問題文
An organization is separating duties among its administrators. One group must be able to create and manage users and roles but must not be able to grant privileges on tables that belong to other role hierarchies. Which system-defined role fits that group?
選択肢
- PUBLIC, because every user already holds it, so user management can be delegated with no additional grant at all.
- SECURITYADMIN, which is the role designed for user creation and which deliberately excludes the ability to manage grants anywhere in the account.
- USERADMIN, which holds the privileges for creating users and roles without the broader management of grants that the role above it carries.
- SYSADMIN, because user creation belongs to the role that owns databases and warehouses in the recommended hierarchy.