ADA-C01 exam dumps

ADA-C01 practice question 39 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 39

Select 3Secure the ACCOUNTADMIN role

A Snowflake administrator is hardening access to the production account after an internal audit found that several senior engineers can directly use the ACCOUNTADMIN role for routine work. The company wants to reduce the risk of accidental or unauthorized use of this highly privileged role while still ensuring emergency administrative access is available. Which TWO actions best align with Snowflake security best practices for securing the ACCOUNTADMIN role?

  1. A

    Limit assignment of the ACCOUNTADMIN role to as few users as possible, and require those users to use a less privileged role for daily tasks.

  2. B

    Assign ACCOUNTADMIN to all users who have the SYSADMIN role so they can manage objects and account settings without additional role switching.

  3. C

    Require multi-factor authentication for users who are granted ACCOUNTADMIN, and restrict use of the role to designated administrators.

  4. D

    Transfer all object ownership from SYSADMIN to ACCOUNTADMIN so privileged work is centralized under a single high-level role.

  5. E

    Create separate custom admin roles for specialized duties and reserve ACCOUNTADMIN only for tasks that truly require top-level account privileges.

Show answer and explanation

Correct answers: A, C, E

Explanation

To secure ACCOUNTADMIN, Snowflake best practices emphasize least privilege, minimizing who holds the role, and avoiding its use for day-to-day administration. ACCOUNTADMIN is the highest-level role in a Snowflake account and should be restricted to a very small set of trusted administrators. Those administrators should typically use lower-privileged roles for routine work and switch to ACCOUNTADMIN only when required. MFA is an important control for privileged access and is strongly aligned with protecting high-risk roles. In addition, organizations should create custom administrative roles for narrowly scoped tasks instead of overusing ACCOUNTADMIN. This approach improves separation of duties and limits exposure. These recommendations align with Snowflake guidance around role-based access control, least-privilege design, and protecting powerful system-defined roles such as ACCOUNTADMIN.

  • A. Correct.

    Correct. Snowflake best practice is to tightly restrict the ACCOUNTADMIN role because it has broad control over account-level settings, billing-related capabilities, security integrations, and access management. Users who need occasional elevated access should normally operate with lower-privileged roles and switch to ACCOUNTADMIN only when necessary. This supports least privilege and reduces the blast radius of mistakes.

  • B. Incorrect.

    Incorrect. Granting ACCOUNTADMIN broadly to SYSADMIN users weakens separation of duties and unnecessarily expands the number of users with the most powerful role in the account. SYSADMIN is intended for managing objects and workloads, while ACCOUNTADMIN is reserved for the highest level of account administration. Broad inheritance of ACCOUNTADMIN is the opposite of hardening.

  • C. Correct.

    Correct. Requiring MFA for highly privileged users is a key security control and is especially important for users who can activate ACCOUNTADMIN. Combining MFA with limiting the role to designated administrators helps reduce the risk of credential compromise leading to full account takeover.

  • D. Incorrect.

    Incorrect. Centralizing ownership under ACCOUNTADMIN is not a recommended security pattern. In Snowflake, SYSADMIN is commonly used for object management, while ACCOUNTADMIN should be used sparingly for account-level administration. Moving broad ownership to ACCOUNTADMIN increases operational risk and makes high-privilege use more common than necessary.

  • E. Correct.

    Correct. Creating custom admin roles for focused responsibilities, such as user administration, security integration management, or warehouse governance, allows organizations to delegate necessary capabilities without exposing full ACCOUNTADMIN privileges. This follows least privilege and is a practical way to keep ACCOUNTADMIN reserved for rare, top-level administrative tasks.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam