ADA-C01 exam dumps

ADA-C01 practice question 51 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 51

Single answerCreate additional Administrators

A Snowflake account currently relies on the built-in ACCOUNTADMIN user for all administrative work. To meet security and operational requirements, the company wants two senior platform engineers to perform day-to-day user, role, warehouse, and database administration without sharing the ACCOUNTADMIN credentials. The security team also requires that the built-in ACCOUNTADMIN role be used only for exceptional break-glass tasks. Which approach should the lead Snowflake architect take to create additional administrators while following Snowflake best practices?

  1. A

    Create two new users, grant them the ACCOUNTADMIN role directly, and instruct them to use ACCOUNTADMIN for routine administration so they have full coverage of all admin tasks.

  2. B

    Create a custom role for administrative duties, grant the required system and object privileges or appropriate admin roles to that custom role, assign it to the two engineers, and keep ACCOUNTADMIN restricted for limited emergency use.

  3. C

    Clone the ACCOUNTADMIN role into a new role, assign the cloned role to the engineers, and revoke ACCOUNTADMIN from the original built-in administrator user.

  4. D

    Grant the SECURITYADMIN role to one engineer and the SYSADMIN role to the other engineer, because Snowflake does not allow a user to hold both administrative capabilities unless they also have ACCOUNTADMIN.

Show answer and explanation

Correct answer: B

Explanation

The correct solution is to create additional administrator users and assign them delegated administrative roles rather than relying on the built-in ACCOUNTADMIN role for everyday operations. Snowflake recommends limiting use of ACCOUNTADMIN because it has unrestricted power across the account. In practice, organizations often create named admin users and assign a combination of built-in roles such as SYSADMIN and SECURITYADMIN, or a custom role hierarchy with explicitly granted privileges, to support operational administration while preserving least privilege and auditability. This approach also avoids credential sharing and aligns with common security best practices for privileged access management. Relevant Snowflake documentation includes guidance on access control, role-based access control (RBAC), system-defined roles such as ACCOUNTADMIN, SYSADMIN, and SECURITYADMIN, and best practices that discourage day-to-day use of ACCOUNTADMIN except for exceptional administrative tasks.

  • A. Incorrect.

    Incorrect. Although granting ACCOUNTADMIN would technically allow the engineers to perform administrative tasks, it violates Snowflake least-privilege guidance. ACCOUNTADMIN is the highest-level role in the system and should be tightly controlled and reserved for limited use. Using it for routine administration increases risk and makes separation of duties harder to enforce.

  • B. Correct.

    Correct. Snowflake best practice is to avoid routine use of ACCOUNTADMIN and instead create additional administrative users and roles with only the privileges needed for their job functions. Depending on the organization's model, this can include granting appropriate built-in administrative roles such as SYSADMIN and SECURITYADMIN, or building a custom role hierarchy that delegates required privileges for managing users, roles, warehouses, and databases. This supports least privilege, accountability, and operational continuity without shared credentials.

  • C. Incorrect.

    Incorrect. Snowflake does not support cloning roles in the way described to reproduce the built-in ACCOUNTADMIN role for administrative delegation. More importantly, duplicating full ACCOUNTADMIN-equivalent access would still undermine least-privilege controls. Revoking ACCOUNTADMIN from the original built-in administrator user is also not the recommended pattern for managing administrative access.

  • D. Incorrect.

    Incorrect. A user can be granted multiple roles in Snowflake, including both SYSADMIN and SECURITYADMIN, without requiring ACCOUNTADMIN. Assigning one role to each engineer would unnecessarily split responsibilities and would not satisfy the requirement that both engineers be able to perform the full set of day-to-day administrative tasks.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam