Users, Groups, and Roles Flashcards
7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Users, Groups, and Roles flashcards as text
Which role allows a user to manage other users' records without full admin access?
Answer: user_admin
The user_admin role grants the ability to create, edit, and manage user records without requiring full admin access.
How can an administrator prevent a specific role from being elevated via 'sudo' in High Security mode?
Answer: Set 'Grantable' to false on the role
Setting the 'Grantable' field to false on a role prevents it from being granted through elevation or sudo.
What is the purpose of the 'sys_user_has_role' table?
Answer: It stores the many-to-many relationship between users and roles
The sys_user_has_role table is a junction table that records which roles are directly assigned to which users.
A group in ServiceNow can have which of the following types of membership?
Answer: Direct users and nested groups
ServiceNow groups support both direct user assignments and nested groups as members.
Which system property controls the maximum number of roles a single user can hold?
Answer: There is no such system property
ServiceNow does not have a built-in system property that limits the number of roles a single user can hold.
What is the effect of checking 'Web service access only' on a user record?
Answer: The user cannot log into the UI but can authenticate for integrations
A 'Web service access only' user cannot log in through the browser UI but can still authenticate for REST/SOAP integrations.
When using role-based access control, which of the following grants the MOST permissive access in ServiceNow?
Answer: admin
The admin role is the most permissive standard role, granting access to virtually all platform features and data.