問題文
An administrator is documenting how Snowflake combines access control models. Which statement correctly describes the combination that Snowflake implements?
選択肢
- Every object is owned by the account itself, so ownership sits above the roles and grants are computed centrally at each object reference.
- Attribute expressions decide access, so grants are computed at query time from the user's attributes rather than being stored.
- Objects have an owner who can grant access to them, and access is otherwise carried by roles that users activate, so the two models operate together.
- Access is attached directly to each user account, and roles exist only as a naming convention that groups users together in reports.