COF-C03 Account Management and Data Governance Practice Question
A Snowflake administrator needs to grant a new analyst the ability to view all tables in the 'SALES' database and query them, but should not be able to modify any data or schema objects. Which sequence of privileges should the administrator grant to meet this requirement with least privilege?
⚠ Common exam trap
The trap here is forgetting that schema-level USAGE is required in addition to database USAGE for a user to access tables within schemas.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant USAGE on the SALES database, USAGE on all schemas in the database, and SELECT on all present and future tables in the database.
To provide read-only access to all tables in a database, the administrator must grant USAGE on the database, USAGE on the schemas, and SELECT on the tables. Including future tables ensures that new tables are automatically accessible. This set of privileges allows querying without any modification rights, aligning with least privilege. Omitting schema USAGE or granting excessive roles would fail the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant the ACCOUNTADMIN role to the analyst, as it includes all necessary privileges for viewing and querying tables.
Why it's wrong here
Granting ACCOUNTADMIN provides far more privileges than needed, violating least privilege. The analyst could modify data, manage users, and change account settings. This is excessive and risky. The requirement is only to view and query tables, so a targeted set of privileges is appropriate, not a powerful administrative role.
- ✗
Grant the predefined role PUBLIC to the analyst, as PUBLIC has SELECT on all tables by default.
Why it's wrong here
The PUBLIC role does not have SELECT on all tables by default. In Snowflake, privileges are not automatically granted to PUBLIC; administrators must explicitly grant them. Assuming PUBLIC has such access is incorrect and could lead to unintended access. This option does not meet the requirement and violates least privilege if privileges were broadly granted.
- ✗
Grant USAGE on the SALES database and SELECT on all tables in the database, but no privileges on schemas.
Why it's wrong here
Without USAGE on the schemas, the analyst cannot access objects within them. USAGE on the database alone is insufficient; the user must also have USAGE on each schema containing the tables. This option would result in errors when querying tables. It fails the requirement because it omits necessary schema-level privileges.
- ✓
Grant USAGE on the SALES database, USAGE on all schemas in the database, and SELECT on all present and future tables in the database.
Why this is correct
This grants the minimum privileges needed: USAGE on the database and schemas allows navigation, and SELECT on tables allows querying. Using GRANT SELECT ON ALL TABLES and ON FUTURE TABLES ensures coverage of existing and new tables. No modification privileges are granted, adhering to least privilege. This is the standard approach for read-only access.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.