ADA-C01 exam dumps

ADA-C01 practice question 502 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 502

Single answerManage Native Apps

A Snowflake administrator at a consumer account needs to deploy a Snowflake Native App from a private listing for a security analytics vendor. The vendor's app requires creating application objects in the consumer account and needs access to a specific events database after installation. The security team requires that the app receive only the minimum privileges needed, and they do not want to grant broad account-level access during installation. Which action should the administrator take to meet these requirements?

  1. A

    Install the app using a role with ACCOUNTADMIN, because Native Apps require full account-level privileges to create application objects and request data access.

  2. B

    Install the app, then grant the app access only to the required events database or specific objects through application roles and privileges requested by the app.

  3. C

    Create the app in a reader account first, validate requested privileges there, and then promote it into the consumer account to avoid granting access directly.

  4. D

    Clone the events database into the application container so the app can read the cloned data without any additional grants after installation.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to install the app and then explicitly grant only the required access to the app for the events database or specific underlying objects. In Snowflake Native Apps, consumers retain control over what the installed application can access in their account. This is a key security property of the Native App Framework: the app can request privileges or references, but the consumer decides whether to grant them. From an administrator perspective, the correct pattern is to follow least-privilege access, review what the app requests, and grant only the minimum necessary permissions after installation rather than defaulting to ACCOUNTADMIN-level access. This aligns with Snowflake documentation and best practices for managing Native Apps, application roles, and consumer-controlled privilege grants.

  • A. Incorrect.

    Incorrect. Native Apps do not inherently require broad ACCOUNTADMIN access simply because they create application objects. While a sufficiently privileged role is needed to install and manage the application package in the consumer account, best practice is to avoid unnecessary account-level privileges and grant only the permissions the app actually needs. Using ACCOUNTADMIN as a blanket requirement violates least-privilege principles.

  • B. Correct.

    Correct. This approach aligns with how Snowflake Native Apps are managed in consumer accounts. After installation, the consumer can grant the application access to specific databases, schemas, or objects that the app requests, rather than granting broad privileges upfront. This supports least privilege and allows the administrator to control exactly what data the app can use.

  • C. Incorrect.

    Incorrect. Reader accounts are not used as a staging area for Native App validation in this way. A reader account is a special Snowflake account managed by a provider for data sharing use cases, not a mechanism for testing or promoting Native Apps into another consumer account. This option reflects a common misunderstanding between data sharing constructs and Native App lifecycle management.

  • D. Incorrect.

    Incorrect. An installed Native App does not gain unrestricted ability to duplicate consumer data into its own context just to avoid grants. Cloning a consumer database into an application's managed objects is not the standard or intended security model for granting app data access. Native Apps typically rely on explicit consumer grants to shared content or referenced objects.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam