ARA-C01 Accounts and Security Practice Question
Network Topology
Refer to the exhibit. An administrator has executed a 'SHOW GRANTS TO ROLE ANALYST_ROLE' command. Based on the output, what is the significance of the 'grant_option' value for the 'SELECT' privilege on the 'SALES_DATA' table?
⚠ Common exam trap
Candidates frequently mistake 'grant_option' for general administrative rights, failing to realize it specifically authorizes the grantee to delegate that exact privilege to other roles in the system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ANALYST_ROLE can grant the SELECT privilege on the SALES_DATA table to other roles in the account.
The 'grant_option' in Snowflake access control determines if a grantee has the authority to pass privileges to other roles. Understanding this output is crucial for architects to audit security and ensure that the principle of least privilege is maintained, as the ability to further delegate access can lead to unauthorized permission expansion if not strictly controlled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ANALYST_ROLE can grant the SELECT privilege on the SALES_DATA table to other roles in the account.
Why this is correct
When the 'grant_option' is set to 'true', it indicates that the privilege was granted using the 'WITH GRANT OPTION' clause. This allows any user active in the `ANALYST_ROLE` to grant that same SELECT privilege to other roles, effectively delegating administrative control over that specific object's access.
- ✗
The ANALYST_ROLE is a managed access role and cannot modify any privileges on the SALES_DATA table.
Why it's wrong here
Managed access is a property of a schema, not a role. Even in a managed access schema, the 'grant_option' column in this output specifically refers to the delegation of the SELECT privilege itself, not the broader management settings of the schema or the role's inability to modify privileges.
- ✗
The SELECT privilege is automatically granted to any role that is a child of the ANALYST_ROLE.
Why it's wrong here
Privileges flow upwards in the role hierarchy (child roles pass privileges to parent roles), not downwards. The 'grant_option' does not affect how privileges are inherited by other roles; it only dictates whether the current role has the right to manually grant that privilege to another distinct role.
- ✗
The ANALYST_ROLE can only grant the SELECT privilege if they also have the OWNERSHIP privilege on the table.
Why it's wrong here
Normally, only the owner of an object can grant privileges. However, the 'WITH GRANT OPTION' allows a non-owner to grant specific privileges to others. In this case, the `ANALYST_ROLE` does not need ownership because the 'grant_option' explicitly provides the necessary authority for that specific SELECT privilege.
About these practice questions
Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.