COF-C02 · Question #308
Who can activate and enforce a network policy for all users in a Snowflake account? (Select TWO).
The correct answer is B. A user with a SECURITYADMIN or higher role E. A role that has the ownership of the network policy. Applying a network policy at the account level (affecting all users) requires either: (B) SECURITYADMIN role or higher (ACCOUNTADMIN), as this is an account-level security operation; or (E) a role that has OWNERSHIP of the network policy object. USERADMIN (option A) does not…
Question
Who can activate and enforce a network policy for all users in a Snowflake account? (Select TWO).
Options
- AA user with an USERADMIN or higher role
- BA user with a SECURITYADMIN or higher role
- CA role that has been granted the ATTACH POLICY privilege
- DA role that has the NETWORK_POLlCY account parameter set
- EA role that has the ownership of the network policy
How the community answered
(28 responses)- A7% (2)
- B71% (20)
- C14% (4)
- D7% (2)
Explanation
Applying a network policy at the account level (affecting all users) requires either: (B) SECURITYADMIN role or higher (ACCOUNTADMIN), as this is an account-level security operation; or (E) a role that has OWNERSHIP of the network policy object. USERADMIN (option A) does not have the privilege to attach network policies at the account level. Option C references an 'ATTACH POLICY' privilege which applies to masking/row access policies, not network policies. Option D is not a valid Snowflake configuration mechanism for network policies.
Topics
Community Discussion
No community discussion yet for this question.