ARA-C01 Accounts and Security Practice Question
A security architect is configuring access control for a Snowflake environment. They need to ensure that a service account used by an ETL tool can only access specific tables in a schema and cannot create or drop any objects. The ETL tool connects using key-pair authentication. Which set of privileges should be granted to the service account's role to adhere to the principle of least privilege?
⚠ Common exam trap
The trap here is assuming that ALL PRIVILEGES on tables or SELECT on all tables in the schema is acceptable, when it grants more access than needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant USAGE on the database and schema, and SELECT on the specific tables.
The principle of least privilege requires granting only the privileges necessary to perform the required tasks. The ETL tool needs to read specific tables, so USAGE on the database and schema plus SELECT on those tables is sufficient. This avoids unnecessary privileges like object creation or data modification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant USAGE on the database and schema, and CREATE TABLE on the schema.
Why it's wrong here
Granting CREATE TABLE allows the role to create new tables, which is explicitly not allowed per the requirement. This also does not grant SELECT on existing tables, so the ETL tool would not be able to read data, failing the primary requirement.
- ✗
Grant USAGE on the database and schema, and SELECT on all tables in the schema.
Why it's wrong here
Granting SELECT on all tables in the schema is broader than necessary; the requirement is to access only specific tables. This violates least privilege by allowing access to tables that the ETL tool should not see, potentially exposing sensitive data.
- ✗
Grant USAGE on the database and schema, and ALL PRIVILEGES on the specific tables.
Why it's wrong here
ALL PRIVILEGES on tables includes SELECT, INSERT, UPDATE, DELETE, TRUNCATE, and REFERENCES. This grants more than the required read-only access and violates least privilege because the ETL tool could modify or delete data, which is not needed.
- ✓
Grant USAGE on the database and schema, and SELECT on the specific tables.
Why this is correct
Granting USAGE on the database and schema allows the role to see and use these objects, while SELECT on the specific tables provides read access only. This follows least privilege because it does not allow any object creation or modification, and restricts access to only the required tables.
About these practice questions
One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.