Courseiva
Application Rules, ACL and NotificationshardMultiple ChoiceObjective-mapped

SNOW-CSA Application Rules, ACL and Notifications Practice Question

A system administrator notices that users in the 'itil' role can see the 'cost' field on the 'cmdb_ci_server' table, but the requirement is to hide it from all except users with the 'cmdb_admin' role. The administrator has already created an ACL with 'read' operation, type 'record', condition 'current.cost' (no script) and granted 'no access' to all roles. However, the field is still visible. What is missing?

⚠ Common exam trap

Test-takers frequently confuse 'record' ACLs with 'field' ACLs, assuming a record ACL with a condition on a field will hide that field, when in reality only a field ACL can control individual field visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The ACL type must be 'field' instead of 'record'

A 'record' ACL controls access to the entire record, but the requirement is to hide a specific field ('cost') from certain roles. To control visibility at the field level, the ACL type must be 'field', not 'record'. A 'record' ACL determines whether a user can see or interact with the whole record, while a 'field' ACL governs access to individual fields. Since the 'cost' field is still visible, the existing 'record' ACL is not applied to the field itself, allowing the 'itil' role to see it via default field-level access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The ACL condition should use a script instead of a condition

    Why it's wrong here

    Condition builder works fine with 'no access'.

  • The ACL must be set to 'mandatory'

    Why it's wrong here

    Mandatory is a field property, not an ACL setting.

  • The user must be removed from the 'itil' role

    Why it's wrong here

    That would be a workaround but not the proper ACL configuration.

  • The ACL type must be 'field' instead of 'record'

    Why this is correct

    Field ACLs control read/write access to individual fields.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 504 original SNOW-CSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SNOW-CSA practice question is part of Courseiva's free ServiceNow certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SNOW-CSA exam.