What you will be able to do
- Choose a CORTEX_ENABLED_CROSS_REGION value that matches a data-residency requirement
- Enable Cortex AI Guardrails and know which accounts and clients they apply to
- Use AI_REDACT in redact or detect mode and know its limits
- Use RAG grounding with Cortex Search to cut down fabricated answers
- Authenticate Cortex REST API calls and choose the right role for them
1.Cross-region inference: where prompts are processed
Controlling model access settles who can call which model. A separate account parameter, CORTEX_ENABLED_CROSS_REGION, settles where the processing happens. When it is enabled, Snowflake can send an inference request to available capacity in another region, within limits you choose. Your stored data stays in your account's region. Only the request payload, meaning the prompt and the response, travels temporarily to the processing region, and nothing is kept there. Credits are charged in your requesting region, and there are no data egress charges.
| Type | Parameter value | Routing behavior |
|---|---|---|
| Global | ANY_REGION | Any Snowflake-supported region, any cloud provider |
| Cloud-specific | AWS_GLOBAL, AZURE_GLOBAL, GCP_GLOBAL | Stays within a designated cloud provider |
| Regional | AWS_US, AWS_EU, AWS_APJ, AWS_JP, AWS_AU, AZURE_US, AZURE_EU, GCP_US | Stays within designated cloud provider regions |
| Disabled | DISABLED | Only your account's home region |
Only ACCOUNTADMIN can set this parameter, and only at the account level. ORGADMIN cannot set it. DISABLED gives the strictest residency, but you can then use only the models and features deployed in your own region. Data in transit is always encrypted. Traffic within one cloud provider stays on that provider's private backbone. Traffic between cloud providers crosses the public internet over mTLS.
Checkpoint 1 of 6· Fill the gap
A regulator requires all inference to stay in the account's home region. Complete the statement.
ALTER ACCOUNT SET CORTEX_ENABLED_CROSS_REGION = ' ? ';DISABLED keeps processing in the home region. AWS_US still allows routing to other AWS US regions, and 'None' is a value of the model allowlist, not of this parameter.
Source: docs.snowflake.comSources1
2.Cortex AI Guardrails against prompt injection
Cortex AI Guardrails protect CoCo, Snowflake CoWork and Cortex Agents at run time. They detect prompt injection by scanning the outputs of each tool for indirect injections, they detect jailbreak attempts, and they look for previously unknown attack patterns. ACCOUNTADMIN turns them on for the whole account with the AI_SETTINGS parameter.
Guardrails depend on the previous section. They are available only on Commercial accounts with cross-region inference enabled to one of a specific set of values. An account with DISABLED does not get them.
ALTER ACCOUNT SET AI_SETTINGS = $$
guardrails:
advanced_prompt_injection:
- enabled: true
$$;Scans cost credits, based on the number of tokens scanned. They are recorded in SNOWFLAKE.ACCOUNT_USAGE.CORTEX_AI_GUARDRAILS_USAGE_HISTORY, where GUARDRAILS_SIGNAL = TRUE marks flagged requests. Legitimate prompts are sometimes flagged, so review the logs regularly.
Checkpoint 2 of 6· Check yourself
An account has CORTEX_ENABLED_CROSS_REGION = 'DISABLED' and wants to turn on Cortex AI Guardrails for its Cortex Agents. What is the result?
Guardrails require cross-region inference to be enabled to one of the listed values.
“The account parameter CORTEX_ENABLED_CROSS_REGION must be set to ANY_REGION, AWS_US, AWS_EU, AWS_JP, AWS_APJ, or AWS_GLOBAL.”Source: docs.snowflake.com
Sources2
3.Sensitive data management with AI_REDACT
Guardrails defend against malicious prompts. AI_REDACT deals with a different risk: personal data in the text you send to a model or store afterwards. It uses an LLM to find PII and works in two modes. In redact mode, the default, it replaces each PII value with a placeholder such as [NAME]. In detect mode, it returns a spans array with the category, start, end and text of each match, so your code can decide what to redact. For example, you could keep known employee names that appear on an allowlist. An optional categories array limits redaction to specific types, such as EMAIL or PAYMENT_CARD_DATA.
The function needs the SNOWFLAKE.CORTEX_USER database role. Its results are best-effort, so a person still has to review the output. It supports US PII plus some UK and Canadian PII. Input and output together are limited to 4,096 tokens, so split longer text into chunks first.
Checkpoint 3 of 6· Match them up
Match each AI_REDACT feature to what it does
Tap a term, then the definition that fits it.
Detect mode plus your own logic is how you build selective redaction; the session parameter controls what happens on errors.
“Use AI_REDACT in detect mode to identify PII locations, then programmatically choose which PII to redact.”Source: docs.snowflake.com
Sources3
4.Reducing hallucinations: ground the model in your data
The documentation provided for this lesson offers one main technique against hallucination: retrieval augmented generation (RAG). In RAG, you fetch relevant passages from a knowledge base and give them to the model, so it answers from your content instead of from memory alone. Cortex Search is a hybrid vector and keyword search engine that can serve as the RAG engine for chat applications or as the retrieval layer for Cortex Agents.
The theme from the earlier sections still applies: AI output is best-effort and needs review, which AI_REDACT's documentation states directly. These sources do not cover specific bias-mitigation techniques or prompt and parameter tuning, so this lesson does not assert any.
Checkpoint 4 of 6· Check yourself
A support assistant invents product details that are not in the company's documentation. Based on these sources, which change most directly addresses this?
RAG grounds the response in retrieved company data. The other options control access, data residency or PII, not whether answers are accurate.
“Retrieval augmented generation (RAG) is a technique for retrieving data from a knowledge base to enhance the generated response”Source: docs.snowflake.com
Checkpoint 5 of 6· Exam question
A role has been granted the SNOWFLAKE."CORTEX-MODEL-ROLE-MISTRAL-LARGE2" application role, but the account's CORTEX_MODELS_ALLOWLIST parameter is set to a list that does not include mistral-large2. When a user under this role calls a Cortex function targeting mistral-large2, what happens?
Correct answer: A — The call succeeds, because model RBAC is evaluated first and grants access independent of the allowlist
- A. Snowflake checks model RBAC first, and if the calling role has usage on the corresponding model object the call is allowed, with the allowlist parameter acting only as a fallback when no RBAC grant exists.
- B. This reverses the actual precedence; the allowlist is the legacy, coarser fallback mechanism and does not override an explicit RBAC grant on the model object.
- C. ACCOUNTADMIN automatically bypasses both mechanisms, but that is unrelated to why this particular role succeeds, since the role already has a direct RBAC grant on the model.
- D. This describes allowlist-only behavior and ignores that RBAC grants are checked first and can independently authorize the call even when the allowlist would otherwise block it.
5.Authenticating to the Cortex REST API
Applications outside SQL call Cortex through its REST API. You send a token in the Authorization header. The token can be a JSON web token (JWT, from key-pair authentication), an OAuth token, or a programmatic access token (PAT). Snowflake suggests creating a dedicated user for these calls.
Authorization works differently here: a REST request runs under the user's default role. That role needs either SNOWFLAKE.CORTEX_USER, which covers all Covered AI features, or SNOWFLAKE.CORTEX_REST_API_USER, which covers only the REST API.
ALTER USER my_user SET DEFAULT_ROLE=my_roleCheckpoint 6 of 6· Check yourself
A service user authenticates with a valid PAT but gets permission errors from the Cortex REST API. Its default role is REPORTING, and CORTEX_USER was granted to a different role, ANALYST. What is the fix?
REST requests always run under the default role, so that role must hold the Cortex database role.
“REST API requests use the user’s default role, so that role must have the necessary privileges.”Source: docs.snowflake.com
Sources5
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.With cross-region inference enabled, your data is stored in the processing region and billed there.Why is that wrong?
Only the prompt and response travel temporarily to the processing region, and nothing is kept there. Credits are charged in the requesting region.
Covered in Cross-region inference: where prompts are processed
2.AI_REDACT guarantees that all PII is removed, so its output needs no review.Why is that wrong?
AI_REDACT is best-effort and model-based, and Snowflake says to review its output.
Covered in Sensitive data management with AI_REDACT
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Your customer data remains stored only in the region where your account is located.”
↩︎ Cross-region inference: where prompts are processed“This parameter cannot be set by the ORGADMIN role.”
↩︎ Cross-region inference: where prompts are processed“You do not incur data egress charges for cross-region inference.”
↩︎ Cross-region inference: where prompts are processed“Credits are consumed in your requesting region, regardless of where the request is processed.”
↩︎ Exam trap 1 - 2.
“provide run-time protection against prompt injection and jailbreak attacks on CoCo, Snowflake CoWork, and Cortex Agents.”
↩︎ Cortex AI Guardrails against prompt injection“Usage is measured based on the number of tokens scanned.”
↩︎ Cortex AI Guardrails against prompt injection“some legitimate prompts may occasionally be flagged.”
↩︎ Cortex AI Guardrails against prompt injection“The account parameter CORTEX_ENABLED_CROSS_REGION must be set to ANY_REGION, AWS_US, AWS_EU, AWS_JP, AWS_APJ, or AWS_GLOBAL.”
↩︎ Checkpoint - 3.
“Users must use a role that has been granted the SNOWFLAKE.CORTEX_USER database role.”
↩︎ Sensitive data management with AI_REDACT“Input and output together can be up to 4,096 tokens. Output is limited to 1,024 tokens.”
↩︎ Sensitive data management with AI_REDACT“AI_REDACT currently supports only US PII and some UK and Canadian PII”
↩︎ Sensitive data management with AI_REDACT“AI_REDACT performs detection and redaction in a best-effort manner using AI models.”
↩︎ Reducing hallucinations: ground the model in your data“AI_REDACT performs detection and redaction in a best-effort manner using AI models.”
↩︎ Exam trap 2“Use AI_REDACT in detect mode to identify PII locations, then programmatically choose which PII to redact.”
↩︎ Checkpoint - 4.https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-search/cortex-search-overviewOfficial docs
“Use Cortex Search as a RAG engine for chat applications with your text data by leveraging semantic search for customized, contextualized responses.”
↩︎ Reducing hallucinations: ground the model in your data“Retrieval augmented generation (RAG) is a technique for retrieving data from a knowledge base to enhance the generated response”
↩︎ Checkpoint - 5.
“Set the Authorization header to include your token (for example, a JSON web token (JWT), OAuth token, or programmatic access token).”
↩︎ Authenticating to the Cortex REST API“SNOWFLAKE.CORTEX_REST_API_USER provides access only to the Cortex REST API.”
↩︎ Authenticating to the Cortex REST API“Consider creating a dedicated user for Cortex REST API requests.”
↩︎ Authenticating to the Cortex REST API“REST API requests use the user’s default role, so that role must have the necessary privileges.”
↩︎ Checkpoint