nerdexam
Snowflake

COF-C02 · Question #569

What happens to the privileges granted to Snowflake system-defined roles?

The correct answer is A. The privileges cannot be revoked. The privileges granted to Snowflake's system-defined roles cannot be revoked. System-defined roles, such as SYSADMIN, ACCOUNTADMIN, SECURITYADMIN, and others, come with a set of predefined privileges that are essential for the roles to function correctly within the Snowflake…

Account Access and Security

Question

What happens to the privileges granted to Snowflake system-defined roles?

Options

  • AThe privileges cannot be revoked.
  • BThe privileges can be revoked by an ACCOUNTADMIN.
  • CThe privileges can be revoked by an orgadmin.
  • DThe privileges can be revoked by any user-defined role with appropriate privileges.

How the community answered

(22 responses)
  • A
    91% (20)
  • B
    5% (1)
  • D
    5% (1)

Explanation

The privileges granted to Snowflake's system-defined roles cannot be revoked. System-defined roles, such as SYSADMIN, ACCOUNTADMIN, SECURITYADMIN, and others, come with a set of predefined privileges that are essential for the roles to function correctly within the Snowflake environment. These privileges are intrinsic to the roles and ensure that users assigned these roles can perform the necessary tasks and operations relevant to their responsibilities. The design of Snowflake's role-based access control (RBAC) model ensures that system-defined roles have a specific set of non-revocable privileges to maintain the security, integrity, and operational efficiency of the Snowflake environment. This approach prevents accidental or intentional modification of privileges that could disrupt the essential functions or compromise the security of the Snowflake account.

Topics

#Snowflake roles#System-defined roles#Privilege management#Access control

Community Discussion

No community discussion yet for this question.

Full COF-C02 Practice