Courseiva

COF-C03 Account Management and Data Governance Practice Question

A user is assigned the 'SECURITYADMIN' role. Which of the following tasks can this user perform?

⚠ Common exam trap

Candidates often assume SECURITYADMIN can also manage data warehouses or databases, failing to observe the principle of Segregation of Duties where SYSADMIN manages data and SECURITYADMIN manages access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant and revoke privileges to other roles.

The SECURITYADMIN role is specifically designed for managing security objects such as roles, grants, and users. This role has the power to grant and revoke privileges to other roles. Keeping this role separate from SYSADMIN (which manages warehouses and databases) is a key governance practice known as Segregation of Duties, ensuring that no single person has unchecked control over both security and data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create and manage warehouses.

    Why it's wrong here

    Creating and managing warehouses is the responsibility of the SYSADMIN role. The SECURITYADMIN role focuses solely on security-related tasks like managing roles and permissions. Combining these roles would violate the principle of Segregation of Duties, which is essential for auditability and risk management in governance.

  • ✗

    Modify account-level billing settings.

    Why it's wrong here

    Managing billing and usage for the entire account is restricted to the ACCOUNTADMIN role. The SECURITYADMIN role does not have the permissions required to view or modify financial data or system-level configuration parameters, as those tasks are reserved for the highest level of administrative control.

  • ✓

    Grant and revoke privileges to other roles.

    Why this is correct

    The SECURITYADMIN role has the ability to manage grants, create roles, and manage users. This role is central to implementing RBAC within the account. Because it controls access to data and other objects, it must be carefully audited to prevent unauthorized privilege escalation and misuse of permissions.

  • ✗

    Drop databases without restriction.

    Why it's wrong here

    The SYSADMIN role is the owner of databases and has the right to manage them, including dropping them. The SECURITYADMIN role lacks the privileges to interact with databases or their contents. This separation ensures that security administrators cannot inadvertently destroy data while performing their security-related duties.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.