Which TWO of the following statements are true regarding the ACCOUNTADMIN role?
Trap 1: It is the only role that can manage data in every database.
While ACCOUNTADMIN has implicit access, it is not the only role that can manage data. Other roles with appropriate grants can manage databases. Best practice dictates that data management should be delegated to functional roles rather than using the highest-privileged account for routine data operations.
Trap 2: It should be used for daily data warehouse maintenance.
Using ACCOUNTADMIN for daily maintenance is a security risk. Best practices require using the Principle of Least Privilege. Daily tasks should be performed by roles specifically assigned for those operations, such as SYSADMIN, to prevent accidental modification of security settings or deletion of critical objects.
Trap 3: It can bypass all Row Access Policies by default.
Even the ACCOUNTADMIN role is subject to Row Access Policies. If a policy is applied to a table, the ACCOUNTADMIN will see the filtered data based on the policy definition. This ensures that even system administrators are governed by the security rules defined by the organization.
- A
It is the only role that can manage data in every database.
Why it fails: While ACCOUNTADMIN has implicit access, it is not the only role that can manage data. Other roles with appropriate grants can manage databases. Best practice dictates that data management should be delegated to functional roles rather than using the highest-privileged account for routine data operations.
- B
It can manage billing and account-level settings.
The ACCOUNTADMIN role has the specific privilege to view and manage billing, usage, and account-wide settings like parameter modifications. These tasks are restricted to this role because they affect the financial and operational stability of the entire Snowflake account across all users and workloads.
- C
It should be used for daily data warehouse maintenance.
Why it fails: Using ACCOUNTADMIN for daily maintenance is a security risk. Best practices require using the Principle of Least Privilege. Daily tasks should be performed by roles specifically assigned for those operations, such as SYSADMIN, to prevent accidental modification of security settings or deletion of critical objects.
- D
It is the only role that can grant the SECURITYADMIN role to users.
The SECURITYADMIN role manages security-related tasks, but only the ACCOUNTADMIN (or a user with similar high-level grants) can initially create or assign the SECURITYADMIN role to other users. This prevents unauthorized escalation of privileges by limiting who can grant high-level administrative powers.
- E
It can bypass all Row Access Policies by default.
Why it fails: Even the ACCOUNTADMIN role is subject to Row Access Policies. If a policy is applied to a table, the ACCOUNTADMIN will see the filtered data based on the policy definition. This ensures that even system administrators are governed by the security rules defined by the organization.