Which Three Actions Can Be Performed Only With System Privileges?
Which three actions can you perform only with system privileges? (Choose three.)
Community Votes
67% of anonymous learners picked answer ABC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can classify an action as object-scoped or catalog-wide, and the trap is treating directory access via UTL_FILE or the WITH GRANT OPTION clause as system-level when both actually belong to the object-privilege model.
Oracle separates system privileges, which are granted at the data-dictionary level and are not tied to a named object, from object privileges, which always name a specific table, procedure or directory. This page explains why querying any table (A), executing a procedure in another schema (B) and logging in to the instance (C) are the three actions that require system privileges in 1Z0-071.
The most common wrong pick is ACD, because candidates assume that reaching operating-system flat files through UTL_FILE must be a system-level capability; in reality UTL_FILE writes through a DIRECTORY object, and READ/WRITE on that directory are object privileges granted to a user.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Queries that must succeed against any table in the database cannot be covered by object privileges, which are always scoped to one named object, so Oracle supplies the SELECT ANY TABLE / READ ANY TABLE system privilege (A). Running a procedure that belongs to a different schema is likewise handled through EXECUTE ANY PROCEDURE rather than by naming a single object, which makes it a system-level action (B). Connecting to the instance at all is governed by CREATE SESSION, the classic system privilege: without it an account cannot even establish a connection, no matter which object privileges it holds (C). All three are catalog-level permissions that exist independently of any schema object.Why the Other Options Are Wrong
D is wrong because UTL_FILE works through a DIRECTORY object, and READ/WRITE on that directory are object privileges granted to a user — Oracle's own documentation notes that these directory privileges are operating-system specific and give read and write access inside the named directory. E is wrong because WITH GRANT OPTION belongs to the object-privilege form of GRANT; when a system privilege is granted, the propagation clause is WITH ADMIN OPTION, so WITH GRANT OPTION is not a system-privilege action at all. That leaves exactly the three catalog-level actions in A, B and C.Community Comment Notes
The community split roughly two to one in favour of ABC over ACD, and braintop's one-line rationale — "D is object privilege to Directory object" — captures why the ACD camp is on weak ground. JUMP56 quoted Oracle's documentation stating that the privileges needed to access files in a directory object are operating-system specific and grant read/write access inside that directory. billysunday1 argues A and B through SELECT ANY TABLE and EXECUTE ANY PROCEDURE, which is exactly the 'ANY' system-privilege doctrine this question tests, while the same thread's claim that B is "an object privilege" shows how easy it is to confuse a per-object EXECUTE grant with the system-level one.Official Reference
Exam Strategy
When an option contains a word like 'any', 'another schema' or 'log in', map it immediately to its catalog-level privilege (SELECT ANY TABLE, EXECUTE ANY PROCEDURE, CREATE SESSION) before reading the distractors. Anything that names a specific object type — a directory, a table, a procedure — is an object privilege and cannot be the system-privilege answer.
Frequently Asked Questions
Why is UTL_FILE flat-file access not a system privilege in this question?
UTL_FILE reads and writes through a DIRECTORY object, and READ/WRITE on that directory are object privileges granted to a specific user, not catalog-wide system privileges.
Can WITH GRANT OPTION be used with system privileges?
No. System privileges are passed on with WITH ADMIN OPTION; WITH GRANT OPTION applies only to the object-privilege form of GRANT.