COF-C03 Account Management and Data Governance Practice Question
When designing a role-based access control (RBAC) model, which THREE of the following are recommended best practices?
⚠ Common exam trap
Candidates often mistakenly believe that assigning privileges directly to users is acceptable for small teams. This leads to poor scalability and makes auditing permissions extremely difficult as the organization grows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant privileges to roles, not directly to users.
A robust RBAC model relies on hierarchical structures to simplify management and minimize errors. By granting privileges to roles rather than users, and nesting roles logically, you create a scalable security architecture. These best practices ensure that permissions are easy to audit, follow the principle of least privilege, and prevent 'privilege creep,' where users accumulate excess access rights that are never revoked over time as their roles change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant privileges to roles, not directly to users.
Why this is correct
Directly granting privileges to users makes auditing and management extremely difficult. Assigning privileges to roles creates a centralized and reusable set of permissions. When a user changes roles, you simply update their role assignment rather than manually modifying permissions on every individual object in the system.
- ✓
Follow the principle of least privilege.
Why this is correct
Granting only the bare minimum permissions necessary for a user to complete their tasks reduces the impact of compromised credentials. This minimizes the risk of unauthorized data access, accidental data deletion, or unauthorized system configuration changes within the Snowflake environment by restricting the scope of each role.
- ✓
Implement a hierarchical role structure.
Why this is correct
A hierarchical structure allows for inheriting privileges from lower-level roles (e.g., 'Analyst' inherits from 'Reader'). This significantly reduces administrative overhead by allowing you to define broad access rights at the top level and add specific, granular permissions only where they are actually needed in the hierarchy.
- ✗
Use the ACCOUNTADMIN role for daily data analysis.
Why it's wrong here
Using ACCOUNTADMIN for daily tasks is a severe security risk. It provides unrestricted power to manage the entire account, including billing, user management, and data access. It should be reserved strictly for administrative tasks that cannot be performed by any other role to maintain system integrity.
- ✗
Assign all users the same 'PUBLIC' role for simplicity.
Why it's wrong here
While every user is automatically part of the PUBLIC role, relying on it for access control is a security failure. The PUBLIC role should have minimal to no permissions. Granting permissions to PUBLIC grants them to everyone, which completely undermines the intent of a secure RBAC model.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.