nerdexam
Snowflake

COF-C02 · Question #308

Who can activate and enforce a network policy for all users in a Snowflake account? (Select TWO).

The correct answer is B. A user with a SECURITYADMIN or higher role E. A role that has the ownership of the network policy. Applying a network policy at the account level (affecting all users) requires either: (B) SECURITYADMIN role or higher (ACCOUNTADMIN), as this is an account-level security operation; or (E) a role that has OWNERSHIP of the network policy object. USERADMIN (option A) does not…

Account Access and Security

Question

Who can activate and enforce a network policy for all users in a Snowflake account? (Select TWO).

Options

  • AA user with an USERADMIN or higher role
  • BA user with a SECURITYADMIN or higher role
  • CA role that has been granted the ATTACH POLICY privilege
  • DA role that has the NETWORK_POLlCY account parameter set
  • EA role that has the ownership of the network policy

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    71% (20)
  • C
    14% (4)
  • D
    7% (2)

Explanation

Applying a network policy at the account level (affecting all users) requires either: (B) SECURITYADMIN role or higher (ACCOUNTADMIN), as this is an account-level security operation; or (E) a role that has OWNERSHIP of the network policy object. USERADMIN (option A) does not have the privilege to attach network policies at the account level. Option C references an 'ATTACH POLICY' privilege which applies to masking/row access policies, not network policies. Option D is not a valid Snowflake configuration mechanism for network policies.

Topics

#Network Policy#Roles and Privileges#Account Administration#Security

Community Discussion

No community discussion yet for this question.

Full COF-C02 Practice