What you will be able to do
- Choose the right Cortex AI SQL function (AI_CLASSIFY, AI_EXTRACT, AI_FILTER, AI_AGG and others) for a text or document task
- Explain what Cortex Search builds and manages, and how a search service is created, granted and queried
- Explain how Cortex Analyst answers natural-language questions over structured data using semantic views
- Tell the three Cortex features apart by interface and by the kind of data each works on
1.Cortex AI SQL functions: LLMs as ordinary SQL calls
Snowflake Cortex makes large language models available inside Snowflake. The most direct way to use them is through the Cortex AI Functions. These are managed functions you call from SQL, and they are also available in Python. They take text or images (and, for some functions, documents, audio or video) as input. The models come from providers including OpenAI, Anthropic, Meta, Mistral AI, DeepSeek and xAI.
Governance is often what an exam question turns on. Every LLM Snowflake offers through its AI features is deployed inside the Snowflake service perimeter, so you can run sentiment or classification on customer text without sending it to an outside API. To call the functions, a role needs the USE AI FUNCTIONS account-level privilege and either the CORTEX_USER or the AI_FUNCTIONS_USER database role.
Most of the functions are task-specific, so the work is picking the right one for the job:
| Function | What it does |
|---|---|
| AI_COMPLETE | Generates a completion for text or an image using a model you choose. The general-purpose option |
| AI_CLASSIFY | Classifies text or images into categories you define |
| AI_FILTER | Returns True or False for an input, for use in SELECT, WHERE or JOIN ON clauses |
| AI_EXTRACT | Extracts specific information from a string or a file |
| AI_SENTIMENT | Extracts sentiment from text |
| AI_SUMMARIZE / AI_SUMMARIZE_AGG | Summarises one input, or a whole text column across rows |
| AI_AGG | Returns insights across many rows of a text column, based on a prompt |
| AI_EMBED / AI_SIMILARITY | Creates embedding vectors, or scores the embedding similarity of two inputs |
| AI_TRANSLATE / AI_REDACT | Translates text between languages, or removes PII from it |
| AI_PARSE_DOCUMENT / AI_TRANSCRIBE | Extracts text and layout from staged documents, or transcribes staged audio and video |
Helper functions support the others. TO_FILE references a staged file, AI_COUNT_TOKENS checks an input against model limits, and PROMPT builds prompt objects. AI_AGG and AI_SUMMARIZE_AGG are not limited by the model's context window, so they can cover a whole column.
AI Functions are built for throughput, which makes them a good fit for batch work over large tables. For interactive use where latency matters, Snowflake points you to the REST APIs instead: Complete, Embed and Agents.
Checkpoint 1 of 7· Check yourself
A legal team wants the specific termination notice period pulled out of each contract text, not a summary of the whole contract. Which function is built for this?
AI_EXTRACT returns specific information from an input. AI_SUMMARIZE condenses the whole input, AI_CLASSIFY assigns a category, and AI_SENTIMENT scores tone.
“AI_EXTRACT: Extracts information from an input string or file, for example, text, images, and documents.”Source: docs.snowflake.com
Checkpoint 2 of 7· Exam question
A developer needs to publish an internal dashboard with sliders, buttons, and charts driven by live Snowflake data, and wants business users to open it directly from Snowsight without installing anything locally. Which service is designed for this?
Correct answer: A — Streamlit in Snowflake, which lets a Python app with interactive widgets run and render inside Snowsight as a deployed schema-level object.
- A. Streamlit in Snowflake is correct because it runs Python apps with interactive widgets and charts natively inside Snowsight, deployed as a schema-level object that business users can open with no local install.
- B. Notebooks are built for interactive, cell-by-cell exploration and documentation, not for packaging a polished widget-driven app for non-technical business users to consume.
- C. Snowpark UDFs execute logic invoked from SQL statements; they have no UI layer and cannot render sliders, buttons, or charts on their own.
- D. Snowsight dashboard tiles display results of saved queries or charts but do not support custom interactive widget logic written in Python.
Sources1
2.Cortex Search: managed retrieval over text
AI functions work on the input you pass them. Often, though, an LLM first needs to find the right passage among thousands of documents. Cortex Search handles that step. It is a hybrid search engine over your text data, combining vector and keyword search. Snowflake takes care of the embeddings, the infrastructure, quality tuning and keeping the index refreshed.
The main uses are retrieval augmented generation (RAG), where Search supplies an LLM with grounded context from your own data, and enterprise search, where it backs a search bar in an application. It can also act as the retrieval layer for Cortex Agents.
You create a search service as an object, either with one SQL statement or from AI & ML » Cortex Search in Snowsight:
CREATE OR REPLACE CORTEX SEARCH SERVICE transcript_search_service
ON transcript_text
ATTRIBUTES region
WAREHOUSE = cortex_search_wh
TARGET_LAG = '1 day'
EMBEDDING_MODEL = 'snowflake-arctic-embed-l-v2.0'
AS (
SELECT
transcript_text,
region,
agent_id
FROM support_transcripts
);What each clause does:
- ON names the column that gets searched.
- ATTRIBUTES makes region available as a filter.
- WAREHOUSE materialises the source query, both when the service is created and whenever the base table changes. Snowflake recommends a dedicated warehouse no larger than MEDIUM.
- TARGET_LAG sets how far the service may lag behind the base table.
The index is built during CREATE, so the statement can take a long time on large datasets. After that, you grant USAGE on the database, schema and service to other roles, check results with SNOWFLAKE.CORTEX.SEARCH_PREVIEW in SQL, and then query the service from applications through the Python API.
Checkpoint 3 of 7· Fill the gap
Which parameter tells the service to check the base table for updates about once a day?
CREATE OR REPLACE CORTEX SEARCH SERVICE transcript_search_service
ON transcript_text
ATTRIBUTES region
WAREHOUSE = cortex_search_wh
? = '1 day'
EMBEDDING_MODEL = 'snowflake-arctic-embed-l-v2.0'
AS (
SELECT
transcript_text,
region,
agent_id
FROM support_transcripts
);TARGET_LAG sets how far the service may fall behind its base table, here roughly one day.
Source: docs.snowflake.comCheckpoint 4 of 7· Put it in order
Put the documented Cortex Search workflow in order
- 1.Run CREATE CORTEX SEARCH SERVICE over the source table
- 2.Preview results with SNOWFLAKE.CORTEX.SEARCH_PREVIEW
- 3.GRANT USAGE on the database, schema and service to the consuming role
- 4.Query the service from the application using the Python API
The walkthrough creates the service and its index, grants usage, previews the results, and only then queries from an application.
“granted usage on it to your role, and previewed it, you can now query it from your application using the Python API.”Source: docs.snowflake.com
Sources2
3.Cortex Analyst: natural-language questions over structured data
Cortex Search works with unstructured text. Cortex Analyst works with structured data. It is a fully managed, LLM-powered service that lets business users ask questions in natural language and get answers without writing SQL. Behind the scenes it is an agentic text-to-SQL system. It is available as a REST API, not a SQL function, so you integrate it into Streamlit apps, Slack, Teams or a custom chat interface.
A database schema alone lacks business definitions, which is why Analyst relies on a semantic layer. The recommended form is Semantic Views: schema-level objects that define logical tables, dimensions, facts, metrics and relationships. Semantic Views come with RBAC, can be shared, and support custom instructions. Older semantic model YAML files stored on stages still work, but only for backward compatibility.
On governance, Cortex Analyst does not train on Customer Data, and the queries it generates follow your RBAC policies. To call it, a role needs SNOWFLAKE.CORTEX_USER, which covers all Covered AI features, or SNOWFLAKE.CORTEX_ANALYST_USER, which covers Analyst only. It also needs SELECT on the tables the semantic model uses. CORTEX_USER is granted to PUBLIC by default, so restricting access means revoking it and granting CORTEX_ANALYST_USER through a custom role.
Checkpoint 5 of 7· Match them up
Match each Semantic View element to what it defines
Tap a term, then the definition that fits it.
These elements give Analyst business meaning a raw schema doesn't have, which improves the accuracy of the SQL it generates.
“Metrics that aggregate data into business KPIs (such as total revenue or average order value)”Source: docs.snowflake.com
| Feature | Interface | Works on | Typical use |
|---|---|---|---|
| AI SQL functions (e.g. AI_COMPLETE, AI_CLASSIFY) | SQL functions, also Python | Text, images and staged files passed as input | High-throughput batch enrichment of table rows |
| Cortex Search | CORTEX SEARCH SERVICE object; queried with SEARCH_PREVIEW or the Python API | Text data, through a hybrid vector and keyword index | RAG retrieval and enterprise search |
| Cortex Analyst | REST API | Structured data described by Semantic Views | Self-serve natural-language analytics (text-to-SQL) |
Checkpoint 6 of 7· Check yourself
Sales managers want to type "What was revenue by region last quarter?" into a Slack bot and get an answer computed from Snowflake tables. Which feature fits?
Answering business questions over structured data with generated SQL is exactly Cortex Analyst's job, and its REST API is how it plugs into tools such as Slack.
“business users can ask questions in natural language and receive direct answers without writing SQL”Source: docs.snowflake.com
Checkpoint 7 of 7· Exam question
An engineering team wants to write DataFrame-style transformation logic in Python that compiles down to SQL and executes entirely inside Snowflake's compute, avoiding data movement to an external Spark or pandas cluster. Which technology fits this requirement?
Correct answer: A — Snowpark, whose Python DataFrame API translates transformation operations into SQL that runs on Snowflake virtual warehouses without moving data out.
- A. Snowpark is correct because its Python DataFrame API mirrors pandas-style syntax while lazily compiling operations into SQL that Snowflake executes on its own compute, so data never leaves the platform.
- B. Streamlit in Snowflake focuses on rendering interactive UI elements from query results; it is a presentation layer, not a DataFrame transformation engine.
- C. Notebooks are an execution surface for running code, including Snowpark code, but the DataFrame-to-SQL translation capability itself belongs to the Snowpark API, not the notebook interface.
- D. Cortex AI SQL functions expose LLM-backed operations like summarization or translation as SQL functions; they do not offer a general DataFrame transformation API.
Sources3
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Cortex Analyst is another AI SQL function you call inside a SELECT, like AI_COMPLETE.Why is that wrong?
Cortex Analyst is a managed service exposed as a REST API that generates SQL from natural language. AI SQL functions are the SQL-callable feature.
Covered in Cortex Analyst: natural-language questions over structured data
2.To use Cortex Search you must first generate embeddings yourself and manage a vector index.Why is that wrong?
Cortex Search provides a hybrid vector and keyword engine and handles embedding, infrastructure, tuning and index refreshes for you.
Covered in Cortex Search: managed retrieval over text
3.Cortex AI SQL functions are the best choice for low-latency, interactive chat responses.Why is that wrong?
AI Functions are optimised for throughput and batch processing. For latency-sensitive interactive work, Snowflake recommends the REST APIs.
Covered in Cortex AI SQL functions: LLMs as ordinary SQL calls
Practise it for real
Create a Cortex Search Service over a small support-transcript table and confirm it returns filtered results
1.Create the support_transcripts table with transcript_text, region and agent_id columns, and insert the four sample rows from the docs
Why: A search service needs a source query over text data
You should see: A table with four transcripts across three regions
2.Run CREATE OR REPLACE CORTEX SEARCH SERVICE transcript_search_service ON transcript_text ATTRIBUTES region with an X-SMALL warehouse and TARGET_LAG = '1 day'
Why: This builds the index and sets which column is searched and which can be filtered
You should see: The statement completes after the index is built. On large tables this can take much longer
3.GRANT USAGE on the database, the schema and the Cortex Search service to the role that will query it
Why: Other roles cannot use the service without USAGE on all three objects
You should see: The grants succeed
4.Run SNOWFLAKE.CORTEX.SEARCH_PREVIEW with the query "internet issues", filter {"@eq": {"region": "North America"}} and limit 1
Why: Previewing confirms the service is populated before an application relies on it
You should see: One result: the North America transcript about the internet being down
Stuck? Get a nudge
If the filter returns nothing, check that region appears in both the ATTRIBUTES clause and the source SELECT.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“All the LLMs that Snowflake provides access to via our Snowflake AI Features are deployed within the Snowflake Service perimeter.”
↩︎ Cortex AI SQL functions: LLMs as ordinary SQL calls“your role needs the USE AI FUNCTIONS account-level privilege and one of the CORTEX_USER or AI_FUNCTIONS_USER database roles”
↩︎ Cortex AI SQL functions: LLMs as ordinary SQL calls“AI_CLASSIFY: Classifies text or images into user-defined categories.”
↩︎ Cortex AI SQL functions: LLMs as ordinary SQL calls“For more interactive use cases where latency is important, use the REST API.”
↩︎ Exam trap 3“AI_EXTRACT: Extracts information from an input string or file, for example, text, images, and documents.”
↩︎ Checkpoint - 2.https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-search/cortex-search-overviewOfficial docs
“a hybrid (vector and keyword) search engine on your text data in minutes”
↩︎ Cortex Search: managed retrieval over text“The two primary use cases for Cortex Search are retrieval augmented generation (RAG) and enterprise search.”
↩︎ Cortex Search: managed retrieval over text“Snowflake recommends using a dedicated warehouse of size no larger than MEDIUM for each service.”
↩︎ Cortex Search: managed retrieval over text“without having to worry about embedding, infrastructure maintenance, search quality parameter tuning, or ongoing index refreshes”
↩︎ Exam trap 2“granted usage on it to your role, and previewed it, you can now query it from your application using the Python API.”
↩︎ Checkpoint - 3.
“Cortex Analyst uses Semantic Views to understand your data and generate accurate SQL queries.”
↩︎ Cortex Analyst: natural-language questions over structured data“Legacy semantic model YAML files (stored on stages) are still supported for backward compatibility, but Semantic Views are the recommended approach for new implementations.”
↩︎ Cortex Analyst: natural-language questions over structured data“CORTEX_USER provides access to all Covered AI features, while CORTEX_ANALYST_USER provides access only to Cortex Analyst.”
↩︎ Cortex Analyst: natural-language questions over structured data“By default, the CORTEX_USER role is granted to the PUBLIC role.”
↩︎ Cortex Analyst: natural-language questions over structured data“Available as a convenient REST API, Cortex Analyst can be seamlessly integrated into any application.”
↩︎ Exam trap 1“This SQL query is then executed in your Snowflake virtual warehouse to generate the final output.”
↩︎ Prediction“Metrics that aggregate data into business KPIs (such as total revenue or average order value)”
↩︎ Checkpoint“business users can ask questions in natural language and receive direct answers without writing SQL”
↩︎ Checkpoint