CertSafari
    Snowflake SnowPro Core Certification (COF-C03)· Lessons

    Domain 1 · Lesson 6/19

    Snowflake Cortex: AI SQL Functions, Cortex Search and Cortex Analyst

    Explain AI/ML and application development features

    11 min read
    5.17% of exam
    3 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Choose the right Cortex AI SQL function (AI_CLASSIFY, AI_EXTRACT, AI_FILTER, AI_AGG and others) for a text or document task
    • Explain what Cortex Search builds and manages, and how a search service is created, granted and queried
    • Explain how Cortex Analyst answers natural-language questions over structured data using semantic views
    • Tell the three Cortex features apart by interface and by the kind of data each works on

    1.Cortex AI SQL functions: LLMs as ordinary SQL calls

    Snowflake Cortex makes large language models available inside Snowflake. The most direct way to use them is through the Cortex AI Functions. These are managed functions you call from SQL, and they are also available in Python. They take text or images (and, for some functions, documents, audio or video) as input. The models come from providers including OpenAI, Anthropic, Meta, Mistral AI, DeepSeek and xAI.

    Governance is often what an exam question turns on. Every LLM Snowflake offers through its AI features is deployed inside the Snowflake service perimeter, so you can run sentiment or classification on customer text without sending it to an outside API. To call the functions, a role needs the USE AI FUNCTIONS account-level privilege and either the CORTEX_USER or the AI_FUNCTIONS_USER database role.

    Most of the functions are task-specific, so the work is picking the right one for the job:

    Choosing a Cortex AI function
    FunctionWhat it does
    AI_COMPLETEGenerates a completion for text or an image using a model you choose. The general-purpose option
    AI_CLASSIFYClassifies text or images into categories you define
    AI_FILTERReturns True or False for an input, for use in SELECT, WHERE or JOIN ON clauses
    AI_EXTRACTExtracts specific information from a string or a file
    AI_SENTIMENTExtracts sentiment from text
    AI_SUMMARIZE / AI_SUMMARIZE_AGGSummarises one input, or a whole text column across rows
    AI_AGGReturns insights across many rows of a text column, based on a prompt
    AI_EMBED / AI_SIMILARITYCreates embedding vectors, or scores the embedding similarity of two inputs
    AI_TRANSLATE / AI_REDACTTranslates text between languages, or removes PII from it
    AI_PARSE_DOCUMENT / AI_TRANSCRIBEExtracts text and layout from staged documents, or transcribes staged audio and video

    Helper functions support the others. TO_FILE references a staged file, AI_COUNT_TOKENS checks an input against model limits, and PROMPT builds prompt objects. AI_AGG and AI_SUMMARIZE_AGG are not limited by the model's context window, so they can cover a whole column.

    AI Functions are built for throughput, which makes them a good fit for batch work over large tables. For interactive use where latency matters, Snowflake points you to the REST APIs instead: Complete, Embed and Agents.

    Checkpoint 1 of 7· Check yourself

    A legal team wants the specific termination notice period pulled out of each contract text, not a summary of the whole contract. Which function is built for this?

    Checkpoint 2 of 7· Exam question

    A developer needs to publish an internal dashboard with sliders, buttons, and charts driven by live Snowflake data, and wants business users to open it directly from Snowsight without installing anything locally. Which service is designed for this?

    Sources1

    AI functions work on the input you pass them. Often, though, an LLM first needs to find the right passage among thousands of documents. Cortex Search handles that step. It is a hybrid search engine over your text data, combining vector and keyword search. Snowflake takes care of the embeddings, the infrastructure, quality tuning and keeping the index refreshed.

    The main uses are retrieval augmented generation (RAG), where Search supplies an LLM with grounded context from your own data, and enterprise search, where it backs a search bar in an application. It can also act as the retrieval layer for Cortex Agents.

    You create a search service as an object, either with one SQL statement or from AI & ML » Cortex Search in Snowsight:

    Creating a Cortex Search Service over a support-transcript tablesql
    CREATE OR REPLACE CORTEX SEARCH SERVICE transcript_search_service
      ON transcript_text
      ATTRIBUTES region
      WAREHOUSE = cortex_search_wh
      TARGET_LAG = '1 day'
      EMBEDDING_MODEL = 'snowflake-arctic-embed-l-v2.0'
      AS (
        SELECT
            transcript_text,
            region,
            agent_id
        FROM support_transcripts
    );

    What each clause does:

    - ON names the column that gets searched. - ATTRIBUTES makes region available as a filter. - WAREHOUSE materialises the source query, both when the service is created and whenever the base table changes. Snowflake recommends a dedicated warehouse no larger than MEDIUM. - TARGET_LAG sets how far the service may lag behind the base table.

    The index is built during CREATE, so the statement can take a long time on large datasets. After that, you grant USAGE on the database, schema and service to other roles, check results with SNOWFLAKE.CORTEX.SEARCH_PREVIEW in SQL, and then query the service from applications through the Python API.

    Checkpoint 3 of 7· Fill the gap

    Which parameter tells the service to check the base table for updates about once a day?

    CREATE OR REPLACE CORTEX SEARCH SERVICE transcript_search_service
      ON transcript_text
      ATTRIBUTES region
      WAREHOUSE = cortex_search_wh
       ?  = '1 day'
      EMBEDDING_MODEL = 'snowflake-arctic-embed-l-v2.0'
      AS (
        SELECT
            transcript_text,
            region,
            agent_id
        FROM support_transcripts
    );

    Checkpoint 4 of 7· Put it in order

    Put the documented Cortex Search workflow in order

    1. 1.Run CREATE CORTEX SEARCH SERVICE over the source table
    2. 2.Preview results with SNOWFLAKE.CORTEX.SEARCH_PREVIEW
    3. 3.GRANT USAGE on the database, schema and service to the consuming role
    4. 4.Query the service from the application using the Python API

    Sources2

    3.Cortex Analyst: natural-language questions over structured data

    Cortex Search works with unstructured text. Cortex Analyst works with structured data. It is a fully managed, LLM-powered service that lets business users ask questions in natural language and get answers without writing SQL. Behind the scenes it is an agentic text-to-SQL system. It is available as a REST API, not a SQL function, so you integrate it into Streamlit apps, Slack, Teams or a custom chat interface.

    A database schema alone lacks business definitions, which is why Analyst relies on a semantic layer. The recommended form is Semantic Views: schema-level objects that define logical tables, dimensions, facts, metrics and relationships. Semantic Views come with RBAC, can be shared, and support custom instructions. Older semantic model YAML files stored on stages still work, but only for backward compatibility.

    On governance, Cortex Analyst does not train on Customer Data, and the queries it generates follow your RBAC policies. To call it, a role needs SNOWFLAKE.CORTEX_USER, which covers all Covered AI features, or SNOWFLAKE.CORTEX_ANALYST_USER, which covers Analyst only. It also needs SELECT on the tables the semantic model uses. CORTEX_USER is granted to PUBLIC by default, so restricting access means revoking it and granting CORTEX_ANALYST_USER through a custom role.

    Checkpoint 5 of 7· Match them up

    Match each Semantic View element to what it defines

    Tap a term, then the definition that fits it.

    Telling the three Cortex features apart
    FeatureInterfaceWorks onTypical use
    AI SQL functions (e.g. AI_COMPLETE, AI_CLASSIFY)SQL functions, also PythonText, images and staged files passed as inputHigh-throughput batch enrichment of table rows
    Cortex SearchCORTEX SEARCH SERVICE object; queried with SEARCH_PREVIEW or the Python APIText data, through a hybrid vector and keyword indexRAG retrieval and enterprise search
    Cortex AnalystREST APIStructured data described by Semantic ViewsSelf-serve natural-language analytics (text-to-SQL)

    Checkpoint 6 of 7· Check yourself

    Sales managers want to type "What was revenue by region last quarter?" into a Slack bot and get an answer computed from Snowflake tables. Which feature fits?

    Checkpoint 7 of 7· Exam question

    An engineering team wants to write DataFrame-style transformation logic in Python that compiles down to SQL and executes entirely inside Snowflake's compute, avoiding data movement to an external Spark or pandas cluster. Which technology fits this requirement?

    Sources3

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Cortex Analyst is another AI SQL function you call inside a SELECT, like AI_COMPLETE.Why is that wrong?

      Cortex Analyst is a managed service exposed as a REST API that generates SQL from natural language. AI SQL functions are the SQL-callable feature.

      Covered in Cortex Analyst: natural-language questions over structured data

    2. 2.To use Cortex Search you must first generate embeddings yourself and manage a vector index.Why is that wrong?

      Cortex Search provides a hybrid vector and keyword engine and handles embedding, infrastructure, tuning and index refreshes for you.

      Covered in Cortex Search: managed retrieval over text

    3. 3.Cortex AI SQL functions are the best choice for low-latency, interactive chat responses.Why is that wrong?

      AI Functions are optimised for throughput and batch processing. For latency-sensitive interactive work, Snowflake recommends the REST APIs.

      Covered in Cortex AI SQL functions: LLMs as ordinary SQL calls

    Practise it for real

    Create a Cortex Search Service over a small support-transcript table and confirm it returns filtered results

    1. 1.Create the support_transcripts table with transcript_text, region and agent_id columns, and insert the four sample rows from the docs

      Why: A search service needs a source query over text data

      You should see: A table with four transcripts across three regions

    2. 2.Run CREATE OR REPLACE CORTEX SEARCH SERVICE transcript_search_service ON transcript_text ATTRIBUTES region with an X-SMALL warehouse and TARGET_LAG = '1 day'

      Why: This builds the index and sets which column is searched and which can be filtered

      You should see: The statement completes after the index is built. On large tables this can take much longer

    3. 3.GRANT USAGE on the database, the schema and the Cortex Search service to the role that will query it

      Why: Other roles cannot use the service without USAGE on all three objects

      You should see: The grants succeed

    4. 4.Run SNOWFLAKE.CORTEX.SEARCH_PREVIEW with the query "internet issues", filter {"@eq": {"region": "North America"}} and limit 1

      Why: Previewing confirms the service is populated before an application relies on it

      You should see: One result: the North America transcript about the internet being down

    Stuck? Get a nudge

    If the filter returns nothing, check that region appears in both the ATTRIBUTES clause and the source SELECT.

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “All the LLMs that Snowflake provides access to via our Snowflake AI Features are deployed within the Snowflake Service perimeter.”
      ↩︎ Cortex AI SQL functions: LLMs as ordinary SQL calls
      “your role needs the USE AI FUNCTIONS account-level privilege and one of the CORTEX_USER or AI_FUNCTIONS_USER database roles”
      ↩︎ Cortex AI SQL functions: LLMs as ordinary SQL calls
      “AI_CLASSIFY: Classifies text or images into user-defined categories.”
      ↩︎ Cortex AI SQL functions: LLMs as ordinary SQL calls
      “For more interactive use cases where latency is important, use the REST API.”
      ↩︎ Exam trap 3
      “AI_EXTRACT: Extracts information from an input string or file, for example, text, images, and documents.”
      ↩︎ Checkpoint
    2. 2.
      “a hybrid (vector and keyword) search engine on your text data in minutes”
      ↩︎ Cortex Search: managed retrieval over text
      “The two primary use cases for Cortex Search are retrieval augmented generation (RAG) and enterprise search.”
      ↩︎ Cortex Search: managed retrieval over text
      “Snowflake recommends using a dedicated warehouse of size no larger than MEDIUM for each service.”
      ↩︎ Cortex Search: managed retrieval over text
      “without having to worry about embedding, infrastructure maintenance, search quality parameter tuning, or ongoing index refreshes”
      ↩︎ Exam trap 2
      “granted usage on it to your role, and previewed it, you can now query it from your application using the Python API.”
      ↩︎ Checkpoint
    3. 3.
      “Cortex Analyst uses Semantic Views to understand your data and generate accurate SQL queries.”
      ↩︎ Cortex Analyst: natural-language questions over structured data
      “Legacy semantic model YAML files (stored on stages) are still supported for backward compatibility, but Semantic Views are the recommended approach for new implementations.”
      ↩︎ Cortex Analyst: natural-language questions over structured data
      “CORTEX_USER provides access to all Covered AI features, while CORTEX_ANALYST_USER provides access only to Cortex Analyst.”
      ↩︎ Cortex Analyst: natural-language questions over structured data
      “By default, the CORTEX_USER role is granted to the PUBLIC role.”
      ↩︎ Cortex Analyst: natural-language questions over structured data
      “Available as a convenient REST API, Cortex Analyst can be seamlessly integrated into any application.”
      ↩︎ Exam trap 1
      “This SQL query is then executed in your Snowflake virtual warehouse to generate the final output.”
      ↩︎ Prediction
      “Metrics that aggregate data into business KPIs (such as total revenue or average order value)”
      ↩︎ Checkpoint
      “business users can ask questions in natural language and receive direct answers without writing SQL”
      ↩︎ Checkpoint

    Ready to test yourself?

    Practise the 31 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.