SnowPro Associate: Platform exam dumps

SnowPro Associate: Platform practice question 298 of 367

SnowPro® Associate: Platform Certification. Associate level, Snowflake. Free question with the correct answer and a full explanation.

SnowPro Associate: Platform Question 298

Single answer○ Enable

A Snowflake administrator is asked to enable a newly created custom role so that data analysts can query curated tables in the ANALYTICS database without granting unnecessary administrative privileges. The analysts already have user accounts but currently can only use the PUBLIC role. Which action should the administrator take FIRST to make the new role available for use by those analysts?

  1. A

    Grant the custom role to the analysts' user accounts or to another role already assigned to them

  2. B

    Transfer ownership of the ANALYTICS database to the custom role

  3. C

    Assign the custom role as the default warehouse for the analysts

  4. D

    Grant the custom role to the SYSADMIN role so the analysts inherit it automatically

Show answer and explanation

Correct answer: A

Explanation

To enable access in Snowflake using role-based access control, an administrator must both grant the necessary object privileges to a role and grant that role into the role hierarchy used by the intended users. Simply creating a role or granting privileges to it is not sufficient. In a least-privilege design, analysts should receive the custom role directly or through an appropriate functional parent role, rather than through powerful administrative roles like SYSADMIN. Snowflake documentation on access control and role hierarchy emphasizes that privileges are activated through roles granted to users or other roles, and that ownership should be limited because it conveys full control over objects.

  • A. Correct.

    Correct. In Snowflake, creating a role and granting object privileges to it does not make it usable by end users until the role is granted to a user or to another role in that user's active role hierarchy. This is the first step required to enable the analysts to activate and use the role.

  • B. Incorrect.

    Incorrect. Ownership transfer is not required to let analysts query tables. Ownership is a powerful privilege used for managing objects, not for basic access enablement. Granting ownership would also violate least-privilege principles in this scenario.

  • C. Incorrect.

    Incorrect. Warehouses and roles are separate concepts in Snowflake. A role cannot be assigned as a default warehouse. Users can have default roles and default warehouses, but those are different properties and one does not replace the other.

  • D. Incorrect.

    Incorrect. Granting the custom role to SYSADMIN does not make it available to analysts unless their assigned roles inherit from SYSADMIN, which would be inappropriate for analysts and would introduce excessive privileges. Role inheritance must be aligned with the users' granted roles.

Timed practice exam

Take a SnowPro Associate: Platform practice test under exam conditions

65 questions in 85 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam