COF-C03 Account Management and Data Governance Practice Question
An administrator discovers that a former employee's user account still exists and is still granted the ANALYST_ROLE. The administrator needs to immediately prevent the account from authenticating while preserving the account and its historical query metadata for an ongoing audit. Which action should the administrator take?
⚠ Common exam trap
The trap here is equating credential removal with account disablement, when Snowflake provides a dedicated DISABLED property that blocks all authentication methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run ALTER USER ... SET DISABLED = TRUE.
Disabling a user with ALTER USER ... SET DISABLED = TRUE immediately blocks authentication while keeping the account, its grants, and its metadata available for audit. Dropping the user or altering credentials does not preserve the account in the desired state, and revoking a role only removes one privilege path rather than blocking sign-in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run ALTER USER ... SET DISABLED = TRUE.
Why this is correct
Setting DISABLED = TRUE on a user prevents that user from authenticating to Snowflake while leaving the account, its grants, and its metadata intact. This is the documented way to suspend access immediately during an investigation or offboarding without losing audit history, and it can be reversed later if needed by setting DISABLED = FALSE.
- ✗
Run DROP USER on the former employee's account.
Why it's wrong here
Dropping the user removes the account entirely and can affect ownership of objects the user created, and it eliminates the ability to inspect the account later. While it does prevent authentication, it does not preserve the account for the audit, so it does not meet the requirement of retaining the account and its historical metadata.
- ✗
Run ALTER USER ... SET PASSWORD = NULL.
Why it's wrong here
Clearing the password does not fully disable the account, because the user may still authenticate through federated authentication, key-pair authentication, or an existing OAuth token. It also does not preserve a clean audit trail of an intentional disablement, and it can be reversed by anyone with the ability to reset the password, so it is not a reliable or complete control.
- ✗
Run REVOKE ROLE ANALYST_ROLE FROM USER on the former employee's account.
Why it's wrong here
Revoking the role removes one path to data but does not stop the user from logging in, and the user may hold other roles that grant access. It also changes the grant history that the audit may rely on. Because the requirement is to prevent authentication entirely while preserving the account, revoking a single role is insufficient.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.