ADA-C01 exam dumps

ADA-C01 practice question 5 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 5

Single answer1.1 Manage administrative roles

A Snowflake account uses a centralized platform team to manage security. The company wants to delegate user and role administration to an identity operations team without giving that team broad access to data objects or account-wide configuration. The identity operations team must be able to create users, reset passwords, rotate key pairs, and grant or revoke roles to users. Which role should be granted to the identity operations team to meet these requirements while following least-privilege best practices?

  1. A

    Grant the SECURITYADMIN role

  2. B

    Grant the USERADMIN role

  3. C

    Grant the SYSADMIN role

  4. D

    Grant the ACCOUNTADMIN role

Show answer and explanation

Correct answer: B

Explanation

The best answer is USERADMIN. Snowflake provides distinct system-defined administrative roles to support separation of duties. USERADMIN is designed for user and role management, including creating users and roles and granting roles to users. SECURITYADMIN is more powerful because it manages grants and security objects broadly, so it is typically reserved for central security administration rather than routine identity operations. SYSADMIN is focused on object administration, and ACCOUNTADMIN should be tightly restricted because it has near-unrestricted administrative capabilities. This aligns with Snowflake best practices for role-based access control and separation of duties: use the least-privileged built-in admin role that satisfies the operational requirement. Reference: Snowflake documentation on system-defined roles and access control best practices, especially the descriptions of USERADMIN, SECURITYADMIN, SYSADMIN, and ACCOUNTADMIN.

  • A. Incorrect.

    Incorrect. SECURITYADMIN is a powerful system role that can manage grants globally, including granting object privileges and managing roles. While it can administer roles, it provides broader security administration capabilities than required for a team that only needs to manage users and grant or revoke roles to users. This exceeds least-privilege guidance.

  • B. Correct.

    Correct. USERADMIN is the system role intended for creating and managing users and roles. In practice, it is the appropriate role to delegate when a team needs to create users, manage user properties such as passwords or public keys, and grant or revoke roles to users, without also receiving broad object privilege management or account-level administrative powers.

  • C. Incorrect.

    Incorrect. SYSADMIN is primarily intended to create and manage warehouses, databases, schemas, and other objects. It is the recommended owner of most custom roles and objects, but it is not the least-privilege role for user lifecycle administration. Granting SYSADMIN would not align with the requirement to delegate identity administration specifically.

  • D. Incorrect.

    Incorrect. ACCOUNTADMIN is the most powerful built-in administrative role and combines capabilities from SYSADMIN and SECURITYADMIN, along with account-level administration. It would allow the team to perform far more actions than required, making it inappropriate for a least-privilege delegation model.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam