ARA-C01 exam dumps

ARA-C01 practice question 35 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 35

Single answerSystem roles and associated best practices

A global company is redesigning access in its Snowflake account after an audit found that several platform engineers were using the ACCOUNTADMIN role for routine work, including warehouse management and role provisioning. The security team wants to reduce risk while preserving operational efficiency. Which approach best aligns with Snowflake system role best practices?

  1. A

    Grant ACCOUNTADMIN to all platform engineers, but require MFA and session policies so they can safely perform all administrative tasks from a single role.

  2. B

    Use SECURITYADMIN for managing users and roles, SYSADMIN for creating and owning warehouses, databases, and other objects, and reserve ACCOUNTADMIN only for a very small number of users for account-level administration.

  3. C

    Assign USERADMIN to platform engineers for all object creation tasks because it inherits the privileges needed to manage warehouses and databases without needing SYSADMIN.

  4. D

    Make SYSADMIN the parent role of ACCOUNTADMIN so object administrators can escalate when necessary without needing separate privileged assignments.

Show answer and explanation

Correct answer: B

Explanation

Snowflake system roles are designed to support separation of duties. In general, SYSADMIN is responsible for object creation and ownership, SECURITYADMIN manages roles and grants, and USERADMIN manages users. ACCOUNTADMIN is the highest-privileged role and is intended for a very limited set of administrators performing account-level tasks, not routine daily operations. A key best practice is to avoid using ACCOUNTADMIN for standard engineering work such as warehouse creation or ordinary role provisioning. Instead, organizations should delegate responsibilities to appropriate lower-privileged system roles or custom functional roles. This aligns with Snowflake documentation on access control and system-defined roles, which emphasizes least privilege, role hierarchy awareness, and limiting use of ACCOUNTADMIN.

  • A. Incorrect.

    This is incorrect. Although MFA and session policies improve security posture, they do not address the core best-practice problem: ACCOUNTADMIN is the most powerful system role and should not be used for routine operational tasks. Snowflake guidance is to limit ACCOUNTADMIN usage to a very small set of trusted administrators and use lower-privileged roles for day-to-day administration.

  • B. Correct.

    This is correct. This approach follows Snowflake's separation-of-duties model for system roles. SECURITYADMIN is intended for managing roles and grants, USERADMIN for users, and SYSADMIN for creating and owning objects such as warehouses and databases. ACCOUNTADMIN, which combines the highest-level administrative capabilities, should be tightly restricted and used sparingly for exceptional account-level tasks. This minimizes blast radius while preserving operational capability.

  • C. Incorrect.

    This is incorrect. USERADMIN is focused on user and role management and does not serve as the primary role for object creation and ownership. A common misconception is that user administration implies broader infrastructure administration. In practice, object lifecycle management belongs with SYSADMIN or custom roles granted appropriate privileges.

  • D. Incorrect.

    This is incorrect. ACCOUNTADMIN is already the top-level administrative system role and should not be restructured as a child of SYSADMIN. Reversing or altering the intended hierarchy undermines Snowflake's role design and creates governance risk. Best practice is to preserve clear privilege boundaries and grant high-privilege roles only where justified.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam