SnowPro Associate: Platform exam dumps

SnowPro Associate: Platform practice question 120 of 367

SnowPro® Associate: Platform Certification. Associate level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Associate: Platform Question 120

Single answer2.1 Define the roles that are used in Snowflake.

A Snowflake account is being set up for a new analytics team. The security lead wants to follow least-privilege and separate administrative responsibilities. One administrator must create and manage users and roles, while a different administrator must create warehouses and manage compute resources. Neither administrator should automatically have unrestricted access to all data objects unless additional privileges are granted. Which pair of built-in system-defined roles best fits this requirement?

  1. A

    ACCOUNTADMIN and SYSADMIN

  2. B

    SECURITYADMIN and SYSADMIN

  3. C

    USERADMIN and SECURITYADMIN

  4. D

    PUBLIC and SYSADMIN

Show answer and explanation

Correct answer: B

Explanation

Snowflake provides several built-in system-defined roles with different administrative responsibilities. For role-based access control and least-privilege design, Snowflake best practice is to avoid using ACCOUNTADMIN for daily work and instead delegate responsibilities to more focused roles. SECURITYADMIN manages security-related tasks such as role grants and, through role hierarchy, includes USERADMIN capabilities for user and role management. SYSADMIN is the recommended role for creating and managing warehouses and other account objects needed for workloads. PUBLIC is not an administrative role; it is implicitly granted broadly and should be used carefully. This question tests understanding of how Snowflake separates duties across system-defined roles and how to apply that separation in a real deployment. Refer to Snowflake documentation on access control, system-defined roles, and the recommended administrative role hierarchy.

  • A. Incorrect.

    Incorrect. ACCOUNTADMIN is the highest-level administrative role in Snowflake and effectively combines capabilities from several administrative roles, including security and system administration. Using ACCOUNTADMIN for routine administration does not align with least-privilege best practices because it provides broader authority than necessary.

  • B. Correct.

    Correct. SECURITYADMIN is intended for managing roles and grants and can manage users through inherited capabilities from USERADMIN. SYSADMIN is intended for creating and managing warehouses and other objects such as databases and schemas, depending on granted ownership/privileges. This pairing cleanly separates security administration from system/object administration and avoids unnecessary use of ACCOUNTADMIN.

  • C. Incorrect.

    Incorrect. USERADMIN is focused on creating and managing users and roles, but it is not the best answer for the full requirement because the second role listed, SECURITYADMIN, is not intended to be the compute administrator. The scenario specifically needs one role for identity/role administration and another for warehouses/compute administration. SYSADMIN, not SECURITYADMIN, is the appropriate built-in role for managing warehouses.

  • D. Incorrect.

    Incorrect. PUBLIC is a role automatically granted to every user and role, but it is not an administrative role for managing users, roles, or warehouses. Pairing PUBLIC with SYSADMIN would not satisfy the requirement for delegated security administration.

Timed practice exam

Take a SnowPro Associate: Platform practice test under exam conditions

65 questions in 85 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam