問題文
A security engineer must give a partner team read access to a single schema inside a database, and the grants must travel with the database when it is later shared or replicated. Which approach fits that requirement?
選択肢
- Grant select on the objects directly to the partner team's users, so that the grants live on the objects themselves and move with them.
- Create a database role in that database, grant it usage on the schema and select on the objects, and grant the database role to the account role the partner team uses.
- Attach a row access policy that admits the partner team's role, because policies are stored in the database.
- Create an account-level custom role, grant it usage on the schema and select on the objects, and rely on the fact that a role defined at the account level is carried along with any database that its grants happen to point at.