Courseiva
Accounts and Security →mediumMultiple Choice

ARA-C01 Accounts and Security Practice Question

Network Topology
+|

Refer to the exhibit. An administrator has executed a 'SHOW GRANTS TO ROLE ANALYST_ROLE' command. Based on the output, what is the significance of the 'grant_option' value for the 'SELECT' privilege on the 'SALES_DATA' table?

⚠ Common exam trap

Candidates frequently mistake 'grant_option' for general administrative rights, failing to realize it specifically authorizes the grantee to delegate that exact privilege to other roles in the system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ANALYST_ROLE can grant the SELECT privilege on the SALES_DATA table to other roles in the account.

The 'grant_option' in Snowflake access control determines if a grantee has the authority to pass privileges to other roles. Understanding this output is crucial for architects to audit security and ensure that the principle of least privilege is maintained, as the ability to further delegate access can lead to unauthorized permission expansion if not strictly controlled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ANALYST_ROLE can grant the SELECT privilege on the SALES_DATA table to other roles in the account.

    Why this is correct

    When the 'grant_option' is set to 'true', it indicates that the privilege was granted using the 'WITH GRANT OPTION' clause. This allows any user active in the `ANALYST_ROLE` to grant that same SELECT privilege to other roles, effectively delegating administrative control over that specific object's access.

  • ✗

    The ANALYST_ROLE is a managed access role and cannot modify any privileges on the SALES_DATA table.

    Why it's wrong here

    Managed access is a property of a schema, not a role. Even in a managed access schema, the 'grant_option' column in this output specifically refers to the delegation of the SELECT privilege itself, not the broader management settings of the schema or the role's inability to modify privileges.

  • ✗

    The SELECT privilege is automatically granted to any role that is a child of the ANALYST_ROLE.

    Why it's wrong here

    Privileges flow upwards in the role hierarchy (child roles pass privileges to parent roles), not downwards. The 'grant_option' does not affect how privileges are inherited by other roles; it only dictates whether the current role has the right to manually grant that privilege to another distinct role.

  • ✗

    The ANALYST_ROLE can only grant the SELECT privilege if they also have the OWNERSHIP privilege on the table.

    Why it's wrong here

    Normally, only the owner of an object can grant privileges. However, the 'WITH GRANT OPTION' allows a non-owner to grant specific privileges to others. In this case, the `ANALYST_ROLE` does not need ownership because the 'grant_option' explicitly provides the necessary authority for that specific SELECT privilege.

About these practice questions

Courseiva writes every ARA-C01 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.