ARA-C01 Accounts and Security Practice Question
A Snowflake architect is designing a multi-tenant environment where each tenant has its own database. The architect wants to ensure that tenant administrators can manage roles and users within their own database but cannot affect other tenants. Which Snowflake feature should be used to achieve this isolation?
⚠ Common exam trap
Test-takers frequently confuse account-level roles with database-scoped roles; account roles grant privileges across the account, not just within a single database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Database roles
Database roles are scoped to a specific database and allow for granular privilege management within that database. By granting a tenant administrator a database role with the ability to create and manage other database roles, you enable them to manage access within their database without affecting other databases. Account roles are too broad and would not provide the needed isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network policies
Why it's wrong here
Network policies control access based on IP addresses and do not provide role-based isolation within Snowflake. They are used to restrict network access, not to manage permissions within databases. They cannot prevent a user from affecting other tenants if they have the appropriate roles.
- ✗
Resource monitors
Why it's wrong here
Resource monitors are used to control credit consumption and do not provide access control or isolation. They can limit compute resources but do not restrict what objects a user can manage. They are unrelated to the requirement of tenant isolation for role management.
- ✗
Account roles
Why it's wrong here
Account roles are global and can be granted privileges on any object in the account. If a tenant administrator is given an account role with manage grants, they could potentially affect other tenants' databases. Account roles do not provide the necessary isolation for a multi-tenant environment.
- ✓
Database roles
Why this is correct
Database roles allow you to define roles within a specific database, enabling granular access control. A tenant administrator can be granted a database role with privileges to manage objects within that database, without having account-level privileges. This provides isolation because database roles are scoped to the database and cannot affect other databases or account-level objects.
About these practice questions
One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.