Courseiva

CCNA Data Collaboration Questions

48 questions · Data Collaboration · All types, answers revealed

1
MCQeasy

Which object acts as the primary container for sharing data with external Snowflake accounts?

A.Data Warehouse
B.Database
C.Share
D.Integration
AnswerC

A Share is the specific Snowflake object designed to grant access to database objects for other accounts. It encapsulates the list of privileges and the specific tables or views being shared, ensuring that the provider maintains centralized control while the consumer can query the data securely.

Why this answer

A Share is the fundamental object in Snowflake that allows a provider to grant access to specific database objects without transferring the data itself. By using Shares, organizations can securely collaborate by allowing consumers to query the provider's data as if it were local to their own account. This architecture is vital for data governance, as it prevents data duplication and ensures consistent security policies across all shared data assets within the ecosystem.

Exam trap

Test-takers often confuse the container 'Share' with the resulting 'Database' created on the consumer side or other auxiliary metadata objects.

2
MCQmedium

A provider wants to share data with a consumer using a reader account because the consumer does not have a Snowflake account. Which statement describes the correct capability of a reader account in this scenario?

A.A reader account is created by the consumer and billed to the consumer, with full privileges to create databases and shares.
B.A reader account can be converted into a standard Snowflake account at any time by the consumer with no provider involvement.
C.A reader account can create its own shares and publish listings to the Snowflake Marketplace for other accounts.
D.A reader account is created and fully managed by the provider, can query shared data, and cannot load or modify data or create its own objects beyond limited query usage.
AnswerD

Reader accounts are provider-owned, provider-billed accounts intended for consumers without Snowflake accounts. The consumer accesses a web interface with limited privileges to query shared data. Readers cannot load data, create shares, or perform most write operations, and the provider pays for the compute they consume.

Why this answer

Reader accounts exist specifically for consumers without a Snowflake account. The provider creates, owns, and pays for them, and the consumer uses a limited interface to query only the shared data. They cannot load data, create shares, or be upgraded into normal accounts.

Exam trap

The trap here is assuming a reader account is a normal consumer-owned Snowflake account, when it is a provider-owned, query-only account billed to the provider.

3
MCQmedium

A provider wants to share data with a consumer but must ensure that the consumer cannot see the underlying base tables, only an aggregated subset. The provider decides to use a secure view. Which statement is true regarding the use of secure views in a share?

A.Secure views cannot be shared; only regular views can be included in a share.
B.Sharing a secure view requires granting the consumer SELECT on the base tables as well.
C.Secure views automatically encrypt the data, so consumers cannot read it without a decryption key.
D.Secure views can be shared, and the consumer can query them without having direct access to the base tables.
AnswerD

Secure views are designed for data sharing because they hide the view definition and the underlying data. When a secure view is granted to a share, the consumer can query the view and receive results based on the view's logic, but they cannot access the base tables directly. This allows providers to share a controlled subset of data while protecting sensitive details.

Why this answer

Secure views are ideal for sharing because they allow consumers to query a defined subset of data without exposing the underlying tables or the view definition. The consumer only needs SELECT on the secure view. This ensures that sensitive base data remains protected while enabling controlled data sharing.

Exam trap

The trap here is assuming that sharing a secure view requires granting access to base tables, when in fact secure views are designed to avoid that.

4
MCQmedium

Which feature should a provider use if they need to allow a consumer to access data based on the consumer's specific identity or organizational attributes?

A.Standard Views
B.Row Access Policies
C.Data Masking Policies
D.Account-level Replication
AnswerB

Row Access Policies provide a centralized mechanism to restrict rows returned by a query based on the current user or role. This is the industry-standard way to manage multi-tenant data access, enabling providers to apply granular security logic that is enforced automatically when the share is queried.

Why this answer

Row-level security, implemented via Row Access Policies, is the correct tool for filtering data dynamically based on user context. In a sharing context, the policy evaluates the current user's attributes at query time. This allows a single shared table to serve different consumers with customized views of the data, ensuring that each consumer only sees the records they are authorized to access without creating separate tables for every partner.

Exam trap

Candidates often choose separate static tables or standard views, missing the dynamic identity evaluation capabilities required for customized consumer access.

5
MCQeasy

A consumer has created a database from a share provided by a partner. The consumer wants to query the shared data but receives an error indicating insufficient privileges. Which role must the consumer's user be granted to access the shared database?

A.The PUBLIC role
B.A role with the IMPORTED PRIVILEGES privilege on the shared database
C.The ACCOUNTADMIN role
D.The SYSADMIN role
AnswerB

In the consumer account, access to a shared database is controlled by the IMPORTED PRIVILEGES privilege. The consumer must grant this privilege on the shared database to a role, and then grant that role to the user. This allows the user to query the shared objects. Without this privilege, the user cannot access the shared data even if the database exists.

Why this answer

To access a shared database, the consumer must grant the IMPORTED PRIVILEGES privilege on that database to a role and then grant that role to the user. This privilege is specific to shared databases and is required for any role that needs to query the shared objects. Other roles like ACCOUNTADMIN or SYSADMIN do not have this privilege by default.

Exam trap

The trap here is assuming that system-defined roles like ACCOUNTADMIN or SYSADMIN automatically have access to shared databases, when in fact the IMPORTED PRIVILEGES privilege must be explicitly granted.

6
MCQmedium

A provider wants to share data with a consumer and ensure that the consumer can only read the data but cannot create any objects in the shared database. The provider has already created a share and granted USAGE on the database and schema, and SELECT on the table. What additional step, if any, is required to enforce read-only access?

A.The provider must grant the CREATE privilege on the schema to the share to allow the consumer to create objects.
B.No additional step is required; the consumer automatically has read-only access to shared databases.
C.The provider must set the share to read-only mode using the ALTER SHARE command.
D.The provider must revoke the USAGE privilege on the database from the share to prevent object creation.
AnswerB

When a consumer creates a database from a share, they receive a read-only version of the shared objects. The consumer cannot create, modify, or drop objects in the shared database. The privileges granted by the provider are limited to USAGE and SELECT, which are read-only. Therefore, no additional step is needed to enforce read-only access; it is inherent to shared databases.

Why this answer

Shared databases in Snowflake are read-only for consumers. The provider grants USAGE on the database and schema, and SELECT on objects, which are read-only privileges. Consumers cannot create or modify objects in a shared database.

No additional configuration is needed to enforce read-only access because it is the default and only behavior for shares.

Exam trap

The trap here is believing that additional privileges or commands are needed to make a share read-only, but shares are always read-only for consumers, and the provider cannot grant write privileges on shared objects.

7
MCQeasy

A consumer account has mounted a shared database from a provider. The consumer's role CONSUMER_ROLE has been granted USAGE on the shared database and its schemas. However, when the consumer tries to query a table in the shared database, they receive an error that the table does not exist. What is the most likely cause?

A.The provider has not granted SELECT on the table to the share.
B.The consumer's role lacks the USAGE privilege on the table.
C.The consumer needs to grant SELECT on the table to CONSUMER_ROLE.
D.The shared database has not been refreshed after the provider added the table.
AnswerA

For a consumer to query a table in a shared database, the provider must grant SELECT on that table to the share. The consumer's USAGE grant on the database and schema is necessary but not sufficient. Without the provider's SELECT grant, the table will not be visible or queryable, resulting in a 'table does not exist' error. This is the most likely cause.

Why this answer

The most likely cause is that the provider has not granted SELECT on the table to the share. Consumers cannot grant privileges on shared objects; they rely on the provider's grants. Without SELECT granted to the share, the table is not accessible, leading to a 'table does not exist' error.

The consumer's USAGE grants on the database and schema are necessary but not sufficient.

Exam trap

The trap here is assuming that consumer-side USAGE grants are enough to query shared tables, when in fact the provider must grant SELECT on each table to the share.

8
MCQhard

Which TWO statements are true regarding the costs associated with Data Sharing in Snowflake?

A.The data provider is responsible for all compute costs incurred by the consumer.
B.The data provider pays for the storage costs of the shared data.
C.The consumer pays for the storage costs of the shared data.
D.The data consumer is responsible for the compute costs of their queries.
E.Both the provider and consumer share the total compute costs equally.
AnswerB, D

Since the shared data physically resides in the provider's Snowflake storage, the provider is responsible for the storage costs. This is a core component of the Snowflake shared-data architecture, where data is never moved or copied to the consumer's account, thus saving storage costs for the consumer.

Why this answer

Understanding the cost model is crucial for data providers. In Snowflake, the data provider pays for the storage of the shared data, as it resides in their account. However, the consumer is responsible for the compute costs incurred when running queries against that shared data.

This separation of costs ensures that data providers can scale their offerings based on data volume, while consumers maintain control over their own compute spend and workload optimization efforts.

Exam trap

Candidates often incorrectly assume that data consumers also pay for the storage of the shared data, or that providers pay for consumer query compute costs.

9
MCQmedium

A data provider at ACME Corp has created a share named REGIONAL_SALES_SHARE and added a secure view on the SALES table. The provider now wants to grant a specific consumer account, named CONSUMER_ACCT, access to this share. Which command should the provider use to accomplish this?

A.GRANT IMPORTED PRIVILEGES ON DATABASE REGIONAL_SALES_SHARE TO ACCOUNT CONSUMER_ACCT;
B.GRANT USAGE ON SHARE REGIONAL_SALES_SHARE TO ACCOUNT CONSUMER_ACCT;
C.ALTER SHARE REGIONAL_SALES_SHARE ADD ACCOUNT = CONSUMER_ACCT;
D.CREATE SHARE REGIONAL_SALES_SHARE GRANT TO ACCOUNT CONSUMER_ACCT;
AnswerC

The ALTER SHARE command with the ADD ACCOUNT clause is the correct way to grant a consumer account access to a share. This command adds the specified account to the share's list of authorized accounts, allowing the consumer to create a database from the share. It is the standard method for sharing data with specific accounts.

Why this answer

To share data with a specific consumer account, the provider must add that account to the share using ALTER SHARE ... ADD ACCOUNT. This grants the consumer account the ability to create a database from the share.

The other commands either have incorrect syntax or serve different purposes, such as granting privileges within an account rather than authorizing an external account.

Exam trap

The trap here is confusing the GRANT USAGE ON SHARE command, which is used to grant a role within the provider's account the ability to manage the share, with the ALTER SHARE ... ADD ACCOUNT command, which is used to authorize a consumer account to access the share.

10
MCQmedium

An organization wants to create a 'Data Exchange' but only for its internal departments and a few selected vendors. They want to control who can join and what data is listed. Which Snowflake feature is best suited for this?

A.Snowflake Marketplace with Public Visibility.
B.A Private Data Exchange.
C.Direct Sharing with a single 'Global Share' object.
D.Database Replication across all department accounts.
AnswerB

A Private Data Exchange provides the exact functionality requested: a managed portal where the organization acts as the administrator. They can invite specific internal and external accounts to join as providers or consumers, ensuring that the data collaboration remains secure, governed, and restricted to a trusted circle of participants.

Why this answer

A Snowflake Data Exchange (often referred to as a Private Exchange) is a private version of the Marketplace. It allows an organization to create its own curated data ecosystem. The organizer can invite specific members, approve or reject listings, and maintain strict governance over the collaboration environment, making it ideal for internal or closed-ecosystem sharing.

Exam trap

Test-takers frequently confuse the Snowflake Marketplace with a Private Data Exchange, overlooking the need for organizational control and restricted membership curation.

11
MCQhard

A provider has created a share and granted SELECT on a table to the share. The provider now wants to allow the consumer to query the table but also wants to ensure that the consumer cannot see the table's columns that contain personal data. The provider decides to create a secure view that excludes the sensitive columns and grants SELECT on the view to the share. The provider does NOT grant SELECT on the base table to the share. What will the consumer experience when querying the shared view?

A.The consumer must be granted SELECT on the base table for the view to return results, but this would expose the sensitive columns.
B.The consumer will receive an error because they lack privileges on the base table referenced by the view.
C.The consumer can query the view successfully and will see only the non-sensitive columns.
D.The consumer can query the view but will also be able to see the sensitive columns because the view is not secure.
AnswerC

A secure view executes with the owner's privileges, so the consumer does not need SELECT on the base table. The view's definition excludes the sensitive columns, and its results only include the projected columns. The consumer can query the view and see the non-sensitive data. The secure property hides the view definition, preventing the consumer from discovering the excluded columns through metadata.

Why this answer

A shared secure view executes with the owner's privileges, so the consumer does not need privileges on the base table. The view definition excludes sensitive columns, and the secure property hides that definition. As a result, the consumer can query the view and see only the non-sensitive columns.

Granting SELECT on the base table is unnecessary and would actually expose the sensitive data.

Exam trap

The trap here is thinking that consumers need privileges on base tables to query a shared view.

12
MCQeasy

A consumer wants to access a shared database from a provider. The provider has already created the share and granted the necessary privileges. What must the consumer do to access the shared data?

A.Grant the USAGE privilege on the share to a role in the consumer's account.
B.Create a database from the share using the CREATE DATABASE ... FROM SHARE command.
C.Use the ALTER SHARE command to add the consumer's account to the share.
D.Request the provider to grant SELECT on the shared objects directly to the consumer's role.
AnswerB

To access a share, the consumer must create a database from the share using CREATE DATABASE <name> FROM SHARE <provider_account>.<share_name>. This command creates a read-only database in the consumer's account that contains the shared objects. Once created, the consumer can grant privileges on the shared database to roles in their account and query the data.

Why this answer

The consumer must create a database from the share using CREATE DATABASE ... FROM SHARE. This creates a read-only database in the consumer's account.

The consumer then grants privileges on that database to their roles to allow users to query the data. The provider must have already added the consumer's account to the share.

Exam trap

The trap here is thinking the consumer can grant privileges on the share or that the provider can grant directly to the consumer's roles, but the consumer must first create a database from the share and manage access within their own account.

13
MCQhard

A provider shares a secure view named SALES_VIEW with a consumer. The view references a table in the provider's database. The provider later renames the underlying table. What is the impact on the consumer's access to SALES_VIEW?

A.The consumer must recreate the database from the share to see the renamed table through the view.
B.The consumer loses access because the view definition becomes invalid and must be re-created.
C.The consumer's access is unaffected because the view continues to resolve to the renamed table.
D.The consumer sees an error only if the renamed table is also granted directly in the share.
AnswerC

Snowflake views bind to underlying objects by internal object ID rather than by name. Renaming the base table does not break the view's definition, so the shared secure view remains valid and the consumer retains access. This is the expected behavior and the reason the rename has no impact on the consumer.

Why this answer

Views in Snowflake reference base objects by internal object identifiers, not by name. Renaming a table therefore does not invalidate dependent views, and a shared secure view continues to function for the consumer. The consumer's access remains intact without any action on either side, which is the key behavior tested here.

Exam trap

The trap here is assuming that renaming a base table breaks a dependent view, when Snowflake resolves views through internal object IDs rather than by name.

14
MCQeasy

A provider wants to share a database with a consumer account. After creating the share and granting the necessary privileges, which command must the provider run to make the share available to the consumer account?

A.ALTER ACCOUNT consumer_account ADD SHARE share_name;
B.ALTER SHARE share_name ADD ACCOUNT = consumer_account_locator;
C.CREATE SHARE share_name WITH ACCOUNT = consumer_account;
D.GRANT USAGE ON SHARE share_name TO ACCOUNT consumer_account;
AnswerB

To make a share available to a specific consumer account, the provider runs ALTER SHARE ... ADD ACCOUNT using the consumer's account locator or organization-qualified account name. This creates the share relationship. Without this step, the consumer cannot see or mount the share even if privileges are granted. This is the fundamental account-to-account sharing command.

Why this answer

The provider makes a share available to a consumer by adding the consumer's account to the share with ALTER SHARE ... ADD ACCOUNT. This is the standard account-to-account sharing step.

Other commands either invent syntax, reverse the direction, or misunderstand how shares are granted. Once the account is added, the consumer can create a database from the share.

Exam trap

The trap here is thinking that shares are granted to accounts like privileges, when in fact accounts are added to shares using ALTER SHARE ... ADD ACCOUNT.

15
MCQmedium

Refer to the exhibit. A provider has executed these commands to prepare data for a consumer. What is the final mandatory step required before the consumer can access the 'campaign_stats' table?

A.The provider must execute: ALTER SHARE marketing_share ADD ACCOUNTS = <consumer_account_locator>;
B.The consumer must execute: CREATE DATABASE marketing_data FROM SHARE <provider_account>.marketing_share;
C.The provider must refresh the metadata of the 'marketing_share' object using the 'COMMIT SHARE' command.
D.The provider must grant the 'IMPORTED PRIVILEGES' role to the share for the campaign_stats table.
AnswerA

The 'ALTER SHARE' command with the 'ADD ACCOUNTS' clause is the definitive step that authorizes a specific consumer account to view and mount the share. Until this command is executed, the share remains private to the provider. This step completes the handshake by identifying exactly which external Snowflake accounts are permitted to access the data.

Why this answer

After creating a share and granting the necessary object privileges (Database, Schema, and Table/View), the share must be associated with one or more consumer accounts. Without this step, the share exists in the provider account but is not visible or accessible to any external entity. The ALTER SHARE command is used to add the consumer's account to the share's distribution list.

Exam trap

Candidates often select database or table grant commands, assuming object privileges automatically expose the share to consumer accounts, forgetting that explicitly adding consumer account identifiers via ALTER SHARE is mandatory.

16
MCQeasy

A consumer account has created a read-only database named SHARED_SALES from a provider's share and now wants to combine the shared tables with its own local table, LOCAL_REGIONS, in a single query. Which statement about this operation is accurate?

A.The consumer cannot join them because shared databases exist in a separate, isolated storage layer that cannot be referenced alongside local tables.
B.The consumer can join them only if the provider grants SELECT on the local table through the share.
C.The consumer must first clone the shared tables into its own database before any join with local data is possible.
D.The consumer can join SHARED_SALES tables with LOCAL_REGIONS because the shared database is mounted as a normal read-only database in the consumer account.
AnswerD

Once a consumer creates a database from a share, that database behaves like any other database for read operations. The consumer can join shared tables with local tables in the same query, subject to USAGE privileges on both. Shared objects are read-only, but reading across databases in one statement is fully supported.

Why this answer

A shared database created from a share is a read-only database in the consumer account, and read-only status does not prevent it from being queried alongside local objects. Consumers routinely join shared tables with their own data, as long as their role holds the needed privileges on both sides of the join.

Exam trap

The trap here is assuming that read-only shared data cannot participate in joins with local tables, when read-only simply means the consumer cannot modify the shared objects.

17
MCQhard

A consumer account has created a database from a share provided by a partner. The consumer wants to ensure that when the provider adds new tables to the share, those tables become available in the consumer's shared database without any manual intervention. Which statement accurately describes the behavior of shared databases in Snowflake?

A.The consumer must recreate the shared database to see new tables added by the provider.
B.New tables added to the share by the provider are automatically available in the consumer's shared database.
C.The consumer must grant SELECT on the new tables to their own roles before they can be queried.
D.The consumer must run ALTER DATABASE ... REFRESH to pull new objects from the share.
AnswerB

Shared databases in Snowflake are dynamic. When a provider grants SELECT on a new table to a share, that table immediately becomes visible and queryable in the consumer's shared database. No action is required from the consumer. This automatic synchronization is a key benefit of Snowflake Data Sharing, enabling real-time access to provider data without manual refreshes or recreation.

Why this answer

Shared databases are automatically updated when the provider adds new objects to the share. The consumer does not need to refresh, recreate, or grant additional privileges. The provider's grant of SELECT on a new table to the share makes it immediately available in the consumer's shared database.

This real-time propagation is a fundamental characteristic of Snowflake Data Sharing.

Exam trap

The trap here is thinking that shared databases require manual refresh or recreation to see new objects, when in fact they are automatically synchronized.

18
MCQhard

A provider has shared a database with a consumer. The consumer reports that they can see the shared database but cannot query any tables because they get an error about insufficient privileges. The provider used the following command to create the share: CREATE SHARE MY_SHARE; then added a database and a table to the share. The provider also granted USAGE on the database and SELECT on the table to a role named SHARE_ROLE, and then granted SHARE_ROLE to MY_SHARE. What is the most likely cause of the consumer's issue?

A.The provider must also grant USAGE on the schema containing the table to SHARE_ROLE.
B.The consumer must create a database from the share before they can query the tables.
C.The share was not granted to the consumer account using ALTER SHARE ... ADD ACCOUNT.
D.The provider must use a secure view instead of a table to share data.
AnswerA

In Snowflake, to grant access to a table in a share, the provider must grant USAGE on the database, USAGE on the schema, and SELECT on the table to the share. The scenario mentions granting USAGE on the database and SELECT on the table, but not USAGE on the schema. Without schema usage, the consumer cannot access the table, resulting in an insufficient privileges error.

Why this answer

To share a table, the provider must grant USAGE on the database, USAGE on the schema, and SELECT on the table to the share. The scenario omits the schema usage grant, which is required for the consumer to access objects within that schema. Without it, queries will fail with insufficient privileges.

Adding the schema usage grant resolves the issue.

Exam trap

The trap here is assuming that granting USAGE on the database and SELECT on the table is sufficient, forgetting that schema-level USAGE is also mandatory for any object access within that schema.

19
MCQeasy

A consumer account has mounted a shared database named partner_db. The consumer wants to create a local table that combines data from the shared database with their own data. What must the consumer do to create this new table?

A.Create the table in one of their own databases using CREATE TABLE my_db.public.combined AS SELECT ... FROM partner_db.public.table
B.Create the table in the shared database using CREATE TABLE partner_db.public.combined AS SELECT ...
C.Request that the provider grant INSERT privileges on the shared schema so the consumer can create a table there.
D.Clone the shared database into their account and then create the table inside the clone.
AnswerA

Consumers can read from shared databases and write results into their own local databases. A CREATE TABLE AS SELECT statement referencing the shared database creates a new table owned by the consumer in their own schema. This is the standard pattern for combining shared data with local data, and it does not require any write privileges on the shared database.

Why this answer

Consumers can query shared databases but cannot create objects inside them. To combine shared data with local data, the consumer creates a new table in their own database using CREATE TABLE AS SELECT that reads from the shared database. This keeps ownership and write privileges with the consumer and avoids any attempt to modify the read-only shared database.

Exam trap

The trap here is assuming that a mounted shared database can be written to like a local database.

20
MCQhard

A provider wants to share data with a consumer but needs to ensure that the consumer cannot see the underlying table structure or any data beyond what is explicitly exposed. The provider also wants to prevent the consumer from using the shared data to infer sensitive information. Which Snowflake feature should the provider use?

A.Dynamic data masking
B.Row access policies
C.Secure views
D.Materialized views
AnswerC

Secure views are designed to hide the underlying SQL definition and prevent users from seeing the base tables or using query optimizations that might leak information. They are ideal for sharing sensitive data because they allow fine-grained control and prevent inference attacks. The provider should use secure views to expose only the necessary data.

Why this answer

Secure views are specifically designed to share data without revealing the underlying table structure or allowing inference. They hide the view definition from unauthorized users and prevent the use of certain optimizations that could leak information. For sharing sensitive data with external consumers, secure views are the recommended feature.

Exam trap

The trap here is confusing secure views with other security features like row access policies or dynamic data masking, which address specific aspects but do not provide the comprehensive hiding and inference prevention that secure views offer.

21
MCQmedium

A retail provider shares a secure view that joins a table in its SALES database with a table in its INVENTORY database. A consumer reports that queries against the shared view fail with an authorization error, even though the view itself is granted to the share. The provider confirms both underlying tables exist and the view definition is valid. Which issue most likely explains the failure?

A.The consumer must be granted the ACCOUNTADMIN role to query cross-database views.
B.The share was not associated with the consumer account.
C.Secure views cannot reference objects in more than one database.
D.The provider did not grant USAGE on the databases and schemas containing the underlying tables to the share.
AnswerD

A secure view references objects across two databases. For the view to execute, the share must include USAGE on each database and schema that holds the referenced tables, in addition to the SELECT grant on the view. Without those container-level grants, the view cannot resolve its dependencies and queries fail with an authorization error.

Why this answer

When a shared view references objects in multiple databases, the share must carry USAGE on every database and schema that contains a referenced object, plus SELECT on the view. Granting only the view leaves the underlying containers inaccessible, so the consumer's query cannot be authorized. Adding the missing container grants resolves the error without changing the view.

Exam trap

The trap here is granting only the view to the share and forgetting that a cross-database view also requires USAGE on each referenced database and schema.

22
MCQmedium

A consumer has created a database from a share. They want to grant their 'ANALYST' role the ability to query the tables within this shared database. Which privilege should they grant to the role?

A.GRANT SELECT ON ALL TABLES IN DATABASE <shared_db> TO ROLE ANALYST;
B.GRANT USAGE ON DATABASE <shared_db> TO ROLE ANALYST;
C.GRANT IMPORTED PRIVILEGES ON DATABASE <shared_db> TO ROLE ANALYST;
D.GRANT OWNERSHIP ON DATABASE <shared_db> TO ROLE ANALYST;
AnswerC

The IMPORTED PRIVILEGES grant is the correct and mandatory way for a consumer to authorize a local role to access a shared database. It effectively passes through all the privileges defined by the provider in the share to the specified local role, ensuring that the analyst can query the tables and views as intended.

Why this answer

When a consumer mounts a share, the resulting database is special. To allow other roles in their account to use it, they use the 'IMPORTED PRIVILEGES' grant. This is a bulk grant that conveys the necessary permissions (like USAGE and SELECT) on all objects within the shared database to a local role, simplifying the permission management for the consumer.

Exam trap

Candidates frequently try granting standard USAGE or SELECT privileges directly on shared databases, failing to remember that shared databases require the special IMPORTED PRIVILEGES grant.

23
MCQhard

A provider wants to share a dynamic table with a consumer. The dynamic table is defined on a base table that is not shared. What must the provider ensure for the consumer to query the dynamic table?

A.The provider must grant SELECT on the base table to the share.
B.The dynamic table must be refreshed before sharing.
C.The consumer must be granted the ability to refresh the dynamic table.
D.The dynamic table must be added to the share, and the dynamic table owner must have the necessary privileges on the base table.
AnswerD

Dynamic tables can be shared like regular tables. The consumer queries the dynamic table directly, and it executes with the owner's privileges. Therefore, the provider must add the dynamic table to the share and ensure the dynamic table owner has SELECT on the base table. The consumer does not need access to the base table.

Why this answer

Dynamic tables can be shared directly. The consumer queries the dynamic table, which executes with the owner's privileges. The provider must add the dynamic table to the share and ensure the owner has SELECT on the base table.

The consumer does not need any privileges on the base table. This allows sharing of transformed data without exposing the source.

Exam trap

The trap here is assuming the consumer needs access to the base table, when dynamic tables execute with the owner's rights.

24
MCQeasy

A consumer has created a database from a share provided by a partner. The consumer wants to allow a specific role, ANALYST_ROLE, to query the shared data. Which privilege must the consumer grant to ANALYST_ROLE on the shared database?

A.OWNERSHIP
B.IMPORTED PRIVILEGES
C.USAGE
D.SELECT
AnswerB

When a consumer creates a database from a share, they must grant the IMPORTED PRIVILEGES privilege on that database to roles that need access. This privilege allows the role to access the shared objects as if they were local, including querying tables and views. It is the standard way to enable access to shared data.

Why this answer

To allow a role to query data in a database created from a share, the consumer must grant the IMPORTED PRIVILEGES privilege on that database to the role. This privilege grants access to the shared objects, including SELECT on tables and views. It is the correct and only privilege that enables access to shared data.

Exam trap

The trap here is assuming that granting USAGE on the database is sufficient, but USAGE only allows visibility of the database, not querying of its objects.

25
Multi-Selecthard

A provider is preparing to share a secure view that references a table in another database. The provider must ensure the consumer can query the view but cannot access the base table. Which two actions must the provider take? (Choose two.)

Select 2 answers
A.Grant SELECT on the secure view to the share.
B.Grant SELECT on the base table to the share.
C.Create a new role that has access to the base table and grant that role to the share.
D.Grant USAGE on the database and schema containing the base table to the share.
E.Grant USAGE on the database and schema containing the secure view to the share.
AnswersA, E

Granting SELECT on the secure view to the share is necessary for the consumer to query the view. This privilege allows the consumer to read data from the view. The provider must also grant USAGE on the containing database and schema. Together, these grants enable access to the view while keeping the base table private.

Why this answer

To share a secure view that references a table in another database, the provider must grant USAGE on the database and schema containing the view, and SELECT on the view, to the share. These two grants allow the consumer to query the view. The base table remains private because the view executes with the owner's rights, and no privileges on the base table are granted.

Exam trap

The trap here is thinking that the base table's database must also be shared or that a role must be granted to the share, but secure views use owner's rights and shares accept only direct object privileges.

26
MCQmedium

A provider wants to ensure that a Reader Account they created does not exceed a budget of 50 credits per month. What is the most effective way to implement this control?

A.Set a hard limit on the 'READER_ACCOUNT_CREDITS' parameter in the provider account settings.
B.Create a Resource Monitor in the provider account and assign it to the Reader Account.
C.Ask the consumer to monitor their own usage and stop querying when they hit 50 credits.
D.The provider must manually drop the Reader Account once the 50-credit threshold is reached each month.
AnswerB

Resource Monitors allow providers to set quotas on credit consumption for a specific time interval, such as monthly. When the Reader Account's warehouses consume credits, the monitor tracks the total. If the limit is reached, the monitor can automatically suspend the Reader Account's compute resources, preventing further unbudgeted costs.

Why this answer

Since the provider is responsible for the costs of a Reader Account, they must have tools to manage that expenditure. Resource Monitors are the standard Snowflake mechanism for this. A provider can create a resource monitor and associate it with the Reader Account (or the warehouses within it) to track credit usage and trigger actions like alerting or suspending the warehouse.

Exam trap

Candidates often incorrectly suggest using Account-level parameters or external billing tools, forgetting that Resource Monitors are the native Snowflake feature designed specifically for credit budget management.

27
MCQhard

A provider has created a share and added a table. The consumer reports that they can see the shared database and schema but cannot see the table. The provider confirms the table was added with ALTER SHARE ... ADD TABLE. Which additional privilege must the provider grant to the share so the consumer can query the table?

A.REFERENCES on the table, granted to the share.
B.SELECT on the table, granted to the share.
C.OWNERSHIP on the table, transferred to the share.
D.USAGE on the database and schema containing the table, granted to the share.
AnswerB

Adding a table to a share does not automatically grant SELECT on it. The provider must explicitly grant SELECT on the table to the share. Without this, the consumer can navigate to the table but queries fail with an authorization error. This is the standard step after ALTER SHARE ... ADD TABLE, and it is required for data access.

Why this answer

When a table is added to a share, the provider must also grant SELECT on that table to the share. The consumer already has visibility of the database and schema, so the missing element is table-level read access. Granting SELECT to the share is the documented step that enables queries.

Other privileges like USAGE, REFERENCES, or OWNERSHIP do not provide the needed row-level read permission.

Exam trap

The trap here is believing that adding an object to a share implicitly grants the privileges needed to query it, when SELECT must be granted to the share explicitly.

28
MCQmedium

A provider uses a reader account to share data with a client that does not have its own Snowflake account. The client now reports that it cannot see newly added tables that the provider granted to the share. The provider confirms the new tables were added to the share with SELECT grants. Which statement explains why the client cannot see the new tables?

A.The reader account's shared database must be recreated to pick up new tables.
B.Reader accounts require a separate share for each new table.
C.The provider must grant USAGE on the schema containing the new tables to the share.
D.Reader accounts can only query tables that existed when the reader account was created.
AnswerC

Adding tables to a share requires that the share also holds USAGE on the containing database and schema. If the new tables live in a schema not yet granted to the share, the consumer cannot see them even though SELECT was granted on the tables themselves. Adding the missing USAGE grant resolves the issue.

Why this answer

For any table to be visible through a share, the share needs USAGE on the table's database and schema in addition to SELECT on the table. If the new tables reside in a schema that was never granted to the share, the consumer cannot see them. Granting the missing schema-level USAGE makes the new tables appear to the reader account without recreating anything.

Exam trap

The trap here is assuming that SELECT on a newly added table is enough, when the share also needs USAGE on the schema that contains it.

29
MCQmedium

A provider account named PROVIDER_ACCT has created a share named PARTNER_SHARE and granted SELECT on a secure view to it. The provider now needs to make this share available to a specific consumer account named CONSUMER_ACCT. Which single command should the provider execute to accomplish this?

A.GRANT USAGE ON SHARE PARTNER_SHARE TO ACCOUNT CONSUMER_ACCT;
B.ALTER SHARE PARTNER_SHARE ADD ACCOUNT = CONSUMER_ACCT;
C.CREATE SHARE PARTNER_SHARE FOR ACCOUNT = CONSUMER_ACCT;
D.ALTER ACCOUNT CONSUMER_ACCT ADD SHARE PARTNER_SHARE;
AnswerB

The ALTER SHARE ... ADD ACCOUNT statement is the correct mechanism to make an existing share available to a named consumer account. Executing it from the provider account binds the share to the consumer's account locator or organization-qualified name, after which the consumer can create a database from the share. This directly satisfies the requirement of exposing PARTNER_SHARE to CONSUMER_ACCT.

Why this answer

Sharing to a specific consumer requires the provider to attach the consumer's account to the share. The ALTER SHARE ... ADD ACCOUNT statement performs this binding and is executed in the provider account.

Once added, the consumer sees the share as an inbound share and can create a database from it, gaining read-only access to the granted objects.

Exam trap

The trap here is assuming shares are granted to accounts the same way privileges are granted to roles, when in fact shares are attached to consumer accounts with ALTER SHARE ... ADD ACCOUNT.

30
MCQmedium

A provider runs CREATE SHARE sales_share; then GRANT USAGE ON DATABASE sales_db TO SHARE sales_share; GRANT USAGE ON SCHEMA sales_db.public TO SHARE sales_share; GRANT SELECT ON TABLE sales_db.public.orders TO SHARE sales_share; ALTER SHARE sales_share ADD ACCOUNT = consumer_acct; A consumer in consumer_acct queries the shared database and receives results. Six months later, the provider executes REVOKE SELECT ON TABLE sales_db.public.orders FROM SHARE sales_share; What is the immediate effect for the consumer?

A.The consumer keeps access but can no longer see the table in SHOW TABLES output.
B.The consumer can still query the shared table because the share was already mounted and the data is cached locally.
C.The consumer immediately loses the ability to query the table and receives an authorization error.
D.The consumer retains read access until the share is dropped or the account is removed from the share.
AnswerC

Privileges granted to a share are enforced at query time against the provider's live data. Revoking SELECT on the table from the share removes the consumer's access instantly, so the next query returns an error such as 'SQL access control error: Insufficient privileges to operate on table'. No re-mounting is required for the revocation to take effect, and previously cached results do not preserve access.

Why this answer

Shares expose live provider data and enforce privileges at query time, so revoking SELECT on a table from a share removes access immediately. The consumer does not need to unmount the database, and cached results do not preserve authorization. The share object and other granted objects remain intact; only the revoked table becomes inaccessible, with a standard insufficient privileges error on the next attempt.

Exam trap

The trap here is assuming that a mounted share or cached results preserve access after a privilege is revoked.

31
MCQeasy

A consumer has mounted a share from a provider and wants to grant a role in their account the ability to query the shared data. What must the consumer do?

A.Ask the provider to grant SELECT directly to the consumer's role.
B.Grant USAGE on the shared database and schemas, and SELECT on the shared tables or views, to the role.
C.Create a new share in the consumer account that references the provider's share.
D.Nothing, because all roles in the consumer account automatically have access to shared databases.
AnswerB

After creating a database from a share, the consumer must grant privileges on that database to roles that need access. This includes USAGE on the database and schema, and SELECT on the specific tables or views. The consumer controls these grants independently of the provider, so this is the correct action.

Why this answer

Consumers manage access to shared databases using standard GRANT statements within their own account. They grant USAGE on the database and schemas, and SELECT on the shared tables or views, to the roles that need access. Providers cannot grant privileges to consumer roles, and access is not automatic.

Exam trap

The trap here is assuming the provider controls access on the consumer side, when in fact the consumer grants privileges on the mounted database to their own roles.

32
Multi-Selecthard

A provider is preparing to share data with a consumer using a direct share. The provider wants to ensure that the consumer can query a specific table and also see any future columns added to that table without additional grants. Which two actions must the provider take? (Choose two.)

Select 2 answers
A.Grant USAGE on the database and schema containing the table to the share.
B.Grant REFERENCES on the table to the share to allow future columns to be visible.
C.Grant SELECT on each future column to the share as they are added.
D.Grant SELECT on the table to the share.
E.Create a secure view that selects all columns from the table and grant SELECT on the view to the share.
AnswersA, D

Granting USAGE on the database and schema to the share is required so that the consumer can access the schema and see the table. Without these grants, the consumer cannot navigate to the table even if SELECT is granted on the table itself. This is a foundational step for any share.

Why this answer

To share a table and automatically include future columns, the provider must grant USAGE on the database and schema to the share, and grant SELECT on the table to the share. SELECT on a table applies to all columns, including those added later. No column-level grants are needed.

A secure view is not required for this purpose.

Exam trap

The trap here is thinking that future columns require additional grants or a view, when in fact a table-level SELECT grant covers all current and future columns.

33
MCQmedium

A Snowflake provider wants to share a secure view with a consumer. The view is defined on a table in a different database than the one containing the view, and the provider must ensure the consumer cannot access the underlying base table directly. Which action should the provider take?

A.Grant USAGE on the database and schema containing the secure view, and SELECT on the secure view, to the share.
B.Grant USAGE on the database containing the base table to the share.
C.Add the base table to the share and rely on the secure view to restrict access.
D.Create a new role with access to the base table and grant that role to the share.
AnswerA

To share a secure view, the provider must grant USAGE on the database and schema that contain the view, and SELECT on the view itself to the share. The base table's database does not need to be shared because the secure view runs with the owner's rights, and the consumer only needs access to the view. This keeps the base table private.

Why this answer

When sharing a secure view that references objects in other databases, the provider must grant USAGE on the database and schema that contain the view, and SELECT on the view, to the share. The base table's database is not shared, and the secure view's owner's rights allow access to the base table without exposing it to the consumer.

Exam trap

The trap here is assuming that the base table's database must also be shared so the view can access it, but secure views execute with the owner's rights and do not require the consumer to have access to the base objects.

34
Multi-Selecthard

To publish a data listing on the Snowflake Marketplace and make it available to all Snowflake customers, which TWO requirements must the provider fulfill?

Select 2 answers
A.The provider must have a Business Profile that has been approved by Snowflake.
B.The provider must use a Business Critical edition account or higher.
C.The provider must agree to the Snowflake Provider and Marketplace Terms.
D.The provider must pay an annual Marketplace listing fee of $5,000.
E.The provider must share the data exclusively through the Marketplace and not through Direct Shares.
AnswersA, C

A Business Profile is a prerequisite for Marketplace participation. It includes details about the company, its contact information, and its data offerings. Snowflake reviews these profiles to ensure providers meet quality and professional standards, which protects the integrity of the Marketplace and provides consumers with confidence in the data they acquire.

Why this answer

Publishing to the Snowflake Marketplace is a formal process that requires more than just technical setup. Providers must have a verified business profile to establish trust and must adhere to Snowflake's provider policies. These requirements ensure that the Marketplace remains a high-quality environment for data consumers and that providers are legitimate entities capable of supporting their data offerings.

Exam trap

Candidates often assume technical configuration is sufficient, ignoring the administrative and legal requirements like a Snowflake-approved business profile and formal agreement to the Provider Terms.

35
MCQhard

A provider wants to share a database with a consumer but must prevent the consumer from seeing the database's table and schema names in its own account. The provider also wants the consumer's queries to be isolated from the provider's own warehouse usage. Which approach satisfies both requirements?

A.Create a secure view that projects the data and grant only the view to the share, then let the consumer use its own warehouse.
B.Use a database replication task to copy the data into the consumer's account.
C.Create a reader account for the consumer and grant the consumer's role access to the provider's warehouse.
D.Grant SELECT on each table directly to the share and let the consumer create a database from the share.
AnswerA

Sharing a secure view hides the underlying table and schema names, since the consumer sees only the view. When the consumer creates a database from the share, it uses its own warehouse for queries, so the provider's warehouse is not consumed. This combination satisfies both the concealment and isolation requirements.

Why this answer

A secure view exposes only the projected result, so the consumer never sees the underlying table or schema names. Because the consumer creates a database from the share and queries it with its own warehouse, the provider's warehouse is untouched. Together, the secure view and consumer-owned warehouse meet both the naming-concealment and usage-isolation requirements.

Exam trap

The trap here is assuming that sharing tables directly conceals their names, when only a secure view hides the underlying schema and table identifiers from the consumer.

36
MCQmedium

A provider has created a share and added a table. The provider now wants to revoke access for a specific consumer account without affecting other consumers. Which command should the provider use?

A.DROP SHARE my_share;
B.ALTER SHARE my_share REMOVE ACCOUNT = consumer_account;
C.REVOKE USAGE ON SHARE my_share FROM ACCOUNT consumer_account;
D.REVOKE SELECT ON TABLE my_table FROM SHARE my_share;
AnswerB

The ALTER SHARE ... REMOVE ACCOUNT command is the correct way to revoke a consumer's access to a share. It removes the specified account from the share, immediately terminating their ability to access the shared data. This action does not affect other consumers who are still added to the share, making it the precise method for this scenario.

Why this answer

To revoke access for a specific consumer, the provider must remove that account from the share using ALTER SHARE ... REMOVE ACCOUNT. This action only affects the specified account and leaves other consumers unaffected.

Dropping the share or revoking table privileges would impact all consumers, which is not desired. The correct command is precise and reversible if needed.

Exam trap

The trap here is using REVOKE or DROP commands that affect the entire share or all consumers, rather than the targeted ALTER SHARE ... REMOVE ACCOUNT command.

37
MCQeasy

A Snowflake data provider creates a Reader Account for a consumer who does not have a Snowflake account. Who is responsible for the compute costs incurred by the queries executed within this Reader Account?

A.The consumer, who is billed directly by Snowflake via a credit card registered to the Reader Account.
B.Snowflake, as part of the free tier benefits for new data consumers.
C.The provider, who is billed for all virtual warehouse usage within the Reader Account.
D.The cost is split equally between the provider and the consumer at the end of each billing cycle.
AnswerC

Reader accounts are managed by the provider, who is responsible for all credit consumption generated by the consumer's activity. The provider can set up resource monitors to control and limit the amount of credits the Reader Account can use. This ensures the provider can share data without facing unexpected or unmanaged costs.

Why this answer

Reader accounts are a feature designed to allow providers to share data with organizations that are not yet Snowflake customers. Because the Reader Account is created and owned by the provider, the provider assumes all financial responsibility for the resources consumed. This includes the credits used by virtual warehouses within the Reader Account for querying the shared data.

Exam trap

Candidates often mistakenly believe the consumer using a Reader Account pays for their own queries, ignoring the fact that the provider fully owns and bills for all usage.

38
MCQmedium

A provider's account is named PROVIDER_ACCT and it has created a share named PARTNER_SHARE that already contains a secure view. The provider now runs: ALTER SHARE PARTNER_SHARE ADD ACCOUNTS = CONSUMER_ACCT; What is the effect of this command in the provider's environment?

A.It fails because the ADD ACCOUNTS clause is only valid at share creation time and cannot be used on an existing share.
B.It grants CONSUMER_ACCT the ability to read the share, but a database must still be created in CONSUMER_ACCT before any shared data is visible there.
C.It immediately creates a read-only database in CONSUMER_ACCT containing all objects in the share, usable without any further consumer action.
D.It converts the share into a listing that is publicly discoverable on the Snowflake Marketplace by all Snowflake accounts.
AnswerB

Adding an account to a share only authorizes that consumer account and places a share object in its 'inbound' area; nothing is readable until a consumer-side role with CREATE DATABASE runs CREATE DATABASE ... FROM SHARE. Until that database is created, the consumer sees only an available share, not tables. This is exactly how data sharing provisioning works.

Why this answer

A share is only an authorization container; adding a consumer account simply permits that account to see an inbound share. Consumers must then create a database from the share with a role that has CREATE DATABASE before any tables become queryable. The provider cannot perform that step on the consumer's behalf, which is why the data is not instantly usable after the ALTER SHARE command.

Exam trap

The trap here is assuming that adding a consumer account to a share also creates the shared database in that consumer account, when the consumer must perform the CREATE DATABASE ... FROM SHARE step.

39
MCQhard

A provider wants to share data with a consumer but needs the shared data to reflect changes in the provider's source tables in near real time. The provider also wants to avoid granting the consumer access to the underlying base tables. Which approach best meets these requirements?

A.Grant SELECT on the base tables directly to the share and instruct the consumer not to modify them.
B.Create a secure view over the base tables and grant SELECT on the view to the share.
C.Create a materialized view over the base tables and grant SELECT on the materialized view to the share.
D.Copy the base tables into a separate database and grant SELECT on the copies to the share.
AnswerB

A secure view queries the base tables at runtime, so consumers always see current data without any refresh process. Because the view is secure, its definition is hidden and consumers cannot infer underlying table structures. Granting SELECT on the view to the share provides access without exposing the base tables, satisfying both requirements.

Why this answer

A secure view provides real-time access to base table data because it executes the underlying query at runtime. It also hides the view definition and base table details from consumers. Granting SELECT on the secure view to the share meets both the freshness and the access restriction requirements, unlike copies or direct table grants.

Exam trap

The trap here is assuming materialized views can be shared like regular views, when shares only support specific object types and materialized views are not among them.

40
Multi-Selecthard

A provider is preparing to share data with a consumer via a direct share. The provider wants to ensure that the consumer can access the data but cannot see the underlying table structure or any other objects in the database. Which two actions should the provider take? (Choose two.)

Select 2 answers
A.Ensure the share contains only the secure view and no other objects.
B.Grant USAGE on the database to the consumer's role.
C.Create a database role and grant it to the consumer.
D.Add the table directly to the share and grant SELECT on the table to the consumer.
E.Create a secure view that selects from the table and add the secure view to the share.
AnswersA, E

To prevent the consumer from seeing any other objects, the provider must ensure that the share contains only the secure view. If other objects are added to the share, the consumer could potentially access them. By limiting the share to the secure view, the provider controls exactly what the consumer can see, aligning with the principle of least privilege.

Why this answer

To share data while hiding the underlying structure, the provider should create a secure view and add it to the share, and ensure the share contains only that view. Secure views prevent consumers from seeing the base table definitions, and limiting the share to the view ensures no other objects are exposed. Other options involve direct table access or ineffective grants that do not meet the security requirements.

Exam trap

The trap here is thinking that adding a table directly to a share is sufficient, when in fact secure views are needed to hide the underlying structure, and extra objects in the share can inadvertently expose data.

41
MCQmedium

A data provider wants to share a subset of data with a specific consumer while ensuring the consumer cannot see any other tables in the same database. What is the most secure and efficient method to achieve this?

A.Grant usage on the entire database to the consumer's role.
B.Create a shared database and grant access to the base tables.
C.Use a Secure View in a dedicated share-ready schema.
D.Enable Secure Data Sharing and grant SELECT on all tables.
AnswerC

Secure Views are specifically optimized to hide internal metadata and query structures from unauthorized users. By placing the view in a dedicated schema, the provider enforces strict isolation, ensuring the consumer only interacts with the specific subset defined by the view logic without discovering other database objects.

Why this answer

Secure Views are essential for sharing specific data subsets because they hide the underlying query logic and schema structure from the consumer. By using a Secure View, the provider maintains granular control over column and row visibility, ensuring data privacy across account boundaries. This approach prevents unauthorized metadata discovery, which is critical in multi-tenant data sharing environments where isolation between different business units or external partners must be strictly maintained for compliance.

Exam trap

Many candidates mistakenly select standard views or table duplication, forgetting that standard views expose underlying metadata and schema structures, violating isolation and security requirements.

42
MCQmedium

A provider wants to share data with a consumer account, but the consumer's account is in a different Snowflake region. The provider's data is in the US West (Oregon) region, and the consumer is in the EU (Frankfurt) region. The provider needs the consumer to access the data with low latency. Which Snowflake feature should the provider use?

A.Create a direct share and add the consumer account; Snowflake automatically replicates the data to the consumer's region.
B.Use database replication to create a replica of the database in the consumer's region, then share the replica with the consumer.
C.Configure a private data exchange and add the consumer; data exchanges replicate data to all member regions automatically.
D.Create a listing on the Snowflake Marketplace and have the consumer request it; Marketplace listings are always served from the consumer's region.
AnswerB

Snowflake supports replicating databases across regions and accounts. The provider can create a secondary database in the consumer's region, keep it synchronized with the primary, and then create a share on the secondary database. The consumer mounts the share from their own region, achieving low-latency access. This is the standard approach for cross-region sharing with performance requirements.

Why this answer

Cross-region sharing with low latency requires the data to be present in the consumer's region. Snowflake database replication allows a provider to create a replica in another region, and a share can be created on that replica. Direct shares, Marketplace listings, and data exchanges do not automatically replicate data across regions, so they would not satisfy the low-latency requirement without additional replication steps.

Exam trap

The trap here is believing that shares, listings, or exchanges automatically replicate data to the consumer's region.

43
MCQmedium

A provider shares a database with a consumer using a direct share. The consumer reports that queries against the shared database fail with an error indicating the database does not exist, even though the share was successfully created and granted to the consumer account. The provider confirmed that the share contains the necessary tables and that the consumer account has been added to the share. What is the most likely cause of the issue?

A.The provider did not grant the USAGE privilege on the database to the consumer's role.
B.The consumer's account is in a different region than the provider's account, and cross-region sharing is not enabled.
C.The provider did not include a secure view in the share, so the consumer cannot access the tables.
D.The consumer has not created a database from the share using CREATE DATABASE ... FROM SHARE.
AnswerD

A share makes data available, but the consumer must explicitly create a database from the share using CREATE DATABASE ... FROM SHARE. Until that step is performed, the shared database does not appear in the consumer's account, causing 'database does not exist' errors. The provider cannot create the database on behalf of the consumer because the share is mounted in the consumer's account.

Why this answer

For a consumer to access a direct share, they must create a database from the share using CREATE DATABASE ... FROM SHARE. The provider's role is to create the share, grant privileges on objects to the share, and add the consumer account.

The consumer must then mount the share by creating a database. Without this step, the shared database is not visible, leading to errors when querying.

Exam trap

The trap here is assuming that granting the share to the consumer account automatically makes the data available without the consumer creating a database from the share.

44
MCQmedium

Refer to the exhibit. Based on the JSON configuration for this Snowflake listing, who will be able to discover and access this data?

A.Any Snowflake customer in the same region as the provider.
B.Only the users within the provider's own Snowflake account.
C.Only the specific accounts 'ORG_A.ACCOUNT_1' and 'ORG_B.ACCOUNT_2'.
D.All accounts belonging to ORG_A and ORG_B, regardless of the individual account names.
AnswerC

Because the listing is marked as private and specifies target accounts, only those named accounts will see the listing in their 'Private Sharing' area. This configuration is ideal for B2B data sharing where the provider wants to leverage the Marketplace's UI and tracking but keep the data restricted to specific partners.

Why this answer

The exhibit defines a Private Listing. Private listings are not visible in the public Snowflake Marketplace. Instead, they are only discoverable by the specific accounts listed in the 'target_accounts' array.

This allows providers to use the Marketplace interface and management tools to share data with specific partners securely, without making the offering public to the entire Snowflake community.

Exam trap

Candidates often assume that 'Private' means it is visible to everyone within the organization, rather than realizing it is restricted to specific, named accounts.

45
Multi-Selectmedium

A provider wants to share data with a consumer using a Direct Share. Which two statements accurately describe the consumer's experience after the share is mounted? (Choose two.)

Select 2 answers
A.The consumer can view the share's objects without any additional storage cost for the shared data.
B.The consumer can modify the shared data directly because they own the mounted database.
C.The consumer must copy the shared data into their own tables before querying it.
D.The consumer can query shared data using their own virtual warehouses.
E.The consumer can create their own tables in the same schema as the shared objects.
AnswersA, D

Because shared data stays in the provider's storage, the consumer incurs no storage charges for the shared data itself. The consumer only pays for compute used to query it. This cost model is a key benefit of Snowflake sharing and is accurately described in this statement.

Why this answer

With Direct Sharing, the consumer mounts a read-only database and queries it using their own compute. Storage remains with the provider, so the consumer incurs no storage cost for the shared data. The consumer cannot modify shared objects or add objects inside the shared database, which distinguishes sharing from copying data.

Exam trap

The trap here is conflating ownership of the mounted database with write access to its contents, when shared databases are strictly read-only for the consumer.

46
MCQeasy

A consumer has mounted a shared database named 'SALES_DATA_SHARED'. They need to add a new column to one of the tables in this database to store local annotations. Which statement best describes the outcome if they attempt this?

A.The operation will succeed, but the changes will only be visible to the consumer's account.
B.The operation will fail because shared databases are read-only for consumers.
C.The operation will succeed only if the provider has granted the 'MODIFY' privilege to the share.
D.The operation will fail unless the consumer is using the 'ACCOUNTADMIN' role.
AnswerB

Any DDL or DML attempt on a shared database results in an error. The read-only nature is a fundamental security and architectural constraint of Snowflake's sharing model. This ensures that the provider remains the sole authority for the data and that the consumer's role is limited to data analysis and retrieval.

Why this answer

Shared databases in Snowflake are strictly read-only for the consumer. The consumer cannot perform any Data Definition Language (DDL) operations like ALTER TABLE, nor any Data Manipulation Language (DML) operations like INSERT or UPDATE on the shared objects. This architecture ensures the integrity of the provider's data and maintains a single version of truth across all consumers.

Exam trap

Candidates often think they can perform local transformations on shared data, failing to realize that shared databases are strictly read-only and cannot be modified by the consumer.

47
MCQhard

A provider has a share containing a secure view that references a table in the same database. The provider wants the share to stop being visible to a specific consumer account but keep the share and its grants intact for other consumers. Which action accomplishes this?

A.Run ALTER SHARE ... ADD ACCOUNTS = <consumer_account> with a REVOKE keyword to flip the account's access off.
B.Run REVOKE USAGE ON DATABASE <shared_db> FROM SHARE <share_name> to detach the consumer account.
C.Run DROP SHARE <share_name> and recreate it immediately, re-adding every consumer except the one to be excluded.
D.Run ALTER SHARE ... REMOVE ACCOUNTS = <consumer_account> so only that account loses access while the share and its grants remain unchanged.
AnswerD

REMOVE ACCOUNTS deletes the account-to-share association for the named consumer only. The share object and all grants on its objects persist, so other consumers are unaffected. The removed account can no longer create a database from the share, and its existing shared database loses access on the next access attempt.

Why this answer

A share's consumer list is managed with ALTER SHARE. Using REMOVE ACCOUNTS for one account revokes that account's access while leaving the share definition and all object grants untouched, so remaining consumers continue working without interruption.

Exam trap

The trap here is reaching for DROP SHARE or privilege revokes to cut off one consumer, when the share's account list is what controls which accounts can mount it.

48
MCQeasy

A data provider at a healthcare analytics company wants to share live patient-readmission metrics with a partner hospital. The partner must query the data with low latency and the provider must retain full ownership and control of the underlying tables. The provider creates a share and grants USAGE on a secure view to the share. Which action must the provider perform next so the partner account can mount and query the shared data?

A.Create a database from the share in the provider account and grant USAGE to the partner.
B.Publish the share as a listing on the Snowflake Marketplace.
C.Add the partner's account to the share using ALTER SHARE ... ADD ACCOUNTS.
D.Grant the CONSUME privilege on the share to the partner's account.
AnswerC

A share becomes consumable only after the provider account is associated with a consumer account. ALTER SHARE ... ADD ACCOUNTS binds the share to the partner's Snowflake account identifier, allowing the consumer to create a database from the share. Until this association exists, the granted objects are inaccessible regardless of privileges.

Why this answer

For a direct share, the provider grants object privileges to the share, then associates the consumer account with the share. The consumer then creates a database from the share to query it. Adding the account is mandatory because privileges alone do not cross account boundaries; the share must be explicitly bound to the consumer's account before it can be mounted.

Exam trap

The trap here is assuming that granting object privileges to a share is sufficient, when the share must also be associated with the consumer's account before any data is visible.

Ready to test yourself?

Try a timed practice session using only Data Collaboration questions.