Courseiva

CCNA Account Mgmt Data Governance Questions

47 questions · Account Mgmt Data Governance topic · All types, answers revealed

1
MCQmedium

A Snowflake account has a custom role named DATA_ENGINEER. The administrator wants to ensure that DATA_ENGINEER can create databases and warehouses but cannot manage users or roles. Which predefined role should DATA_ENGINEER be granted to achieve this?

A.SYSADMIN
B.ACCOUNTADMIN
C.USERADMIN
D.SECURITYADMIN
AnswerA

SYSADMIN is the predefined role responsible for creating and managing warehouses, databases, and other objects. Granting SYSADMIN to DATA_ENGINEER provides the necessary privileges to create databases and warehouses. It does not include the ability to manage users or roles, which aligns with the requirement to restrict those actions.

Why this answer

SYSADMIN is the predefined role that provides privileges to create and manage warehouses, databases, and other objects. It does not include user or role management, which is handled by SECURITYADMIN and USERADMIN. By granting SYSADMIN to DATA_ENGINEER, the administrator ensures the role can perform its intended tasks without over-privileging it.

Exam trap

The trap here is assuming that ACCOUNTADMIN is needed for object creation, overlooking that SYSADMIN provides the necessary privileges without user management.

2
MCQeasy

A compliance officer needs to confirm which roles have been granted to a specific user across the account, including grants made through role hierarchies. Which Snowflake command should be used to retrieve this information?

A.SHOW GRANTS TO USER <username>
B.SHOW GRANTS ON USER <username>
C.SHOW USERS
D.SHOW ROLES
AnswerA

SHOW GRANTS TO USER lists all roles granted directly to the user and, importantly, also reflects roles inherited through the role hierarchy. This gives the compliance officer a complete view of effective role assignments. It is the standard command for auditing user-role relationships and directly answers the requirement without needing to inspect each role individually.

Why this answer

SHOW GRANTS TO USER returns the roles granted to a named user, including those inherited through role hierarchies, which is exactly what a compliance audit needs. SHOW GRANTS ON targets object privileges, SHOW ROLES lists role definitions, and SHOW USERS lists user accounts. Only SHOW GRANTS TO USER maps a user to their effective roles.

Exam trap

The trap here is mixing up TO and ON in the SHOW GRANTS syntax, where TO is for roles granted to a user and ON is for privileges on an object.

3
MCQhard

A user is assigned the 'SECURITYADMIN' role. Which of the following tasks can this user perform?

A.Create and manage warehouses.
B.Modify account-level billing settings.
C.Grant and revoke privileges to other roles.
D.Drop databases without restriction.
AnswerC

The SECURITYADMIN role has the ability to manage grants, create roles, and manage users. This role is central to implementing RBAC within the account. Because it controls access to data and other objects, it must be carefully audited to prevent unauthorized privilege escalation and misuse of permissions.

Why this answer

The SECURITYADMIN role is specifically designed for managing security objects such as roles, grants, and users. This role has the power to grant and revoke privileges to other roles. Keeping this role separate from SYSADMIN (which manages warehouses and databases) is a key governance practice known as Segregation of Duties, ensuring that no single person has unchecked control over both security and data.

Exam trap

Candidates often assume SECURITYADMIN can also manage data warehouses or databases, failing to observe the principle of Segregation of Duties where SYSADMIN manages data and SECURITYADMIN manages access.

4
Multi-Selecthard

A governance team is designing a strategy to classify and protect data across many databases in a Snowflake account. They want a scalable approach that applies protection consistently without editing each table definition manually. Which two capabilities should the team use to accomplish this goal? (Choose two.)

Select 2 answers
A.Grant the SECURITYADMIN role to all analysts so they can manage their own masking policies.
B.Use the ACCOUNT_USAGE.TAG_REFERENCES view to audit which columns carry governance tags.
C.Apply a separate masking policy to every sensitive column using ALTER TABLE for each column.
D.Enable Tri-Secret Secure to automatically classify and mask sensitive columns.
E.Create tags and associate masking policies with them, then apply the tags to columns across tables.
AnswersB, E

TAG_REFERENCES in the ACCOUNT_USAGE schema records tag assignments across the account, including the object, column, and tag involved. Governance teams query it to verify coverage, find untagged sensitive columns, and produce audit evidence. It complements tag-based masking by providing visibility into where tags are applied, which is essential for a scalable classification program.

Why this answer

Tag-based masking and tag reference auditing together form a scalable governance pattern. Associating masking policies with tags means protection follows the tag wherever it is applied, and TAG_REFERENCES provides the visibility needed to confirm coverage and identify gaps. Manual per-column policies and broad role grants do not scale, and encryption features address a different control objective.

Exam trap

The trap here is treating an encryption feature such as Tri-Secret Secure as a data classification and masking mechanism, when it protects data at rest rather than controlling query output.

5
MCQmedium

A company requires all data at rest within Snowflake to be encrypted using a customer-provided key. Which feature should they implement?

A.Always Encrypted.
B.Tri-Secret Secure.
C.Transparent Data Encryption (TDE).
D.Client-Side Encryption.
AnswerB

Tri-Secret Secure combines Snowflake-managed keys with customer-managed keys (CMK) stored in a key management service. This architecture ensures that data remains encrypted with keys that are under the customer's direct control, satisfying stringent compliance and data privacy requirements for sensitive organizational data stored in the cloud.

Why this answer

Tri-Secret Secure is the Snowflake feature that allows customers to manage their own encryption keys, providing an extra layer of security beyond Snowflake's standard managed keys. This is critical for highly regulated industries like finance or healthcare that require strict control over data encryption. By using their own keys, customers ensure that even if Snowflake infrastructure were compromised, the data remains inaccessible without the customer-held key materials.

Exam trap

Candidates often confuse Tri-Secret Secure with standard encryption-at-rest or external tokenization, failing to recognize that Tri-Secret Secure specifically involves customer-managed keys (CMK).

6
MCQeasy

Which object type in Snowflake is required to store a compiled masking policy before it can be applied to a table column?

A.A stored procedure.
B.A masking policy object.
C.A data masking role.
D.A secure function.
AnswerB

A masking policy is a first-class schema object in Snowflake. It defines the logic that determines whether data is returned as-is or masked based on the user's role. Once created, it remains dormant until explicitly assigned to a column, allowing for reusable security definitions across multiple tables.

Why this answer

In Snowflake, masking policies are independent, schema-level objects. Before a policy can be enforced on a column, it must be created using the 'CREATE MASKING POLICY' command. This object encapsulates the logic for transformation and the conditional access rules.

Once defined, the policy is then mapped to one or more columns via an 'ALTER TABLE' statement or during table creation, providing a modular approach to data governance.

Exam trap

Candidates often confuse the masking policy object with the table column itself. They assume applying the policy creates the object, rather than realizing the policy must exist independently beforehand.

7
MCQmedium

A data administrator needs to identify which users have failed to log in successfully over the last 30 days due to authentication errors. Which Snowflake object should they query?

A.The ACCESS_HISTORY view.
B.The LOGIN_HISTORY view.
C.The QUERY_HISTORY view.
D.The SESSIONS view.
AnswerB

LOGIN_HISTORY records all login attempts, including timestamps, usernames, client IP addresses, and the success status of the request. It is the definitive source for auditing authentication failures. Accessing this view requires the ACCOUNTADMIN role or a role with specific privileges granted to view account-level metadata.

Why this answer

The LOGIN_HISTORY table function in the ACCOUNT_USAGE schema provides a detailed audit trail of all connection attempts to the account. By filtering for the IS_SUCCESS column set to 'NO' and specifying the timeframe, the administrator can effectively monitor for potential brute-force attempts or configuration errors. This is a critical component for maintaining a robust security posture and ensuring compliance with organizational access monitoring policies.

Exam trap

Candidates often confuse ACCOUNT_USAGE views with INFORMATION_SCHEMA views, failing to realize INFORMATION_SCHEMA has limited retention periods.

8
MCQhard

A security administrator has created a masking policy that replaces the value of a column with a SHA2 hash for users without the role 'HR_ROLE'. The policy is applied to the 'SSN' column of the 'EMPLOYEES' table. A user with the role 'ANALYST_ROLE' queries the table and sees the hashed values. However, when the same user runs a query that includes the 'SSN' column in a WHERE clause, the query returns no results even though matching records exist. What is the most likely cause of this behavior?

A.The user lacks the SELECT privilege on the table, so the query returns no rows.
B.The masking policy is applied to the column, but the user does not have the privilege to see the original values, so the WHERE clause is evaluated against the masked values, which do not match the search condition.
C.The masking policy is not applied to the WHERE clause, so the original values are used for filtering, but the user cannot see them, resulting in an error.
D.The user's role has not been granted the USAGE privilege on the masking policy, so the policy is bypassed and the original values are used, but the user cannot see them due to column-level security.
AnswerB

Masking policies are applied at query runtime before any filtering occurs. When a user without the unmasking role queries the column, they see the masked value. If they then use that masked value in a WHERE clause, the comparison is against the masked data, not the original. This can lead to unexpected empty results if the search term is the original value.

Why this answer

The correct answer is that the WHERE clause is evaluated against masked values. Masking policies transform data at query time, so any filtering or joining on the masked column uses the masked representation. This is a critical concept: masking does not prevent the column from being used in predicates, but it changes the data used for those predicates, which can lead to unexpected results if the user expects to filter on original values.

Exam trap

The trap here is assuming that masking policies only affect the output of a query and not the evaluation of predicates like WHERE clauses, leading to confusion when queries return no rows.

9
MCQmedium

A security administrator needs to ensure that a set of sensitive columns in an existing table are automatically masked for all users except those with the role 'HR_ADMIN'. The masking must be applied without modifying the underlying data. Which Snowflake feature should be used?

A.Secure Views
B.Object Tagging
C.Row Access Policies
D.Dynamic Data Masking
AnswerD

Dynamic Data Masking uses masking policies to obfuscate column values at query time based on the user's role. It does not alter the stored data. Applying a masking policy to the sensitive columns and granting the policy's exemption to HR_ADMIN achieves the requirement without data changes.

Why this answer

Dynamic Data Masking is the correct feature because it applies masking policies to columns, dynamically masking data based on the user's role at query time without altering stored data. It provides fine-grained control and is designed for this exact scenario of protecting sensitive columns from unauthorized users.

Exam trap

The trap here is confusing object tagging with data masking; tags classify data but do not enforce masking.

10
MCQhard

Refer to the exhibit. A user with the role 'ANALYST_ROLE' cannot see tables inside the 'sales_db.public' schema despite having 'USAGE' on the database. What is the most likely reason for this access issue?

A.The user needs the 'OWNERSHIP' privilege on the schema.
B.The user lacks the 'USAGE' privilege on the schema.
C.The database is not set as the default database for the user.
D.The user is missing the 'MANAGE GRANTS' privilege.
AnswerB

Access to a database does not grant implicit access to its schemas. To browse or query objects within a schema, a user must have the USAGE privilege on that specific schema. Without this privilege, the database contents will appear empty even if the database is accessible.

Why this answer

In Snowflake, the USAGE privilege on a database is insufficient to view objects within schemas; the user must also be granted USAGE on the schema and SELECT on the specific tables or views. This multi-layered privilege requirement is a core component of Snowflake's security model, preventing accidental data exposure by requiring explicit grants at every level of the object hierarchy, from the database down to the individual object.

Exam trap

Candidates incorrectly assume that having USAGE on a database automatically grants visibility into its schemas and tables, overlooking Snowflake's strict requirement for explicit USAGE grants at the schema level.

11
MCQhard

A data governance team wants to classify data in a table using tags. They create a tag 'PII' and apply it to the 'ssn' column. Later, they need to ensure that only users with the 'PII_READER' role can see the actual values, while all other users see a masked value. They decide to use a tag-based masking policy. Which statement accurately describes how tag-based masking policies work in Snowflake?

A.A tag-based masking policy is only enforced when the tag is set on the column and the user querying the data has the APPLY TAG privilege on the tag.
B.A tag-based masking policy is applied to a tag, and any column with that tag automatically inherits the masking policy, provided the tag is set at the column level and the policy is attached to the tag.
C.A tag-based masking policy requires that the tag be applied at the table level, and the policy then masks all columns in the table that contain sensitive data.
D.A tag-based masking policy can only be used with tags that are defined at the account level, not at the schema or database level.
AnswerB

Tag-based masking policies are attached to a tag object. When a column is assigned that tag, the masking policy associated with the tag is automatically applied to the column. This allows centralized management: changing the policy on the tag affects all tagged columns. The policy must be attached to the tag using ALTER TAG ... SET MASKING POLICY, and the tag must be set on the column.

Why this answer

Tag-based masking policies provide a scalable way to protect sensitive data by associating a masking policy with a tag. When a column is tagged, the policy automatically applies. This decouples the masking logic from individual column alterations.

The policy attached to the tag defines the masking condition, often using IS_ROLE_IN_SESSION to allow specific roles to see unmasked data. This approach simplifies governance across many tables and columns.

Exam trap

The trap here is confusing the APPLY TAG privilege with the enforcement of tag-based masking, when enforcement is automatic once the tag and policy are linked.

12
MCQeasy

A Snowflake administrator needs to grant a new analyst the ability to view all tables in the 'SALES' database and query them, but should not be able to modify any data or schema objects. Which sequence of privileges should the administrator grant to meet this requirement with least privilege?

A.Grant the ACCOUNTADMIN role to the analyst, as it includes all necessary privileges for viewing and querying tables.
B.Grant the predefined role PUBLIC to the analyst, as PUBLIC has SELECT on all tables by default.
C.Grant USAGE on the SALES database and SELECT on all tables in the database, but no privileges on schemas.
D.Grant USAGE on the SALES database, USAGE on all schemas in the database, and SELECT on all present and future tables in the database.
AnswerD

This grants the minimum privileges needed: USAGE on the database and schemas allows navigation, and SELECT on tables allows querying. Using GRANT SELECT ON ALL TABLES and ON FUTURE TABLES ensures coverage of existing and new tables. No modification privileges are granted, adhering to least privilege. This is the standard approach for read-only access.

Why this answer

To provide read-only access to all tables in a database, the administrator must grant USAGE on the database, USAGE on the schemas, and SELECT on the tables. Including future tables ensures that new tables are automatically accessible. This set of privileges allows querying without any modification rights, aligning with least privilege.

Omitting schema USAGE or granting excessive roles would fail the requirement.

Exam trap

The trap here is forgetting that schema-level USAGE is required in addition to database USAGE for a user to access tables within schemas.

13
MCQeasy

Which feature in Snowflake allows you to track and audit all SQL queries executed across the entire account?

A.ACCESS_HISTORY.
B.QUERY_HISTORY.
C.SESSION_HISTORY.
D.DATA_TRANSFER_HISTORY.
AnswerB

The QUERY_HISTORY view (and corresponding table function) captures the full SQL statement, the user, the start/end times, and the warehouse used for every query. It is the comprehensive source for auditing account-wide query activity and is essential for security auditing and performance monitoring tasks.

Why this answer

The QUERY_HISTORY table function and the ACCOUNT_USAGE.QUERY_HISTORY view are the primary methods for auditing query activity. These objects record every query submitted, who submitted it, the warehouse used, and the execution time. This is critical for data governance because it provides a forensic trail for compliance, troubleshooting, and understanding how data is accessed and modified over time by different users.

Exam trap

Candidates often look for specific monitoring features or warehouse logs instead of recognizing the built-in QUERY_HISTORY table function and view as the primary auditing mechanism.

14
MCQhard

Refer to the exhibit. If a user with the 'ANALYST' role queries a table protected by this policy, what will they see?

A.The actual email addresses.
B.The string '***@***.com'.
C.An error message indicating insufficient privileges.
D.NULL values.
AnswerB

Because the 'ANALYST' role is not part of the allowed list, the policy execution falls through to the default masking value defined in the ELSE clause. This ensures that sensitive information is properly obscured for unauthorized users, maintaining the integrity of the data governance policy.

Why this answer

The MASKING POLICY uses the CURRENT_ROLE() function to determine visibility. Since the 'ANALYST' role is not included in the 'IN' clause of the CASE statement, the query will evaluate to the ELSE condition. Consequently, the sensitive email data will be replaced by the literal string '***@***.com'.

This demonstrates how attribute-based access control works in Snowflake, ensuring that sensitive data exposure is restricted based on the user's active role.

Exam trap

Candidates often misread conditional masking logic, assuming unauthorized roles see null values or errors instead of the explicit mask output.

15
MCQhard

Refer to the exhibit. What happens if a user with the 'ANALYST' role queries the 'ssn' column protected by this policy?

A.The query fails with an 'Access Denied' error.
B.The column value is replaced with the masked output.
C.The query returns NULL for all rows.
D.The user sees the unmasked ssn data.
AnswerB

The logic dictates that the policy checks if the role is 'HR_ADMIN'. Since the 'ANALYST' role does not match this, the condition is false. Consequently, Snowflake applies the masking function to the 'ssn' column, returning a masked value to the user to protect the PII data.

Why this answer

When a masking policy is applied, Snowflake evaluates the condition at query runtime. If the condition evaluates to FALSE for the current user's role, Snowflake replaces the data with the masked value defined in the policy. This ensures that sensitive data is only revealed to authorized users, protecting the organization from unauthorized data exposure while allowing the schema and query logic to remain unchanged for all users.

Exam trap

Candidates frequently assume that a masking policy will cause the query to fail or return an error for unauthorized users, rather than simply returning the masked, redacted data value.

16
MCQmedium

A security administrator needs to ensure that all data loaded into Snowflake is encrypted using a customer-managed key. Which feature should be configured?

A.Snowflake-managed keys with automatic rotation.
B.Tri-Secret Secure.
C.Always Encrypted feature.
D.Column-Level Security encryption.
AnswerB

Tri-Secret Secure combines a customer-managed key (stored in their cloud provider's key management service) with a Snowflake-managed key. This setup provides an additional layer of security and auditability, ensuring that Snowflake cannot decrypt customer data without access to the customer-provided key material.

Why this answer

Tri-Secret Secure is the Snowflake feature that enables customers to maintain control over their data encryption keys. By combining a customer-managed key with a Snowflake-managed key, the organization ensures that data is encrypted at the storage layer while allowing for key rotation and revocation. This is a vital component for high-compliance industries requiring total control over the data lifecycle and access to encrypted storage buckets.

Exam trap

Candidates often confuse Tri-Secret Secure with standard encryption-at-rest or Time Travel features, failing to recognize it specifically as the customer-managed key integration feature.

17
Multi-Selectmedium

A governance team is implementing data classification in Snowflake and wants to use tags to drive both discovery and enforcement. Which TWO capabilities are provided by Snowflake tags in this context? (Choose two.)

Select 2 answers
A.Tags replace the need for role-based access control by granting privileges to users automatically.
B.Tags automatically encrypt the underlying column data at rest.
C.Tags can be attached to tables, columns, and other objects to record classification metadata.
D.Tags can be used in the WHERE clause of a query to filter rows based on the tag value.
E.A masking policy can be associated with a tag so that any column carrying the tag is automatically masked.
AnswersC, E

Snowflake tags are schema-level objects that can be assigned to a wide range of objects, including tables, columns, views, and warehouses. This makes them suitable for recording classification such as PII or sensitivity level directly on the object. The metadata is then queryable, enabling discovery and reporting, which is a core governance use case for tags in a classification program.

Why this answer

Snowflake tags record classification metadata on objects such as tables and columns, supporting discovery and reporting. They also integrate with masking policies through tag-based masking, so any column carrying the tag is automatically protected. Tags do not encrypt data, do not grant privileges, and cannot filter rows in a query, making those options incorrect for this governance use case.

Exam trap

The trap here is treating tags as an access-control or encryption mechanism, when they are metadata labels that can drive masking but do not grant privileges or encrypt data.

18
MCQmedium

An organization wants to restrict access to Snowflake based on the source IP address of the client application. Which object should the administrator configure to enforce this network-level security?

A.Authentication Policy
B.Access Control Policy
C.Network Policy
D.Session Policy
AnswerC

A Network Policy is the specific Snowflake object designed to control network access. It allows administrators to create a whitelist of allowed IP addresses and a blacklist of blocked IPs, which can be applied at either the account level or to specific individual users.

Why this answer

Network policies are the primary mechanism for restricting access to Snowflake based on IP addresses. By defining allowed and blocked IP ranges, administrators can protect the account from unauthorized access attempts originating from outside the corporate network. This is a foundational governance task that ensures only trusted traffic can reach the Snowflake service, effectively mitigating risks associated with stolen credentials or external malicious activity.

Exam trap

Candidates often look for 'Firewall' settings in Snowflake. They fail to realize that 'Network Policies' is the specific terminology Snowflake uses for IP-based access control and filtering.

19
MCQmedium

A security team at a healthcare company must guarantee that query results returned from a table named PATIENT_RECORDS are filtered based on the department of the user executing the query, without requiring any changes to existing SQL statements. The policy must evaluate a mapping table that lists each user and their department. Which Snowflake object should be created to meet this requirement?

A.A secure view defined over PATIENT_RECORDS that joins the mapping table.
B.A masking policy applied to the DEPARTMENT column of the PATIENT_RECORDS table.
C.A network policy that limits access to the PATIENT_RECORDS table by department IP ranges.
D.A row access policy attached to the PATIENT_RECORDS table that references a mapping table.
AnswerD

A row access policy is a schema-level object that is attached to a table and evaluated at query time, returning a boolean expression that determines which rows are visible. By referencing a mapping table that correlates the CURRENT_USER() or CURRENT_ROLE() with a department, the policy filters rows automatically without any change to the SQL that users execute.

Why this answer

Row access policies are the Snowflake feature designed to filter rows at query time based on the execution context, such as the current user or role. Because the policy is evaluated dynamically and can join against a mapping table, it enforces per-department visibility transparently: existing SQL statements continue to work, and users see only the rows their department is authorized to view.

Exam trap

The trap here is confusing row-level filtering with column-level masking, since both are policy objects attached to a table but only one removes rows from the result set.

20
MCQmedium

A company's security team wants to ensure that when a user with the role PII_ANALYST queries a table, only rows where the region column equals 'US' are returned, but they do not want to create separate copies of the table for each region. Which Snowflake feature should they implement?

A.Object tagging
B.Secure view
C.Column-level masking policy
D.Row access policy
AnswerD

A row access policy is a schema-level object that filters rows returned by a query based on a condition evaluated at query time. It can use functions like CURRENT_ROLE() to dynamically restrict rows. This directly matches the requirement to return only rows where region equals 'US' for the PII_ANALYST role, without duplicating the table.

Why this answer

A row access policy is designed to filter rows based on a condition evaluated at query time, such as the user's role. By attaching a row access policy to the table, the security team can ensure that PII_ANALYST sees only rows where region equals 'US', while other roles may see different rows or all rows. This avoids data duplication and centralizes access control.

Exam trap

The trap here is confusing column-level masking with row-level filtering, assuming that a masking policy can restrict which rows are returned.

21
MCQmedium

A data administrator wants to ensure that all data access is audited. Where can they find a list of all tables accessed by a specific user?

A.QUERY_HISTORY.
B.ACCESS_HISTORY.
C.INFORMATION_SCHEMA.TABLES.
D.LOGIN_HISTORY.
AnswerB

The ACCESS_HISTORY view contains a detailed record of all objects touched by every query. This is the primary source of truth for auditing data access patterns. It provides clear, structured information about which users accessed which tables, views, and columns, making it easy to generate audit reports.

Why this answer

The ACCESS_HISTORY view, introduced to enhance Snowflake's governance capabilities, provides a comprehensive log of every object access event. It records which columns were queried and which tables were accessed by specific users. This tool is essential for compliance, allowing administrators to audit who accessed sensitive data and when, fulfilling regulatory requirements like GDPR or HIPAA that demand strict tracking of data usage.

Exam trap

Candidates often suggest looking at QUERY_HISTORY, which only shows the text of the query, not the specific underlying objects or columns accessed by that query.

22
MCQmedium

An administrator needs to grant the role 'ANALYST' the ability to see all queries executed in the account for auditing purposes. Which privilege should be granted to 'ANALYST'?

A.MONITOR USAGE
B.MANAGE GRANTS
C.SELECT on the QUERY_HISTORY view
D.USAGE on the database
AnswerA

The MONITOR USAGE privilege on the account allows a role to view usage information, including queries executed in the account. Granting this privilege to 'ANALYST' enables them to access the QUERY_HISTORY views and monitor all queries, which is necessary for auditing.

Why this answer

To allow a role to view all queries executed in the account, the MONITOR USAGE privilege must be granted. This privilege provides access to the ACCOUNT_USAGE schema, including the QUERY_HISTORY view, which contains records of all queries. Other privileges like USAGE on a database or MANAGE GRANTS do not grant account-wide query visibility.

Exam trap

The trap here is assuming that SELECT on the QUERY_HISTORY view can be granted directly; ACCOUNT_USAGE views require the MONITOR USAGE privilege instead.

23
MCQmedium

When designing a role-based access control (RBAC) model, which THREE of the following are recommended best practices?

A.Grant privileges to roles, not directly to users.
B.Follow the principle of least privilege.
C.Implement a hierarchical role structure.
D.Use the ACCOUNTADMIN role for daily data analysis.
E.Assign all users the same 'PUBLIC' role for simplicity.
AnswerA, B, C

Directly granting privileges to users makes auditing and management extremely difficult. Assigning privileges to roles creates a centralized and reusable set of permissions. When a user changes roles, you simply update their role assignment rather than manually modifying permissions on every individual object in the system.

Why this answer

A robust RBAC model relies on hierarchical structures to simplify management and minimize errors. By granting privileges to roles rather than users, and nesting roles logically, you create a scalable security architecture. These best practices ensure that permissions are easy to audit, follow the principle of least privilege, and prevent 'privilege creep,' where users accumulate excess access rights that are never revoked over time as their roles change.

Exam trap

Candidates often mistakenly believe that assigning privileges directly to users is acceptable for small teams. This leads to poor scalability and makes auditing permissions extremely difficult as the organization grows.

24
MCQhard

A company has a table named customer_orders that contains a column storing the customer's full name. A masking policy has been applied to that column. The policy uses CURRENT_ROLE() to compare the executing role against a list of roles allowed to see the raw value. A user with a role that is not in the allowed list runs a query that includes the column in an ORDER BY clause. What does the user see?

A.The user sees the raw value in the result set but the sort is performed on the masked value.
B.The user sees the masked value in the result set and the sort is performed on the masked value.
C.The user sees the masked value in the result set, but the sort is performed on the raw value because ORDER BY is evaluated before masking.
D.The query fails because masking policies cannot be applied to columns used in ORDER BY.
AnswerB

When a masking policy is attached to a column, every reference to that column in a query is replaced by the policy expression for users who are not authorized to see the raw data. This includes references in the select list, WHERE clause, and ORDER BY clause. Therefore the user sees the masked value and the ordering is computed on the masked representation, not the original name.

Why this answer

A masking policy rewrites every reference to the protected column for unauthorized users, including references in ORDER BY. The user therefore sees the masked value and sorting is based on that masked value. The policy is not bypassed by placing the column in a sort clause.

Exam trap

The trap here is believing that a masked column can still influence sorting on its raw value, when the policy replaces the column reference everywhere.

25
MCQeasy

What is the primary purpose of a 'Tag' in Snowflake from a data governance perspective?

A.To increase query performance for joins.
B.To identify and track sensitive data for compliance.
C.To define the access level of a user.
D.To compress data for storage savings.
AnswerB

Tags are essential for data discovery and governance. They allow administrators to mark tables or columns (e.g., 'PII' = 'True') and then use account-level views to query those tags. This makes it easy to audit sensitive data locations and verify compliance with internal and external policies.

Why this answer

Tags in Snowflake are used to label and categorize data objects for governance, reporting, and cost allocation. By applying a tag to a table or column, an administrator can track sensitive data across the entire account. This allows for automated reporting on data lineage and compliance, enabling teams to quickly identify where PII or other critical information resides for regulatory auditing and risk management purposes.

Exam trap

Candidates frequently confuse tags with access control privileges or data masking policies, incorrectly believing that tags themselves restrict access rather than just labeling or categorizing data objects for governance.

26
MCQeasy

A user with the role 'SYSADMIN' wants to grant the privilege to create databases to a custom role 'DB_CREATOR'. Which command should the SYSADMIN execute?

A.GRANT CREATE DATABASE ON DATABASE mydb TO ROLE DB_CREATOR;
B.GRANT CREATE DATABASE TO ROLE DB_CREATOR;
C.GRANT USAGE ON DATABASE mydb TO ROLE DB_CREATOR;
D.GRANT CREATE DATABASE ON ACCOUNT TO ROLE DB_CREATOR;
AnswerD

The CREATE DATABASE privilege is granted at the account level. SYSADMIN has the authority to grant this privilege to other roles. The correct syntax is GRANT CREATE DATABASE ON ACCOUNT TO ROLE DB_CREATOR; This allows the role to create databases within the account.

Why this answer

The CREATE DATABASE privilege is an account-level privilege, so it must be granted with the ON ACCOUNT clause. The SYSADMIN role has the authority to grant this privilege. The correct command is GRANT CREATE DATABASE ON ACCOUNT TO ROLE DB_CREATOR;

Exam trap

The trap here is omitting the ON ACCOUNT clause or trying to grant on a database object, which is invalid for account-level privileges.

27
MCQmedium

An administrator discovers that a former employee's user account still exists and is still granted the ANALYST_ROLE. The administrator needs to immediately prevent the account from authenticating while preserving the account and its historical query metadata for an ongoing audit. Which action should the administrator take?

A.Run ALTER USER ... SET DISABLED = TRUE.
B.Run DROP USER on the former employee's account.
C.Run ALTER USER ... SET PASSWORD = NULL.
D.Run REVOKE ROLE ANALYST_ROLE FROM USER on the former employee's account.
AnswerA

Setting DISABLED = TRUE on a user prevents that user from authenticating to Snowflake while leaving the account, its grants, and its metadata intact. This is the documented way to suspend access immediately during an investigation or offboarding without losing audit history, and it can be reversed later if needed by setting DISABLED = FALSE.

Why this answer

Disabling a user with ALTER USER ... SET DISABLED = TRUE immediately blocks authentication while keeping the account, its grants, and its metadata available for audit. Dropping the user or altering credentials does not preserve the account in the desired state, and revoking a role only removes one privilege path rather than blocking sign-in.

Exam trap

The trap here is equating credential removal with account disablement, when Snowflake provides a dedicated DISABLED property that blocks all authentication methods.

28
MCQeasy

Which of the following describes the correct order of precedence for role inheritance in Snowflake?

A.Object-level privileges override role-level inheritance.
B.Privileges are inherited only from the ACCOUNTADMIN role.
C.Parent roles inherit all privileges granted to their child roles.
D.Child roles always inherit the privileges of the parent role.
AnswerC

In Snowflake's hierarchical model, when a role is granted to another, the parent role automatically inherits all privileges assigned to the child role. This allows administrators to manage permissions efficiently by building chains of roles that correspond to the structural requirements of the organization's data access needs.

Why this answer

Snowflake utilizes a hierarchical RBAC model where privileges are additive. When a role is granted to another role, the parent role inherits all privileges assigned to the child role. This design allows for the creation of functional roles that map to business units or job tasks, ensuring that permissions are managed efficiently and transparently throughout the entire organizational structure of the account.

Exam trap

Candidates frequently reverse role inheritance direction, incorrectly assuming child roles inherit privileges from parent roles instead of the reverse.

29
MCQeasy

Which of the following describes the purpose of 'Time Travel' from a data governance perspective?

A.To improve query performance by caching historical results.
B.To provide a mechanism for restoring deleted or altered data.
C.To hide sensitive data from users who do not have access.
D.To manage the lifecycle of virtual warehouses automatically.
AnswerB

Time Travel enables users to query data as it existed at any point within the retention period. This allows for the easy recovery of dropped tables or modified rows, providing an essential layer of protection against accidental data loss and supporting organizational data integrity and compliance requirements.

Why this answer

Time Travel allows for the recovery of data that was accidentally deleted or modified, serving as a critical safety net for data governance. By enabling the retention of historical data, Snowflake empowers administrators to restore states after human error, minimizing data loss and operational downtime. This functionality is essential for maintaining data integrity and business continuity, ensuring that the organization can reliably recover from unintended data lifecycle events without needing to restore from full backups.

Exam trap

Candidates often confuse Time Travel with disaster recovery or full system backups, failing to recognize that its primary design purpose is the quick recovery of accidentally deleted, updated, or dropped database objects.

30
MCQhard

A data steward needs to ensure that a column containing email addresses is masked for all users except those with the role 'COMPLIANCE_OFFICER'. The masking should show a fixed string '****' for unauthorized users. Which Snowflake feature should be used?

A.Masking policy
B.Object tagging
C.Secure view
D.Row access policy
AnswerA

A masking policy is a schema-level object that can be applied to a column to dynamically mask its data based on the user's role. You can define a policy that returns '****' for all roles except 'COMPLIANCE_OFFICER'. This precisely meets the requirement of column-level masking for unauthorized users.

Why this answer

A masking policy in Snowflake allows column-level security by dynamically masking data based on the user's role or other conditions. By applying a masking policy to the email column that returns '****' for all roles except 'COMPLIANCE_OFFICER', the data steward ensures that only authorized users see the actual email addresses. This is the correct feature for column-level masking.

Exam trap

The trap here is confusing row access policies with masking policies; row access policies filter rows, not mask column values.

31
MCQmedium

An organization requires that specific sensitive columns in a table be masked for all users except those in the 'DATA_STEWARD' role. Which mechanism should the architect implement to enforce this policy efficiently?

A.Apply a row-level security policy to the table.
B.Create secure views that use a CASE statement to filter columns.
C.Apply a masking policy using the IS_ROLE_IN_SESSION function.
D.Use data replication to create a separate table for stewards.
AnswerC

Dynamic Data Masking policies are the native Snowflake feature for this requirement. Using IS_ROLE_IN_SESSION allows the policy to check the current session's role effectively. This is the standard, scalable approach for enforcing column-level security across an account, ensuring that sensitive data is protected regardless of how it is queried.

Why this answer

Dynamic Data Masking (DDM) provides a centralized way to protect sensitive data by applying masking policies to columns. By using the IS_ROLE_IN_SESSION function within the policy, the system evaluates the user's active role dynamically during query execution. This ensures that only members of the DATA_STEWARD role see unmasked data, while others see the masked output, maintaining governance consistency without needing to physically alter the underlying data storage or create multiple filtered views.

Exam trap

Candidates often assume that creating multiple views with different permissions is the correct approach, failing to realize that DDM is more efficient, centralized, and avoids the maintenance overhead of managing numerous views.

32
MCQmedium

A user with the role DATA_ANALYST has been granted the USAGE privilege on a database and schema, but when they try to query a table in that schema, they receive an error that the table does not exist. The table exists and is owned by the role DATA_ENGINEER. What is the most likely cause of this issue?

A.The table is owned by DATA_ENGINEER, and ownership transfers all privileges, so DATA_ANALYST cannot access it.
B.The DATA_ANALYST role lacks the SELECT privilege on the table.
C.The DATA_ANALYST role does not have USAGE on the database and schema.
D.The table is a secure view, and secure views require additional privileges.
AnswerB

In Snowflake, having USAGE on a database and schema allows you to see the schema and potentially list objects, but to query a table, you need the SELECT privilege on that table. Without SELECT, the table appears as if it does not exist when queried. The error message 'table does not exist' is often misleading; it can also mean the user lacks privileges. Granting SELECT on the table to DATA_ANALYST would resolve the issue.

Why this answer

In Snowflake, to query a table, a role must have the SELECT privilege on that table. Having USAGE on the database and schema only allows navigation and listing. Without SELECT, the table is effectively inaccessible, and Snowflake returns a 'table does not exist' error to avoid leaking information.

Granting SELECT to DATA_ANALYST resolves the problem. Ownership by another role does not prevent granting privileges.

Exam trap

The trap here is interpreting the 'table does not exist' error literally, when it often indicates a missing privilege rather than a missing object.

33
MCQmedium

A user with the role 'ANALYST' needs to be able to see the definition of a secure view named 'sales_view' in the 'sales_db' database. The view owner has granted SELECT on the view to ANALYST. However, when ANALYST runs SHOW VIEWS, the view definition is not visible. What is the most likely cause?

A.The ANALYST role needs the MONITOR privilege on the view to see its definition.
B.The ANALYST role lacks the USAGE privilege on the database and schema.
C.The view definition is only visible if the user has the SELECT privilege on all underlying tables.
D.Secure views do not expose their definition to users who do not have the OWNERSHIP privilege on the view.
AnswerD

Secure views are designed to hide the view definition from users who do not own the view. Even with SELECT privilege, non-owners cannot see the view's SQL definition. This is a security feature to prevent exposure of underlying data or logic.

Why this answer

Secure views intentionally hide their definition from users who do not own the view. Even with SELECT privilege, non-owners cannot see the view's SQL definition. This is a key security feature of secure views.

Exam trap

The trap here is assuming that SELECT privilege includes the right to see the view definition; for secure views, only the owner can see it.

34
MCQmedium

What is the primary function of the 'SECURITYADMIN' role in Snowflake's RBAC model?

A.Creating and managing virtual warehouses.
B.Managing access control, including users and roles.
C.Granting ownership of data objects to users.
D.Monitoring account-level credit consumption.
AnswerB

The SECURITYADMIN role is designed to handle all aspects of user and role management, including creating roles, granting them to users, and managing privileges. It is the primary vehicle for implementing the organization's security and access control policies in compliance with the principle of least privilege.

Why this answer

The SECURITYADMIN role is dedicated to the management of users, roles, and grants. By separating administrative duties into distinct roles like SECURITYADMIN (for access) and SYSADMIN (for objects), Snowflake enables a clear separation of concerns. This is a critical governance practice that prevents a single individual from having both the ability to create objects and the ability to assign permissions to those objects, thereby reducing the risk of unauthorized access.

Exam trap

Candidates often confuse SECURITYADMIN with SYSADMIN, incorrectly believing that SECURITYADMIN creates physical objects like warehouses and databases rather than managing users, roles, and privileges.

35
MCQmedium

What is the primary role of the 'ORGANIZATIONADMIN' role in Snowflake?

A.To manage data access within a single account.
B.To perform account-level management across the organization.
C.To query all data across the entire organization.
D.To assign roles to users within a single database.
AnswerB

The ORGADMIN role is designed specifically for managing multiple accounts within an organization. It allows for creating new accounts, managing replication, and viewing usage metrics across the entire enterprise. It is a critical role for administrators who need a global view and control over their entire Snowflake ecosystem.

Why this answer

The ORGANIZATIONADMIN (ORGADMIN) role is responsible for managing tasks at the account-level across the entire organization. This includes creating and managing multiple accounts, monitoring organizational usage, and configuring global replication. This role is highly privileged and exists above the ACCOUNTADMIN level, allowing for centralized control over the enterprise's Snowflake footprint while maintaining segregation between different business units or environments within the same organization.

Exam trap

Candidates often confuse ORGADMIN with ACCOUNTADMIN, mistakenly believing that ACCOUNTADMIN has the authority to manage organizational-level settings like cross-account replication or multi-account billing.

36
MCQhard

What is the consequence of applying a Row Access Policy to a table that already contains existing data?

A.The data must be reloaded to apply the policy.
B.Existing queries will continue to return all rows.
C.The policy is applied immediately to all subsequent queries.
D.The table must be dropped and recreated.
AnswerC

Row Access Policies are enforced at the query level. As soon as the policy is successfully attached to the table, the Snowflake engine will apply the filtering criteria to every query executed against that table, ensuring consistent security enforcement regardless of when the data was originally loaded.

Why this answer

When a Row Access Policy is applied to an existing table, the policy immediately takes effect for all subsequent queries. Any user who runs a query against the table will only see the rows allowed by the policy logic. This is critical for governance because it provides an immediate, retroactive enforcement of security rules without needing to migrate or transform the existing data in the table, ensuring compliance from the moment the policy is activated.

Exam trap

Candidates often mistakenly believe that applying a Row Access Policy requires reloading data or recreating the table, failing to realize that Snowflake applies policies retroactively to all existing data immediately.

37
MCQmedium

A company wants to enforce that all data in a specific schema is protected by a data classification tag before it can be queried by analysts. The security team has created a tag named DATA_CLASS and a masking policy associated with that tag. Analysts report they can still see raw values in some columns. What is the most likely cause?

A.The masking policy uses CURRENT_ROLE() and the analysts are using a role that is not listed in the policy's allowed roles.
B.The masking policy was created but not associated with the DATA_CLASS tag.
C.The analysts have been granted the APPLY MASKING POLICY privilege on the tag.
D.The DATA_CLASS tag was created in a different database than the schema being protected.
AnswerB

A tag-based masking policy only takes effect when the policy is attached to the tag. Creating the policy and the tag separately does not link them. If the policy is not set on the tag, columns carrying the tag are not masked. The security team must run ALTER TAG ... SET MASKING POLICY to associate the policy with the tag so that all tagged columns are protected.

Why this answer

Tag-based masking requires the masking policy to be attached to the tag. Creating both objects without linking them leaves tagged columns unmasked. The fix is to associate the policy with the tag so that every column carrying the tag is automatically protected.

Exam trap

The trap here is assuming that creating a tag and a masking policy is sufficient, when the policy must be explicitly attached to the tag.

38
Multi-Selecthard

A governance team needs to implement data classification and access control for a new table containing sensitive data. They want to (1) tag columns with a sensitivity level, and (2) enforce that only users with a specific role can see the unmasked data. Which two Snowflake features should they use together to achieve these goals? (Choose two.)

Select 2 answers
A.Network policy
B.Row access policy
C.Secure view
D.Object tagging
E.Masking policy
AnswersD, E

Object tagging allows the governance team to assign tags to columns, such as sensitivity level, for classification and tracking. Tags can be used to document data sensitivity and can be leveraged in policies. They are essential for the first requirement of tagging columns with a sensitivity level. Tags alone do not enforce access control, but they provide metadata for governance.

Why this answer

Object tagging is used to classify columns with sensitivity levels, providing metadata for governance. Masking policies enforce column-level access control by dynamically masking data based on the user's role. Together, they satisfy both requirements: tagging for classification and masking for access enforcement.

Other features like row access policies or secure views do not provide the needed column-level masking and tagging combination.

Exam trap

The trap here is confusing row-level filtering with column-level masking, or assuming that tagging alone can enforce access control.

39
MCQhard

A data governance lead is configuring tag-based masking so that columns tagged with a PII classification are automatically protected. The lead creates a tag named PII_CLASSIFICATION and a masking policy, then applies the tag to several columns. Later, an analyst queries a tagged column and sees unmasked values. The masking policy was attached to the tag using ALTER TAG ... SET MASKING POLICY. What is the most likely cause?

A.The masking policy was attached to the tag but the tag was not applied to the specific column at the column level.
B.Tag-based masking requires the tag to be a system tag rather than a user-defined tag.
C.The masking policy must be attached to the tag before the tag is created on the column, and the order was reversed.
D.The analyst's role has the ACCOUNTADMIN role granted, which bypasses all masking policies.
AnswerA

Tag-based masking only takes effect on columns that actually carry the tag. Creating the tag and associating the masking policy with the tag is not sufficient; the tag must be set on each column, for example with ALTER TABLE ... MODIFY COLUMN ... SET TAG. If the tag was applied only to the table or never set on the column, queries against that column return unmasked data, which matches the observed behavior.

Why this answer

Tag-based masking requires two conditions to be satisfied: the masking policy must be associated with the tag, and the tag must be applied to the target column. If the tag was only created or applied at the table level rather than the column level, Snowflake has no tagged column to protect, so queries return the original values. Verifying the column's tag assignment resolves the issue.

Exam trap

The trap here is assuming that associating a masking policy with a tag automatically protects every column, when the tag must still be applied to each column individually.

40
MCQmedium

Which administrative role should be used to manage the lifecycle of warehouses and databases, while strictly avoiding the management of users and roles?

A.ACCOUNTADMIN
B.SYSADMIN
C.USERADMIN
D.SECURITYADMIN
AnswerB

The SYSADMIN role is specifically designed for the administration of objects such as databases, schemas, and warehouses. It has the necessary permissions to manage these objects but lacks the ability to create users or modify security roles, perfectly fulfilling the requirement for a separation of duties in governance.

Why this answer

The SYSADMIN role is the standard role for creating and managing data objects such as databases, schemas, tables, and warehouses. It is distinct from the SECURITYADMIN role, which manages user identities and permissions. This separation of duties is a fundamental pillar of Snowflake's security architecture, ensuring that operational and administrative control over data objects is kept separate from the management of user access, thereby mitigating the risk of privilege escalation and internal misuse.

Exam trap

Candidates frequently select ACCOUNTADMIN out of habit, failing to respect the principle of least privilege required by the question to avoid managing users and roles.

41
MCQmedium

An administrator needs to restrict access to sensitive PII data. Which TWO of the following are valid approaches to implement governance in Snowflake?

A.Apply a Row Access Policy to the table.
B.Implement column-level Dynamic Data Masking.
C.Use physical data partitioning to store PII in separate tables.
D.Assign the ACCOUNTADMIN role to all data stewards.
E.Export data to an encrypted S3 bucket for security.
AnswerA, B

Row Access Policies are a native governance feature that restricts the number of rows returned by a query based on the current user's role or attributes. This is a primary tool for ensuring users only view data relevant to their specific department or geographic region.

Why this answer

Snowflake provides several layers of defense-in-depth to secure sensitive information. Row Access Policies filter which rows a user can see, while Dynamic Data Masking transforms column data based on user privileges. Using these in combination allows architects to build a highly restrictive environment where users only interact with the exact data subsets and column values they are authorized to access, complying with strict regulatory data privacy standards.

Exam trap

Candidates frequently confuse row access policies and data masking with traditional database views or warehouse-level resource monitors used for cost control.

42
MCQeasy

A data steward needs to review the history of changes made to a table, including which columns were added or dropped and when, for an audit that covers the past 60 days. The table is in a database that has a data retention period of 90 days. Which Snowflake feature should the steward use to retrieve this information?

A.The ACCESS_HISTORY view in the ACCOUNT_USAGE schema.
B.The ACCOUNT_USAGE.QUERY_HISTORY view filtered by the table name.
C.Time Travel by querying the table with AT (TIMESTAMP => ...) for each day in the audit period.
D.The object change history accessible through the ACCOUNT_USAGE schema, such as the COLUMNS view with its deleted and change tracking columns.
AnswerD

The ACCOUNT_USAGE schema includes views that track object metadata over time. The COLUMNS view, for example, records column definitions and marks deleted columns, allowing a steward to see when columns were added or dropped. This provides the structured change history needed for the audit, independent of the table's data retention period.

Why this answer

Object change history in the ACCOUNT_USAGE schema records metadata changes such as column additions and drops, with timestamps and deleted markers. This is the correct source for auditing schema evolution. Time Travel and query or access history views serve different purposes and do not provide a structured column change log.

Exam trap

The trap here is confusing Time Travel, which returns past data, with object change history, which records metadata changes.

43
MCQhard

Refer to the exhibit. User 'jdoe' holds the 'manager' role. Which privileges does 'jdoe' possess regarding roles and data access?

A.jdoe has the privileges of the manager role only.
B.jdoe has the privileges of the manager and analyst roles.
C.jdoe must explicitly switch to the analyst role to see its data.
D.jdoe only has access to objects created by the analyst role.
AnswerB

The GRANT command establishes a hierarchy where the parent role inherits all privileges of the child role. Since jdoe holds the manager role, and manager holds the analyst role, jdoe inherently possesses the combined set of privileges from both roles, enabling access to all underlying objects.

Why this answer

Snowflake's role-based access control (RBAC) supports hierarchy. When 'analyst' is granted to 'manager', and 'manager' is granted to 'jdoe', 'jdoe' inherits all privileges assigned to both the 'manager' and 'analyst' roles. This inheritance model allows for complex organizational structures while keeping grant management simple.

It is crucial for governance, as it prevents over-privileging by allowing admins to nest permissions logically rather than assigning every individual role directly to users.

Exam trap

Candidates assume users only hold the privileges of their directly assigned role, ignoring multi-level hierarchical grants where roles are nested.

44
MCQmedium

A data engineer needs to ensure that sensitive PII columns are masked for all users except for a specific group of HR analysts. Which Snowflake feature is the most efficient and scalable solution to implement this requirement?

A.Create secure views for every user role in the account.
B.Implement Dynamic Data Masking policies on the sensitive columns.
C.Use the UNMASK function in every query selecting sensitive data.
D.Apply Row-Level Security to hide rows containing sensitive PII.
AnswerB

Dynamic Data Masking provides a centralized and scalable way to protect sensitive data. By defining a policy that checks for the HR role, security administrators can ensure that data is masked for general users while remaining visible to HR, all without modifying the physical data stored in the tables.

Why this answer

Dynamic Data Masking (DDM) allows centralized management of data access policies based on the user's role. By attaching a masking policy to a column, Snowflake automatically evaluates the user's role at query runtime. This approach is superior to static masking or manual view management because it centralizes governance, minimizes data duplication, and ensures that security policies remain consistent regardless of how the user accesses the underlying table.

Exam trap

Candidates often suggest using Row Access Policies or separate tables for different roles, which creates unnecessary data redundancy and significant maintenance challenges compared to using DDM.

45
MCQmedium

Which of the following describes the purpose of 'Object Tagging' in Snowflake?

A.To encrypt sensitive data at the column level.
B.To logically group objects for discovery and compliance reporting.
C.To restrict user access based on their network location.
D.To automatically optimize query performance.
AnswerB

Object tagging provides a mechanism to attach labels to objects, which can then be used to query and report on the data. For example, a tag like 'PII: True' helps security teams identify and audit all sensitive columns across the entire account for compliance documentation.

Why this answer

Object tagging allows administrators to assign metadata to objects (like tables, columns, or warehouses) to facilitate discovery, tracking, and governance. Tags are useful for identifying sensitive data, tracking costs, or enforcing compliance. This is a crucial feature for large organizations that need to report on data usage, lifecycle, and sensitivity across thousands of objects, making it easier to manage and audit data at scale.

Exam trap

Candidates often think tags are used for performance optimization or data clustering. They fail to recognize that tags are primarily metadata tools for discovery, compliance, and cost reporting purposes.

46
MCQmedium

An administrator wants to ensure that a specific role can only access Snowflake from the corporate office IP range. Which tool should they use?

A.Row Access Policies.
B.Granting specific network privileges.
C.Network Policies.
D.Setting a Session Policy.
AnswerC

Network Policies allow administrators to specify a list of IP addresses that are permitted (or blocked) from connecting to the Snowflake account. These policies can be applied globally or to specific users, providing a flexible and secure way to enforce location-based access controls.

Why this answer

Network Policies are the mechanism to restrict access by IP address. By creating a policy and applying it to a specific user or the entire account, administrators can ensure that connections only succeed from authorized locations. This is a foundational governance practice to protect against unauthorized access from external or insecure network locations, effectively creating a perimeter around the data platform.

Exam trap

Candidates often think they can restrict access by role using IP addresses directly in the role definition. They miss that Network Policies are global or user-level objects, not role-level objects.

47
MCQmedium

A security administrator for a Snowflake account needs to grant the role FINANCE_ANALYST to a user named Priya. The administrator also wants Priya to be able to grant FINANCE_ANALYST to other users in the future. Which SQL statement should the administrator execute?

A.GRANT ROLE FINANCE_ANALYST TO USER priya;
B.ALTER USER priya SET DEFAULT_ROLE = FINANCE_ANALYST;
C.GRANT ROLE FINANCE_ANALYST TO ROLE priya;
D.GRANT ROLE FINANCE_ANALYST TO USER priya WITH GRANT OPTION;
AnswerD

This statement grants the role to the user and includes WITH GRANT OPTION, which authorizes Priya to subsequently grant that same role to other users or roles. Snowflake supports this clause for role grants, enabling delegated administration without assigning a broader security role.

Why this answer

Delegating role administration requires the WITH GRANT OPTION clause on a GRANT ROLE statement directed at the user. This lets the grantee grant that specific role onward without needing SECURITYADMIN or USERADMIN. Simply granting the role or altering the default role does not confer grant authority.

Exam trap

The trap here is assuming that granting a role automatically lets the grantee grant it to others; delegation requires the explicit WITH GRANT OPTION clause.

Ready to test yourself?

Try a timed practice session using only Account Mgmt Data Governance questions.