Courseiva

COF-C03 Account Management and Data Governance Practice Question

A compliance officer needs to confirm which roles have been granted to a specific user across the account, including grants made through role hierarchies. Which Snowflake command should be used to retrieve this information?

⚠ Common exam trap

The trap here is mixing up TO and ON in the SHOW GRANTS syntax, where TO is for roles granted to a user and ON is for privileges on an object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SHOW GRANTS TO USER <username>

SHOW GRANTS TO USER returns the roles granted to a named user, including those inherited through role hierarchies, which is exactly what a compliance audit needs. SHOW GRANTS ON targets object privileges, SHOW ROLES lists role definitions, and SHOW USERS lists user accounts. Only SHOW GRANTS TO USER maps a user to their effective roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SHOW GRANTS TO USER <username>

    Why this is correct

    SHOW GRANTS TO USER lists all roles granted directly to the user and, importantly, also reflects roles inherited through the role hierarchy. This gives the compliance officer a complete view of effective role assignments. It is the standard command for auditing user-role relationships and directly answers the requirement without needing to inspect each role individually.

  • ✗

    SHOW GRANTS ON USER <username>

    Why it's wrong here

    SHOW GRANTS ON is used to list privileges granted on a specific object, such as a table or warehouse, not roles granted to a user. Using ON with a user is not the correct syntax for retrieving role assignments and would not return the hierarchical role information required. It addresses object privileges rather than user-role mappings.

  • ✗

    SHOW USERS

    Why it's wrong here

    SHOW USERS returns a list of users with attributes such as login name, display name, and default role, but it does not enumerate the roles granted to each user. The default role is only one of potentially many. It cannot answer which roles a user has across the hierarchy, so it is insufficient for this audit.

  • ✗

    SHOW ROLES

    Why it's wrong here

    SHOW ROLES lists all roles that exist in the account along with their comments and owners, but it does not indicate which roles are granted to a particular user. It provides an inventory of roles, not assignments. The compliance officer would still need to run additional queries to determine which of those roles the user actually holds.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.