問題文
A media company is designing a role hierarchy for a Snowflake account that holds subscriber billing records. Analysts must read the records, a platform team must create and drop objects in the same schema without reading the billing columns, and an internal audit group must review who holds which privilege without querying any data. Which design follows least privilege while leaving room for later teams?
選択肢
- Give every user a single shared role, and control what each person sees by attaching masking policies to the billing columns so that unauthorized people receive masked values.
- Grant the three groups the system-defined roles that most closely match their duties, and restrict what each group can actually reach by attaching network policies to the individual users.
- Grant the privileges directly to each user rather than to roles, because that removes the inheritance paths that could accidentally widen access later.
- Create one custom role per job function with only the privileges that function needs, grant each of those roles to a parent custom role for administration, and leave the system roles out of the design.