nerdexam
Snowflake

COF-C02 · Question #580

Based on Snowflake recommendations, when creating a hierarchy of custom roles, the top-most custom role should be assigned to which role?

The correct answer is A. ACCOUNTADMIN. Based on Snowflake recommendations, when creating a hierarchy of custom roles, the top-most custom role should ideally be granted to the ACCOUNTADMIN role. This recommendation stems from the best practices for implementing a least privilege access control model, ensuring that…

Account Access and Security

Question

Based on Snowflake recommendations, when creating a hierarchy of custom roles, the top-most custom role should be assigned to which role?

Options

  • AACCOUNTADMIN
  • BSECURITYADMIN
  • CSYSADMIN
  • DUSERADMIN

How the community answered

(66 responses)
  • A
    94% (62)
  • B
    3% (2)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Based on Snowflake recommendations, when creating a hierarchy of custom roles, the top-most custom role should ideally be granted to the ACCOUNTADMIN role. This recommendation stems from the best practices for implementing a least privilege access control model, ensuring that only the necessary permissions are granted at each level of the role hierarchy. The ACCOUNTADMIN role has the highest level of privileges in Snowflake, including the ability to manage all aspects of the Snowflake account. By assigning the top-most custom role to ACCOUNTADMIN, you ensure that the administration of role hierarchies and the assignment of roles remain under the control of users with the highest level of oversight and responsibility within the Snowflake environment.

Topics

#Role hierarchy#Custom roles#ACCOUNTADMIN#Best practices

Community Discussion

No community discussion yet for this question.

Full COF-C02 Practice