Courseiva

COF-C03 Account Management and Data Governance Practice Question

A Snowflake account has a custom role named DATA_ENGINEER. The administrator wants to ensure that DATA_ENGINEER can create databases and warehouses but cannot manage users or roles. Which predefined role should DATA_ENGINEER be granted to achieve this?

⚠ Common exam trap

The trap here is assuming that ACCOUNTADMIN is needed for object creation, overlooking that SYSADMIN provides the necessary privileges without user management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYSADMIN

SYSADMIN is the predefined role that provides privileges to create and manage warehouses, databases, and other objects. It does not include user or role management, which is handled by SECURITYADMIN and USERADMIN. By granting SYSADMIN to DATA_ENGINEER, the administrator ensures the role can perform its intended tasks without over-privileging it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SYSADMIN

    Why this is correct

    SYSADMIN is the predefined role responsible for creating and managing warehouses, databases, and other objects. Granting SYSADMIN to DATA_ENGINEER provides the necessary privileges to create databases and warehouses. It does not include the ability to manage users or roles, which aligns with the requirement to restrict those actions.

  • ✗

    ACCOUNTADMIN

    Why it's wrong here

    ACCOUNTADMIN has all privileges, including user and role management. Granting it to DATA_ENGINEER would violate the requirement to prevent management of users and roles. It also grants unnecessary privileges like billing management. Therefore, it is not the appropriate choice for this scenario.

  • ✗

    USERADMIN

    Why it's wrong here

    USERADMIN is limited to creating and managing users and roles. It does not have the privilege to create databases or warehouses. Granting USERADMIN would not provide the required capabilities and would also grant user/role management, which is explicitly not desired. Thus, it fails both parts of the requirement.

  • ✗

    SECURITYADMIN

    Why it's wrong here

    SECURITYADMIN is focused on user and role management, not on creating databases or warehouses. Granting SECURITYADMIN to DATA_ENGINEER would give it the ability to manage users and roles, which contradicts the requirement to prevent that. Additionally, SECURITYADMIN does not inherently provide the privilege to create databases or warehouses; those are typically under SYSADMIN.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.