Courseiva

COF-C03 Account Management and Data Governance Practice Question

A data administrator needs to identify which users have failed to log in successfully over the last 30 days due to authentication errors. Which Snowflake object should they query?

⚠ Common exam trap

Candidates often confuse ACCOUNT_USAGE views with INFORMATION_SCHEMA views, failing to realize INFORMATION_SCHEMA has limited retention periods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The LOGIN_HISTORY view.

The LOGIN_HISTORY table function in the ACCOUNT_USAGE schema provides a detailed audit trail of all connection attempts to the account. By filtering for the IS_SUCCESS column set to 'NO' and specifying the timeframe, the administrator can effectively monitor for potential brute-force attempts or configuration errors. This is a critical component for maintaining a robust security posture and ensuring compliance with organizational access monitoring policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACCESS_HISTORY view.

    Why it's wrong here

    ACCESS_HISTORY tracks queries executed on tables, views, and columns rather than authentication attempts. While useful for auditing data access, it does not record user login success or failure statuses. It is designed to track how data moves through the system, not how users enter the system.

  • ✓

    The LOGIN_HISTORY view.

    Why this is correct

    LOGIN_HISTORY records all login attempts, including timestamps, usernames, client IP addresses, and the success status of the request. It is the definitive source for auditing authentication failures. Accessing this view requires the ACCOUNTADMIN role or a role with specific privileges granted to view account-level metadata.

  • ✗

    The QUERY_HISTORY view.

    Why it's wrong here

    QUERY_HISTORY only logs successfully submitted queries and their associated execution metadata. Since a failed login prevents a user session from starting, no queries can be executed. Therefore, this view lacks the necessary information to track authentication failures happening at the account connection level.

  • ✗

    The SESSIONS view.

    Why it's wrong here

    The SESSIONS view contains information about active or recently completed user sessions. It does not record failed login attempts because a session is only created after a successful authentication. Therefore, if a user fails to authenticate, they never generate an entry in the SESSIONS view.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.