SnowPro Core (COF-C03) · Free practice question 2 of 15
SECURITYADMIN for user and role management
You're setting up role-based access in a new Snowflake account. Which built-in role is the recommended starting point for creating and managing users and other roles?
- A.ACCOUNTADMIN
- B.SECURITYADMIN
- C.SYSADMIN
- D.PUBLIC
Show answer and explanation
Correct answer: B. SECURITYADMIN
Why: SECURITYADMIN is purpose-built for user and role management. ACCOUNTADMIN can do it but has broader powers and should be used sparingly. SYSADMIN owns the object hierarchy (warehouses, databases, schemas). PUBLIC is granted to every role and is for default grants only.
More free SnowPro Core (COF-C03) questions
- Micro-partition immutability
- Multi-cluster warehouses for concurrency
- Snowflake edition for extended Time Travel
- Recovering a truncated table with Time Travel
- Types of internal stages
- File sizing for COPY INTO
- Query result cache
- Reader accounts for non-Snowflake consumers
- LATERAL FLATTEN on VARIANT arrays
- Streams and tasks for change data capture
- Clustering keys for partition pruning
- Network policies for IP allowlisting
- Zero-copy cloning for QA environments
- Snowpipe auto-ingest for low latency