COF-C02 · Question #496
What does Snowflake recommend for a user assigned the ACCOUNTADMIN role?
The correct answer is C. The user should be required to use Multi-Factor Authentication (MFA). Snowflake strongly recommends that all users assigned the ACCOUNTADMIN role use Multi-Factor Authentication (MFA). ACCOUNTADMIN is the most powerful role in a Snowflake account - it can manage all objects, billing, and security configurations. Because a compromised ACCOUNTADMIN…
Question
What does Snowflake recommend for a user assigned the ACCOUNTADMIN role?
Options
- AThe ACCCUKTMKIN role should be set as tie user's default role.
- BThe user should use federated authentication instead of a password
- CThe user should be required to use Multi-Factor Authentication (MFA).
- DThere should be just one user with the ACCOUNTADMIN role in each Snowflake account.
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C90% (26)
Explanation
Snowflake strongly recommends that all users assigned the ACCOUNTADMIN role use Multi-Factor Authentication (MFA). ACCOUNTADMIN is the most powerful role in a Snowflake account - it can manage all objects, billing, and security configurations. Because a compromised ACCOUNTADMIN credential could result in a full account takeover, MFA provides a critical second layer of protection. Snowflake's security best practices documentation explicitly calls out MFA as a requirement for this role. While it is also recommended to limit the number of ACCOUNTADMIN users (option D is good practice), Snowflake's primary, explicit recommendation is MFA enforcement.
Topics
Community Discussion
No community discussion yet for this question.