SnowPro Associate: Platform exam dumps

SnowPro Associate: Platform practice question 296 of 367

SnowPro® Associate: Platform Certification. Associate level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Associate: Platform Question 296

Single answer○ Enable

A Snowflake administrator wants to allow analysts to use Snowsight so they can run worksheets, view query history, and manage their own SQL development without using the Classic Console. Several analysts report that they can authenticate successfully, but they cannot access Snowsight features after login. The administrator wants to enable the required access using the minimum appropriate privilege model. Which action should the administrator take?

  1. A

    Grant the global SNOWFLAKE.USER privilege to the analysts' role

  2. B

    Grant the SYSADMIN role to all analysts so they can open Snowsight

  3. C

    Grant USAGE on at least one warehouse and one database to the analysts' role

  4. D

    Enable Tri-Secret Secure so Snowsight becomes available for the analysts

Show answer and explanation

Correct answer: A

Explanation

This scenario focuses on enabling access to Snowsight, Snowflake's web interface for SQL development, monitoring, and object management. The key requirement is the global SNOWFLAKE.USER privilege, which is used to allow users to access Snowsight functionality. While analysts also need the appropriate role-based privileges on warehouses, databases, schemas, and other objects to perform work once inside Snowsight, those object privileges do not replace the need for SNOWFLAKE.USER. Best practice is to grant only the privileges required for the user's job rather than broad administrative roles such as SYSADMIN. This aligns with Snowflake's role-based access control and least-privilege guidance in Snowflake documentation for Snowsight access and global privileges.

  • A. Correct.

    Correct. To use Snowsight, a user must have the SNOWFLAKE.USER global privilege. This privilege enables access to Snowsight-specific features and user experience capabilities. Without it, a user may be able to authenticate to Snowflake but still be unable to use Snowsight as intended. This is the least-privilege action specifically tied to enabling Snowsight access.

  • B. Incorrect.

    Incorrect. SYSADMIN is a powerful administrative role and is far beyond what is needed just to allow analysts to use Snowsight. Granting SYSADMIN violates least-privilege principles and is not required to enable the interface. Analysts typically need only their business role plus the specific privilege that allows Snowsight access.

  • C. Incorrect.

    Incorrect. Warehouse and database privileges are needed to run queries against data, but they do not by themselves enable Snowsight access. A user can still lack access to Snowsight even if they have USAGE on compute and data objects. This option reflects the common misconception that object privileges alone control access to all user interfaces.

  • D. Incorrect.

    Incorrect. Tri-Secret Secure is a security feature related to encryption key management and has nothing to do with enabling Snowsight access. It does not control whether users can open or use Snowsight.

Timed practice exam

Take a SnowPro Associate: Platform practice test under exam conditions

65 questions in 85 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam