nerdexam
Snowflake

COF-C02 · Question #517

Which roles can make grant decisions to objects within a managed access schema? (Select TWO)

The correct answer is A. ACCOUNTADMIN B. SECURITYADMIN. In a managed access schema, the privilege to grant access to objects is centralized - it is removed from individual object owners and reserved for the schema owner or a role with the MANAGE GRANTS privilege. ACCOUNTADMIN always retains the ability to grant any privilege across…

Account Access and Security

Question

Which roles can make grant decisions to objects within a managed access schema? (Select TWO)

Options

  • AACCOUNTADMIN
  • BSECURITYADMIN
  • CSYSTEMADMIN
  • DORGADMIN
  • EUSERADMIN

How the community answered

(23 responses)
  • A
    87% (20)
  • C
    4% (1)
  • D
    9% (2)

Explanation

In a managed access schema, the privilege to grant access to objects is centralized - it is removed from individual object owners and reserved for the schema owner or a role with the MANAGE GRANTS privilege. ACCOUNTADMIN always retains the ability to grant any privilege across the account, and SECURITYADMIN holds the global MANAGE GRANTS privilege by default, allowing both to make grant decisions within managed access schemas. Regular roles like SYSADMIN, ORGADMIN, or USERADMIN cannot grant object privileges inside a managed access schema unless explicitly given that ability.

Topics

#Snowflake Roles#Managed Access Schema#Grant Management#Security Privileges

Community Discussion

No community discussion yet for this question.

Full COF-C02 Practice