AI_REDACT currently supports only US PII and some UK and Canadian PII”
      ↩︎ Sensitive data management with AI_REDACT
      “AI_REDACT performs detection and redaction in a best-effort manner using AI models.”
      ↩︎ Reducing hallucinations: ground the model in your data
      “AI_REDACT performs detection and redaction in a best-effort manner using AI models.”
      ↩︎ Exam trap 2
      “Use AI_REDACT in detect mode to identify PII locations, then programmatically choose which PII to redact.”
      ↩︎ Checkpoint
    4. 4.
      “Use Cortex Search as a RAG engine for chat applications with your text data by leveraging semantic search for customized, contextualized responses.”
      ↩︎ Reducing hallucinations: ground the model in your data
      “Retrieval augmented generation (RAG) is a technique for retrieving data from a knowledge base to enhance the generated response”
      ↩︎ Checkpoint
    5. 5.
      “Set the Authorization header to include your token (for example, a JSON web token (JWT), OAuth token, or programmatic access token).”
      ↩︎ Authenticating to the Cortex REST API
      “SNOWFLAKE.CORTEX_REST_API_USER provides access only to the Cortex REST API.”
      ↩︎ Authenticating to the Cortex REST API
      “Consider creating a dedicated user for Cortex REST API requests.”
      ↩︎ Authenticating to the Cortex REST API
      “REST API requests use the user’s default role, so that role must have the necessary privileges.”
      ↩︎ Checkpoint

    Ready to test yourself?

    Practise the 26 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.