Snowflake SnowPro Core COF-C03 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Snowflake SnowPro Core COF-C03 Exam Dumps and Practice Test Dumps.

 

Question 61

Which Snowflake feature is used to control access to databases, schemas, tables, and other objects?

  1. Virtual warehouse
  2. Role-based access control
  3. Micro-partitioning
  4. Query acceleration

Correct Answer: 2

Explanation

Snowflake uses role-based access control, commonly called RBAC, to manage access to account objects and data. Privileges are granted to roles, and roles are assigned to users or other roles through a role hierarchy. This approach allows administrators to organize permissions around job responsibilities rather than managing every permission individually for each user. Virtual warehouses provide compute resources, micro-partitioning supports storage and query efficiency, and query acceleration addresses certain performance workloads. RBAC is therefore the primary security model for controlling which users can access and operate on Snowflake objects.

Question 62

A user needs to query tables in a schema. Which privilege is generally required on the schema itself?

  1. MODIFY
  2. OWNERSHIP
  3. USAGE
  4. INSERT

Correct Answer: 3

Explanation

The USAGE privilege on a schema allows a role to access objects within that schema when the role also has the necessary privileges on those objects. For example, querying a table generally requires USAGE on the containing database and schema along with SELECT on the table. OWNERSHIP provides much broader control and is not required simply to query data. MODIFY and INSERT have different purposes and do not replace the required schema access privilege. Understanding parent-object privileges is important because having SELECT on a table alone may not be sufficient if the role cannot access the database or schema containing that table.

Question 63

Which privilege is typically required on a database before a role can access objects within its schemas?

  1. USAGE
  2. DELETE
  3. INSERT
  4. TRUNCATE

Correct Answer: 1

Explanation

USAGE on a database is generally required before a role can access schemas and objects contained within that database. Snowflake’s access model follows an object hierarchy, so privileges may be required at multiple levels. For example, a role querying a table typically needs USAGE on the database and schema, along with SELECT on the table. INSERT, DELETE, and TRUNCATE are object-specific privileges associated with modifying table data and do not provide basic database access. Properly granting parent-object privileges is therefore an important part of building functional and secure Snowflake role configurations.

Question 64

What is the main purpose of a role hierarchy in Snowflake?

  1. To increase storage capacity
  2. To allow roles to inherit privileges from other roles
  3. To create additional warehouses
  4. To compress table data

Correct Answer: 2

Explanation

A Snowflake role hierarchy allows one role to inherit the privileges granted to another role. This enables administrators to build structured access models where higher-level roles receive the privileges of lower-level roles without repeatedly granting the same permissions. For example, a departmental role can inherit privileges from several functional roles. Role hierarchies do not increase storage capacity, create compute resources, or compress data. They are strictly related to authorization management. This inheritance model can simplify administration in larger environments by reducing duplicate grants and making access relationships easier to maintain.

Question 65

Which privilege allows a role to retrieve rows from a Snowflake table?

  1. UPDATE
  2. SELECT
  3. DELETE
  4. REFERENCES

Correct Answer: 2

Explanation

The SELECT privilege permits a role to query and retrieve data from a Snowflake table or view, subject to the required privileges on parent objects. It does not grant the ability to modify table data. UPDATE permits modification of existing rows, DELETE allows rows to be removed, and REFERENCES is associated with operations involving object references and constraints. Snowflake’s RBAC model typically grants SELECT to an appropriate role and then assigns that role to users who need read access. This separation helps administrators provide read-only access without granting unnecessary data modification capabilities.

Question 66

Which privilege would be most appropriate when a role needs to add rows to an existing table?

  1. SELECT
  2. INSERT
  3. USAGE
  4. MONITOR

Correct Answer: 2

Explanation

The INSERT privilege allows a role to add rows to an existing Snowflake table. It is a data manipulation privilege and is distinct from SELECT, which permits reading data. USAGE is commonly associated with accessing parent objects such as databases and schemas, while MONITOR provides monitoring-related capabilities on supported objects. A role performing an INSERT operation may need additional privileges depending on the exact SQL statement and objects involved, but INSERT is the table privilege directly associated with adding rows. Granting only SELECT would allow querying the table but would not authorize inserting new records.

Question 67

Which Snowflake role is automatically available in every Snowflake account and is commonly used for broad administrative control?

  1. PUBLIC
  2. SYSADMIN
  3. SECURITYADMIN
  4. ACCOUNTADMIN

Correct Answer: 4

Explanation

ACCOUNTADMIN is the highest-level system-defined role in Snowflake and is intended for account-level administration. It has extensive privileges and should be used carefully because assigning or operating with this role can provide very broad control over the account. SYSADMIN is commonly used for managing objects and warehouses, while SECURITYADMIN focuses heavily on security-related administration. PUBLIC is a role granted to every user but is not equivalent to account administration. Snowflake recommends following least-privilege practices rather than routinely using ACCOUNTADMIN for everyday operational activities that can be performed with narrower roles.

Question 68

Which system-defined role is primarily associated with managing grants, users, and security-related administration?

  1. SECURITYADMIN
  2. USERADMIN
  3. SYSADMIN
  4. PUBLIC

Correct Answer: 1

Explanation

SECURITYADMIN is a Snowflake system-defined role intended primarily for security administration, including managing grants and many account security-related objects. USERADMIN is more specifically associated with managing users and roles, while SYSADMIN is commonly used for managing databases, schemas, warehouses, and other objects. PUBLIC is automatically available to users but is not an administrative role. In a well-designed Snowflake environment, administrative responsibilities are separated among roles so that individuals receive only the permissions required for their duties. SECURITYADMIN therefore provides a central role for managing access-related administration.

Question 69

Which system-defined role is commonly responsible for creating and managing users and roles?

  1. SYSADMIN
  2. USERADMIN
  3. PUBLIC
  4. SECURITYADMIN

Correct Answer: 2

Explanation

USERADMIN is a system-defined Snowflake role designed for managing users and roles. It provides a more focused administrative responsibility than ACCOUNTADMIN and can be used as part of a least-privilege security design. SECURITYADMIN has broader security administration responsibilities, including managing many grants, while SYSADMIN generally manages database objects and compute resources. PUBLIC is automatically granted to all users and is not intended for administrative management. Separating user and role administration from object administration can make responsibilities clearer and reduce the risk associated with granting overly broad administrative privileges.

Question 70

Which system-defined role is commonly used to create and manage databases, schemas, tables, and warehouses?

  1. SYSADMIN
  2. USERADMIN
  3. PUBLIC
  4. ORGADMIN

Correct Answer: 1

Explanation

SYSADMIN is commonly used to manage Snowflake objects such as databases, schemas, tables, views, and virtual warehouses when the role has the appropriate privileges. It is an important operational role in Snowflake’s administrative hierarchy and is generally preferable to using ACCOUNTADMIN for routine object management. USERADMIN focuses on users and roles, PUBLIC is automatically granted broadly, and ORGADMIN is associated with organization-level administration. A properly designed Snowflake environment can delegate object-management responsibilities to SYSADMIN while keeping highly privileged account-level functions restricted to appropriate administrators.

Question 71

A user can select from a table but cannot access the database containing it. Which missing privilege should be investigated first?

  1. DELETE on the table
  2. USAGE on the database
  3. INSERT on the table
  4. UPDATE on the table

Correct Answer: 2

Explanation

USAGE on the database should be investigated because Snowflake access follows an object hierarchy. A role generally needs the ability to access the database and schema before it can use objects contained within them. Having SELECT on a table does not necessarily provide access through the parent database and schema. DELETE, INSERT, and UPDATE are data manipulation privileges and do not solve the missing parent-level access. Administrators should verify the role’s effective privileges at each relevant level, including database, schema, and table. This layered privilege model helps maintain both functionality and security.

Question 72

Which security principle recommends granting users only the permissions required to perform their responsibilities?

  1. Data sharing
  2. Least privilege
  3. Query acceleration
  4. Automatic clustering

Correct Answer: 2

Explanation

The principle of least privilege means users and roles should receive only the permissions necessary to perform their assigned responsibilities. Applying this principle reduces unnecessary access and limits the potential impact of mistakes or compromised credentials. In Snowflake, least privilege can be implemented by creating appropriately scoped roles and granting only required object privileges. Data sharing addresses controlled distribution of data, query acceleration addresses performance, and automatic clustering concerns data organization. Least privilege is therefore a fundamental security concept that should guide role design, administrative delegation, and access reviews in Snowflake environments.

Question 73

Which Snowflake capability allows sensitive columns to be protected based on the role or context of the user querying the data?

  1. Dynamic data masking
  2. Multi-cluster warehouse
  3. Time Travel
  4. Result caching

Correct Answer: 1

Explanation

Dynamic data masking allows Snowflake to protect sensitive column values by applying masking policies when data is queried. The value presented to a user can depend on conditions such as the user’s role or other policy logic. This allows organizations to provide access to a dataset while reducing exposure of sensitive information. Multi-cluster warehouses address query concurrency, Time Travel provides historical data access, and result caching can reuse eligible query results. Dynamic masking is therefore a security and governance capability rather than a compute or historical-data feature.

Question 74

What is the primary purpose of a masking policy in Snowflake?

  1. To change warehouse size
  2. To control how sensitive column values are displayed
  3. To schedule queries
  4. To create database schemas

Correct Answer: 2

Explanation

A masking policy controls how sensitive column values are presented to users when they query protected data. Depending on the policy logic and execution context, authorized users may see the original value while other users receive a masked or transformed representation. This helps organizations protect sensitive information without necessarily removing the underlying data from the table. Masking policies do not resize warehouses, schedule queries, or create schemas. They are part of Snowflake’s governance and security capabilities and can be applied to appropriate columns to enforce consistent protection across data-access scenarios.

Question 75

Which Snowflake feature can restrict access to rows based on the role or other session context?

  1. Row access policy
  2. File format
  3. Resource monitor
  4. Query tag

Correct Answer: 1

Explanation

A row access policy can control which rows a user is allowed to see when querying a protected table or view. The policy evaluates conditions and can use information about the querying context, such as roles or session attributes, to determine whether rows should be returned. This enables organizations to implement row-level security without maintaining separate physical copies of the same dataset for every user group. File formats describe staged files, resource monitors manage credit usage, and query tags identify queries. Row access policies therefore provide a direct mechanism for enforcing row-level data visibility.

Question 76

A company wants regional managers to see only rows belonging to their assigned region. Which capability is most relevant?

  1. Search optimization
  2. Row access policy
  3. Result cache
  4. Multi-cluster warehouse

Correct Answer: 2

Explanation

A row access policy is appropriate when different users need to see different subsets of rows from the same table. The policy can evaluate user or session information and determine whether a particular row should be visible. For example, a regional manager could be allowed to view records associated with that manager’s authorized region while other regions remain hidden. Search optimization and multi-cluster warehouses address performance, while result caching concerns query-result reuse. Row access policies therefore provide a security mechanism for enforcing row-level visibility while allowing multiple groups to query the same underlying table.

Question 77

Which Snowflake feature is designed to protect personally identifiable information by replacing sensitive values with controlled representations during queries?

  1. Dynamic data masking
  2. Warehouse suspension
  3. Time Travel
  4. Data unloading

Correct Answer: 1

Explanation

Dynamic data masking is designed to protect sensitive information such as personally identifiable information by controlling how column values are presented during query execution. A masking policy can determine whether a user receives the original value or a masked representation based on defined conditions. The underlying stored data remains available to authorized operations while exposure to unauthorized users is reduced. Warehouse suspension affects compute usage, Time Travel handles historical data, and data unloading moves data to files. Dynamic masking is therefore the relevant Snowflake capability for protecting sensitive column values during data access.

Question 78

Which Snowflake capability can help determine whether a user’s access should be evaluated according to a specific security policy at query time?

  1. Policy-based access controls
  2. Warehouse resizing
  3. File compression
  4. Micro-partition creation

Correct Answer: 4

Explanation

Snowflake provides policy-based security controls that evaluate access conditions when data is queried. Capabilities such as masking policies and row access policies allow organizations to define rules that determine how data should be exposed based on roles, session information, or other supported conditions. Warehouse resizing changes compute capacity, file compression concerns storage and data movement efficiency, and micro-partitions are automatically managed storage units. Policy-based controls therefore provide the mechanism for applying dynamic governance rules during data access. This approach helps organizations enforce consistent protection without maintaining separate datasets for every access group.

Question 79

Which authentication option can Snowflake support for users who need passwordless authentication?

  1. Key-pair authentication
  2. Plain-text file authentication
  3. Table authentication
  4. Schema authentication

Correct Answer: 1

Explanation

Snowflake supports key-pair authentication as an alternative to password-based authentication for supported users and applications. With key-pair authentication, a user authenticates using a private key while Snowflake validates the corresponding public key associated with the user. This approach is particularly useful for automated workloads and service-oriented access where storing passwords may be undesirable. The other listed choices are not Snowflake authentication mechanisms. Key management must be handled carefully, including protecting private keys and following organizational security requirements. Proper authentication design is an important part of securing automated Snowflake connections.

Question 80

Which authentication approach is commonly preferred for automated applications because it avoids storing a user password in the application?

  1. Key-pair authentication
  2. Manual browser login
  3. Shared plaintext password
  4. Temporary table authentication

Correct Answer: 1

Explanation

Key-pair authentication can be useful for automated applications because the application can authenticate using cryptographic credentials rather than storing a user’s password. The private key must be protected securely, while the corresponding public key is configured for the Snowflake user. This approach can reduce reliance on passwords in application configurations and is well suited to programmatic connections. Manual browser authentication is not appropriate for unattended workloads, while shared plaintext passwords create security risks. Temporary tables do not provide authentication. Key-pair authentication is therefore a relevant method for securely connecting automated workloads to Snowflake.