COF-C03 Account Management and Data Governance Practice Question
Exhibit
SHOW GRANTS ON SCHEMA sales_db.public;
Refer to the exhibit. A user with the role 'ANALYST_ROLE' cannot see tables inside the 'sales_db.public' schema despite having 'USAGE' on the database. What is the most likely reason for this access issue?
⚠ Common exam trap
Candidates incorrectly assume that having USAGE on a database automatically grants visibility into its schemas and tables, overlooking Snowflake's strict requirement for explicit USAGE grants at the schema level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user lacks the 'USAGE' privilege on the schema.
In Snowflake, the USAGE privilege on a database is insufficient to view objects within schemas; the user must also be granted USAGE on the schema and SELECT on the specific tables or views. This multi-layered privilege requirement is a core component of Snowflake's security model, preventing accidental data exposure by requiring explicit grants at every level of the object hierarchy, from the database down to the individual object.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user needs the 'OWNERSHIP' privilege on the schema.
Why it's wrong here
Ownership is not required to view data; it is only required to manage the object or grant privileges to others. Granting ownership of a schema to a general user is a security risk and violates the principle of least privilege, as it allows them to drop the schema.
- ✓
The user lacks the 'USAGE' privilege on the schema.
Why this is correct
Access to a database does not grant implicit access to its schemas. To browse or query objects within a schema, a user must have the USAGE privilege on that specific schema. Without this privilege, the database contents will appear empty even if the database is accessible.
- ✗
The database is not set as the default database for the user.
Why it's wrong here
Setting a default database is a convenience for users to avoid using fully qualified names, but it is not a security requirement for accessing data. A user can query any object they have explicit privileges on by using its fully qualified name, regardless of their default settings.
- ✗
The user is missing the 'MANAGE GRANTS' privilege.
Why it's wrong here
The MANAGE GRANTS privilege allows a role to modify access control for other roles. It is an administrative privilege that is not required for a user to see or query tables in a schema. Normal data access is managed through standard object-level privileges, not administrative ones.
About these practice questions
This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.