ADA-C01 exam dumps

ADA-C01 practice question 6 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 6

Single answer1.1 Manage administrative roles

A company is tightening administrative controls in Snowflake after an internal audit. The security team wants one role to manage users, passwords, MFA enrollment resets, and role grants, while a separate role must manage warehouses, resource monitors, and account-level parameters. The team also wants to avoid granting broader privileges than necessary. Which pair of built-in system roles best meets these requirements?

  1. A

    Grant SECURITYADMIN for user and role administration, and SYSADMIN for warehouses, resource monitors, and account parameter management

  2. B

    Grant USERADMIN for user administration, and ACCOUNTADMIN for warehouses, resource monitors, and account parameter management

  3. C

    Grant USERADMIN for user and role administration, and SYSADMIN for warehouses, resource monitors, and account parameter management

  4. D

    Grant SECURITYADMIN for user and role administration, and ACCOUNTADMIN for warehouses, resource monitors, and account parameter management

Show answer and explanation

Correct answer: D

Explanation

Snowflake best practice is to limit use of ACCOUNTADMIN because it is the most powerful built-in role, combining capabilities of SYSADMIN and SECURITYADMIN plus account-level administration. For managing administrative roles, candidates should understand the distinction between USERADMIN, SECURITYADMIN, SYSADMIN, and ACCOUNTADMIN. USERADMIN is focused on users and roles, SECURITYADMIN handles security-related administration and grants, SYSADMIN manages object creation and operational administration, and ACCOUNTADMIN is required for the broadest account-level tasks such as account parameter management. In this scenario, the cleanest least-privilege alignment among built-in roles is SECURITYADMIN for user/role and grant administration, and ACCOUNTADMIN for warehouses, resource monitors, and account-level parameters. This reflects Snowflake documentation on system-defined roles and the recommendation to reserve ACCOUNTADMIN for only those tasks that require it.

  • A. Incorrect.

    Incorrect. SECURITYADMIN can manage grants globally and is appropriate for user and role administration, but SYSADMIN is primarily intended to create and manage objects such as warehouses and databases, not broader account-level administration such as account parameters. Account-level administrative tasks are typically handled by ACCOUNTADMIN.

  • B. Incorrect.

    Incorrect. USERADMIN is the built-in role focused on creating and managing users and roles, but it does not have the broader grant-management capabilities associated with SECURITYADMIN. In the scenario, the security team specifically wants management of role grants as part of the administrative function. In addition, while ACCOUNTADMIN can manage warehouses, resource monitors, and account parameters, this option does not best align with the requirement to centralize user and grant administration under the most appropriate built-in security role.

  • C. Incorrect.

    Incorrect. USERADMIN can create and manage users and roles, but it is not the best fit when the requirement explicitly includes role grants and broader security administration. SYSADMIN can manage warehouses and many object-level administrative tasks, but it is not the correct built-in role for account-level parameter management.

  • D. Correct.

    Correct. SECURITYADMIN is the built-in system role intended for security-related administration, including managing grants and user/role administration. ACCOUNTADMIN is the top-level administrative role and is required for broad account-level administration, including managing account parameters and other account-wide settings. It can also manage warehouses and resource monitors. This pairing separates security administration from account/platform administration while avoiding use of ACCOUNTADMIN for both functions.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam