nerdexam
ServiceNow

CSA · Question #464

If you have the Impersonate role, what type of user are you not able to impersonate?

The correct answer is C. System Administrator. In ServiceNow, the Impersonate role allows a user to log in and act as another user for testing, troubleshooting, or support purposes. However, impersonating a System Administrator (admin) is explicitly blocked as a security safeguard to prevent privilege escalation - even a…

Submitted by tarun92· Apr 18, 2026Database Management and Platform Security

Question

If you have the Impersonate role, what type of user are you not able to impersonate?

Options

  • ACustomer
  • BVIP
  • CSystem Administrator
  • DApprover
  • ECatalog User

How the community answered

(23 responses)
  • B
    4% (1)
  • C
    91% (21)
  • D
    4% (1)

Explanation

In ServiceNow, the Impersonate role allows a user to log in and act as another user for testing, troubleshooting, or support purposes. However, impersonating a System Administrator (admin) is explicitly blocked as a security safeguard to prevent privilege escalation - even a user with the Impersonate role cannot assume the full admin privileges of the system_administrator role. All other roles listed (Customer, VIP, Approver, Catalog User) represent standard non-admin roles that can be impersonated without violating this security boundary.

Topics

#Impersonation#User Roles#Platform Security#System Administrator

Community Discussion

No community discussion yet for this question.

Full CSA Practice