ARA-C01 Accounts and Security Practice Question
Which object type should an architect use to manage granular access permissions to a specific schema within a database?
⚠ Common exam trap
Candidates often choose 'User' or 'Account' instead of 'Role'. They mistakenly think permissions are assigned directly to users, ignoring Snowflake's best practice of assigning all privileges to roles for easier maintenance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role
Role-Based Access Control (RBAC) in Snowflake relies on roles to manage privileges. By assigning specific privileges like USAGE or SELECT to a role, and then granting that role to users or other roles, the architect implements the principle of least privilege. This hierarchy allows for scalable management of security, ensuring that users only have the access they need to perform their jobs while maintaining auditability for compliance and security monitoring purposes across the entire organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User
Why it's wrong here
Users represent individuals or services that connect to Snowflake. They do not hold privileges directly; instead, they are granted roles that contain the necessary privileges. Managing permissions directly on a user object is not a scalable practice and violates the core design principles of Snowflake's role-based access model.
- ✓
Role
Why this is correct
Roles are the fundamental unit of access control in Snowflake. They act as containers for privileges, which can then be granted to users. By creating custom roles for specific schemas, an architect can effectively group permissions and grant them to the appropriate users in a manageable and auditable way.
- ✗
Warehouse
Why it's wrong here
Warehouses are compute resources used to execute queries and data manipulation. While roles are used to grant privileges on warehouses, the warehouse object itself is not a container for schema-level permissions. Granting warehouse access does not confer any access to the tables or schemas within the databases.
- ✗
Integration
Why it's wrong here
Integrations are specialized objects used for connecting Snowflake to external services, such as cloud storage, notification services, or identity providers. They are configured for cross-platform communication and do not serve as containers for granting database schema access or managing user permissions for internal data objects.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.