Subdomain 1.2: Given a set of business requirements, design access control framework
1.A new team lead must be able to create users and roles for their department. The security team wants to give them only these abilities, without account-wide privilege management or the ability to create databases. Which system-defined role should be granted?
- A.SECURITYADMIN, which can create users and roles and also holds the global MANAGE GRANTS privilege over every object.
- B.USERADMIN, which holds the CREATE USER and CREATE ROLE privileges and nothing broader for object administration.
- C.ACCOUNTADMIN, which encapsulates SYSADMIN and SECURITYADMIN and so covers user and role creation in a single grant.
- D.SYSADMIN, which can create warehouses and databases and is the usual parent for custom roles that own objects.
Show answer & explanation
Correct answer: B — USERADMIN, which holds the CREATE USER and CREATE ROLE privileges and nothing broader for object administration.
- A. Incorrect. SECURITYADMIN can create users and roles but also has MANAGE GRANTS, which lets it grant or revoke privileges on any object, exceeding the stated limit.
- B. Correct. USERADMIN is dedicated to user and role administration and is the least-privileged system role that satisfies the requirement.
- C. Incorrect. ACCOUNTADMIN is the top-level role with the broadest authority, including billing and account settings, so it violates the least-privilege requirement.
- D. Incorrect. SYSADMIN manages objects such as databases and warehouses; it does not hold CREATE USER or CREATE ROLE and it is the opposite of the requested scope.