What you will be able to do
- Explain how the four Snowflake editions build on each other and how an edition affects cost
- Identify the features that need Enterprise Edition or higher
- Choose the lowest edition for compliance, failover/failback, or full isolation requirements
- Find an account's edition with SQL
1.Four editions, each building on the last
Snowflake has four editions: Standard, Enterprise, Business Critical and Virtual Private Snowflake (VPS). They are cumulative. Each edition includes everything in the one below it and adds edition-specific features, higher levels of service, or both. This shapes most exam questions on editions: when a scenario needs a capability, the answer is usually the *lowest* edition that provides it, because every edition above it includes it too.
The edition affects price as well as features. It sets the unit costs for the credits and data storage you use. Two other factors also affect unit costs: the account's region, and whether it is an On Demand account (usage-based pricing, no long-term licensing requirements) or a Capacity account (discounted pricing in return for an upfront Capacity commitment). Changing editions is described as easy, so an organization can move up as its needs grow.
Standard Edition is the introductory offering, with full, unlimited access to all of Snowflake's standard features. Plenty is already included at this level: SOC 2 Type II certification, federated authentication and SSO, OAuth, network policies, multi-factor authentication, automatic encryption of all data, object-level access control, Time Travel up to 1 day, and 7 days of Fail-safe. Virtual warehouses, resource monitors, dynamic tables, external tables, Iceberg tables, hybrid tables, Snowpark, Snowpipe, streams and tasks, and database and share replication are all available on every edition too.
SELECT edition FROM SNOWFLAKE.ORGANIZATION_USAGE.ACCOUNTS WHERE account_name = CURRENT_ACCOUNT();Checkpoint 1 of 6· Fill the gap
Which schema completes the query that returns the current account's edition?
SELECT edition FROM SNOWFLAKE. ? .ACCOUNTS WHERE account_name = CURRENT_ACCOUNT();The edition column is in the ACCOUNTS view of the ORGANIZATION_USAGE schema, and you need access to that schema to query it.
Source: docs.snowflake.comCheckpoint 2 of 6· Check yourself
Besides the features available, what does the choice of Snowflake edition directly determine?
The edition sets the unit costs for credits and storage. Region and On Demand vs Capacity pricing also affect those costs.
“The Snowflake Edition that your organization chooses determines the unit costs for the credits and the data storage you use.”Source: docs.snowflake.com
Sources1
2.What Enterprise Edition adds
Enterprise Edition includes everything in Standard and adds features aimed at large-scale enterprises and organizations. Most fall into three groups.
Scale and performance. Multi-cluster virtual warehouses, which scale compute to meet concurrency needs, start at Enterprise. So do the query acceleration service, search optimization for point lookups, and materialized views with automatic maintenance. A Standard account that is seeing query queuing can resize a warehouse or add more warehouses by hand, but it can't get automatic multi-cluster scaling without upgrading.
Longer history. Standard Time Travel goes back 1 day. Enterprise extends it to up to 90 days. Fail-safe stays at 7 days on every edition.
Governance and privacy. Column-level security (masking policies), row-level security (row access policies), aggregation and projection policies, differential privacy, sensitive-data classification, the ACCESS_HISTORY view for auditing user access, and periodic rekeying of encrypted data all need Enterprise or higher. Object tags exist on every edition, but some tagging features need Enterprise.
| Feature | Standard | Enterprise | Business Critical | VPS |
|---|---|---|---|---|
| Time Travel up to 1 day, Fail-safe 7 days | ✔ | ✔ | ✔ | ✔ |
| Database and share replication | ✔ | ✔ | ✔ | ✔ |
| Multi-cluster virtual warehouses | — | ✔ | ✔ | ✔ |
| Extended Time Travel (up to 90 days) | — | ✔ | ✔ | ✔ |
| Column-level and row-level security | — | ✔ | ✔ | ✔ |
| Materialized views, search optimization, query acceleration | — | ✔ | ✔ | ✔ |
| Tri-Secret Secure (customer-managed keys) | — | — | ✔ | ✔ |
| Private connectivity (AWS PrivateLink, Azure Private Link, Google Cloud Private Service Connect) | — | — | ✔ | ✔ |
| PHI (HIPAA/HITRUST CSF), PCI DSS, FedRAMP/ITAR support | — | — | ✔ | ✔ |
| Failover/failback and client connection redirection | — | — | ✔ | ✔ |
| Dedicated metadata store and pool of compute resources | — | — | — | ✔ |
Checkpoint 3 of 6· Check yourself
A Standard Edition customer wants masking policies on sensitive columns and needs to restore data changed 30 days ago. What is the lowest edition that covers both?
Column-level security and Time Travel beyond 1 day (up to 90 days) both start at Enterprise Edition.
“Column-level Security to apply masking policies to columns in tables or views — requires Enterprise Edition (or higher).”Source: docs.snowflake.com
Checkpoint 4 of 6· Exam question
A security team configures SSO federated authentication and a network policy once at the account level, and every virtual warehouse a user connects through immediately enforces the same login requirements without any per-warehouse configuration. Which layer provides this centralized authentication and access-control enforcement?
Correct answer: B — Cloud Services layer
- A. Incorrect. The compute layer consists of virtual warehouses that execute queries; it consumes access decisions rather than making them, so it cannot be the source of centralized authentication.
- B. Correct. The Cloud Services layer coordinates authentication, SSO, network policies, and RBAC for the entire account, so the same enforcement applies uniformly regardless of which warehouse a session uses.
- C. Incorrect. The storage layer holds table and file data; it has no role in evaluating login credentials or session-level network policies.
- D. Incorrect. Warehouses do not maintain their own separate authentication configuration, which is exactly why the team did not need to repeat the setup per warehouse.
3.Business Critical and Virtual Private Snowflake
Business Critical Edition was formerly called Enterprise for Sensitive Data (ESD). It includes everything in Enterprise and adds stronger security and data protection for organizations with extremely sensitive data, especially PHI that must comply with HIPAA and HITRUST CSF. It is also the lowest edition with PCI DSS support, support for U.S. public-sector requirements such as FedRAMP and ITAR, customer-managed encryption keys through Tri-Secret Secure, and private connectivity to the Snowflake service through AWS PrivateLink, Azure Private Link or Google Cloud Private Service Connect.
Business Critical also adds account failover/failback for business continuity and disaster recovery, along with redirecting client connections between accounts. This is easy to confuse: *replicating* databases and shares between accounts is available on every edition, but *failing over* to another account starts at Business Critical. One more requirement applies to PHI regardless of edition. A signed business associate agreement (BAA) with Snowflake Inc. has to be in place before any PHI is stored.
Virtual Private Snowflake (VPS) is the highest level of security, intended for organizations with the strictest requirements, such as financial institutions. It includes everything in Business Critical, but runs in a completely separate Snowflake environment, isolated from all other Snowflake accounts. VPS accounts don't share any hardware resources with accounts outside the VPS. Two matrix rows are VPS-only: a dedicated metadata store and pool of compute resources, and full encryption of all data transmissions, including internal transmissions within the VPS. VPS account locators also use a different format from other editions.
Checkpoint 5 of 6· Check yourself
A bank needs its Snowflake environment to share no hardware resources at all with any other Snowflake customer. Which edition meets this requirement?
Only VPS runs in a completely separate environment that shares no hardware with accounts outside it. Business Critical adds security features but not that isolation.
“isolated from all other Snowflake accounts (that is, VPS accounts do not share any type of hardware resources with accounts outside the VPS).”Source: docs.snowflake.com
Checkpoint 6 of 6· Exam question
An analyst runs `DESCRIBE TABLE orders` and `SHOW TABLES IN SCHEMA sales` in Snowsight while no virtual warehouse is running, and both commands return results instantly without the analyst resuming a warehouse. Which layer supplied these results?
Correct answer: C — Cloud Services layer
- A. Incorrect. The storage layer holds the actual table data and micro-partitions, but object metadata such as column definitions and table lists is served through the services layer's catalog, not read directly from storage for these commands.
- B. Incorrect. `DESCRIBE` and `SHOW` did not require a running warehouse in this scenario, which rules out the compute layer as the source of the response.
- C. Correct. The Cloud Services layer maintains the metadata catalog for databases, schemas, and tables, so structural commands like `DESCRIBE` and `SHOW` are answered from that catalog without needing compute resources.
- D. Incorrect. Snowflake does not cache table definitions on the client machine between sessions; the catalog lookup happens server-side in the services layer on every call.
Sources1
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Multi-cluster warehouses can be turned on in Standard Edition to handle query queuing.Why is that wrong?
Multi-cluster warehouses are an Enterprise Edition feature. A Standard account can only resize a warehouse or redirect queries to more warehouses by hand.
Covered in What Enterprise Edition adds
2.Storing PHI under HIPAA requires Virtual Private Snowflake.Why is that wrong?
PHI support starts at Business Critical Edition, and a signed BAA with Snowflake is also needed. VPS adds full isolation, not PHI eligibility.
3.Because database replication is on every edition, account failover/failback is too.Why is that wrong?
Replication is on all editions, but failover and failback between accounts starts at Business Critical.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Each successive edition builds on the previous edition through the addition of edition-specific features and/or higher levels of service.”
↩︎ Four editions, each building on the last“Capacity: Discounted pricing based on an upfront Capacity commitment.”
↩︎ Four editions, each building on the last“Standard Edition is our introductory level offering, providing full, unlimited access to all of Snowflake’s standard features.”
↩︎ Four editions, each building on the last“with additional features that are designed specifically for the needs of large-scale enterprises and organizations.”
↩︎ What Enterprise Edition adds“Business Critical Edition, formerly known as Enterprise for Sensitive Data (ESD), offers even higher levels of data protection”
↩︎ Business Critical and Virtual Private Snowflake“before any PHI data can be stored in Snowflake, a signed business associate agreement (BAA) must be in place”
↩︎ Business Critical and Virtual Private Snowflake“Dedicated metadata store and pool of compute resources (used in virtual warehouses).”
↩︎ Business Critical and Virtual Private Snowflake“In addition, account failover/failback adds support for business continuity and disaster recovery.”
↩︎ Exam trap 3“The Snowflake Edition that your organization chooses determines the unit costs for the credits and the data storage you use.”
↩︎ Checkpoint“In addition, account failover/failback adds support for business continuity and disaster recovery.”
↩︎ Prediction“isolated from all other Snowflake accounts (that is, VPS accounts do not share any type of hardware resources with accounts outside the VPS).”
↩︎ Checkpoint - 2.
“Snowflake Time Travel (1 day standard for all accounts; additional days, up to 90, allowed with Snowflake Enterprise)”
↩︎ What Enterprise Edition adds“Support for PHI data (in compliance with HIPAA and HITRUST CSF regulations) — requires Business Critical Edition (or higher).”
↩︎ Exam trap 2“Column-level Security to apply masking policies to columns in tables or views — requires Enterprise Edition (or higher).”
↩︎ Checkpoint - 3.
“Multi-cluster warehouses are an Enterprise Edition feature.”
↩︎ What Enterprise Edition adds“Multi-cluster warehouses are an Enterprise Edition feature.”
↩︎ Exam trap 1