COF-C03 Account Management and Data Governance Practice Question
What is the primary function of the 'SECURITYADMIN' role in Snowflake's RBAC model?
⚠ Common exam trap
Candidates often confuse SECURITYADMIN with SYSADMIN, incorrectly believing that SECURITYADMIN creates physical objects like warehouses and databases rather than managing users, roles, and privileges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing access control, including users and roles.
The SECURITYADMIN role is dedicated to the management of users, roles, and grants. By separating administrative duties into distinct roles like SECURITYADMIN (for access) and SYSADMIN (for objects), Snowflake enables a clear separation of concerns. This is a critical governance practice that prevents a single individual from having both the ability to create objects and the ability to assign permissions to those objects, thereby reducing the risk of unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Creating and managing virtual warehouses.
Why it's wrong here
Managing virtual warehouses is a responsibility of the SYSADMIN role or a dedicated warehouse administrator. The SECURITYADMIN role is specifically focused on identity and access management, not the operational side of compute resource provisioning or the monitoring of query execution performance within the account.
- ✓
Managing access control, including users and roles.
Why this is correct
The SECURITYADMIN role is designed to handle all aspects of user and role management, including creating roles, granting them to users, and managing privileges. It is the primary vehicle for implementing the organization's security and access control policies in compliance with the principle of least privilege.
- ✗
Granting ownership of data objects to users.
Why it's wrong here
While SECURITYADMIN can manage grants, it does not typically handle the ownership transfer of objects, which is primarily a function of the SYSADMIN role. SECURITYADMIN focuses on the security and permission layer, whereas SYSADMIN focuses on the lifecycle and administration of the data objects themselves.
- ✗
Monitoring account-level credit consumption.
Why it's wrong here
Credit consumption monitoring is the responsibility of the ACCOUNTADMIN role, as it is a global account setting that relates to billing. The SECURITYADMIN role does not have the permissions required to view or modify billing-related configurations or resource monitors that control credit usage in the account.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.