COF-C03 Data Collaboration Practice Question
A consumer has created a database from a share. They want to grant their 'ANALYST' role the ability to query the tables within this shared database. Which privilege should they grant to the role?
⚠ Common exam trap
Candidates frequently try granting standard USAGE or SELECT privileges directly on shared databases, failing to remember that shared databases require the special IMPORTED PRIVILEGES grant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GRANT IMPORTED PRIVILEGES ON DATABASE <shared_db> TO ROLE ANALYST;
When a consumer mounts a share, the resulting database is special. To allow other roles in their account to use it, they use the 'IMPORTED PRIVILEGES' grant. This is a bulk grant that conveys the necessary permissions (like USAGE and SELECT) on all objects within the shared database to a local role, simplifying the permission management for the consumer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GRANT SELECT ON ALL TABLES IN DATABASE <shared_db> TO ROLE ANALYST;
Why it's wrong here
While this looks like standard SQL, Snowflake requires a specific syntax for shared databases. You cannot grant individual privileges like SELECT on objects inside a shared database directly. Instead, you must use the IMPORTED PRIVILEGES mechanism which acts as a container for all the rights the provider has authorized via the share.
- ✗
GRANT USAGE ON DATABASE <shared_db> TO ROLE ANALYST;
Why it's wrong here
Granting USAGE on the database alone is insufficient for the ANALYST role to query the underlying tables. In a shared database context, USAGE only allows the role to see the database exists. To actually interact with the data, the role needs the permissions bundled within the IMPORTED PRIVILEGES grant.
- ✓
GRANT IMPORTED PRIVILEGES ON DATABASE <shared_db> TO ROLE ANALYST;
Why this is correct
The IMPORTED PRIVILEGES grant is the correct and mandatory way for a consumer to authorize a local role to access a shared database. It effectively passes through all the privileges defined by the provider in the share to the specified local role, ensuring that the analyst can query the tables and views as intended.
- ✗
GRANT OWNERSHIP ON DATABASE <shared_db> TO ROLE ANALYST;
Why it's wrong here
Ownership cannot be granted to a role for a shared database in the same way it is for a local database. The consumer role that created the database from the share is the technical owner, but their powers are limited by the share's read-only nature. Granting ownership would not provide the correct query access for an analyst.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.