Subdomain 1.1: Design and implement access control strategies.
1.A user holds primary role ANALYST and has secondary roles activated with USE SECONDARY ROLES ALL, including ENGINEER which has CREATE TABLE on schema dev.work. The user runs CREATE TABLE dev.work.t (id INT) while ANALYST lacks that privilege. Which TWO statements describe the result?(Select 2)
- A.Secondary roles supply privileges only for SELECT statements, so DML statements such as INSERT also ignore the privileges of ENGINEER in this session.
- B.The statement succeeds and the table is owned by ENGINEER, because Snowflake uses the secondary role that carries the missing privilege.
- C.The statement succeeds and ownership is shared by ANALYST and ENGINEER, since both roles are active in the session at the same time.
- D.If the primary role were ENGINEER with CREATE TABLE, the new table would be owned by ENGINEER, since ownership goes to the primary role.
- E.The CREATE TABLE statement fails because object creation is authorized using only the primary role and not any activated secondary role.
Show answer & explanation
Correct answers: D, E — If the primary role were ENGINEER with CREATE TABLE, the new table would be owned by ENGINEER, since ownership goes to the primary role.; The CREATE TABLE statement fails because object creation is authorized using only the primary role and not any activated secondary role.
- A. Secondary roles contribute privileges for SELECT, DML and other non-CREATE operations. The restriction is specific to creating objects.
- B. Secondary roles do not authorize CREATE and never receive ownership. The statement fails with an insufficient privileges error.
- C. Every object has exactly one owner role. Ownership is never shared among active roles.
- D. A created object is owned by the primary role that executed the CREATE. Secondary roles never take ownership.
- E. CREATE statements are evaluated against the primary role only. Privileges from secondary roles do not authorize object creation.