Which Two Statements Are True About WITH GRANT OPTION?

System privileges versus object privileges Granting privileges on tables
Answer Correct answer: B, D — WITH GRANT OPTION is an object-privilege clause: the grantee may pass the privilege on with or without the option, but cannot grant it to PUBLIC.

Which two are true about the WITH GRANT OPTION clause? (Choose two.)

  1. It can be used for system and object privileges.
  2. The grantee can grant the object privilege to any user in the database, with or without including this option. Correct Answer
  3. The grantee must have the GRANT ANY OBJECT PRIVILEGE system privilege to use this option.
  4. It cannot be used to pass on privileges to PUBLIC by the grantee. Correct Answer
  5. It can be used when granting privileges to roles.

Community Insight

It tests the scope of WITH GRANT OPTION — it belongs to object privileges, and the grantee may pass the privilege on (with or without the option) but not to PUBLIC — with the trap being confusion with WITH ADMIN OPTION, which is used for system privileges and roles.

WITH GRANT OPTION lets the grantee of an object privilege pass that privilege on to other users in the database, but never to PUBLIC, which is why (B, D) are the two true statements in this 1Z0-071 question.

Most candidates choose A, assuming WITH GRANT OPTION works for system privileges the same way WITH ADMIN OPTION does; Oracle does not accept the grant-option clause for system privileges or role grants.

Community Discussion (6 comments)

Thameur01 👍 1 Selected: D
D. It cannot be used to pass on privileges to PUBLIC by the grantee. F. It can be used to pass on privileges to other users by the grantee.
bca123 👍 1 Selected: D
WHAT ABOUT D , THAT ALSO CORRECT SEEMS,
bfb7c7d 👍 1
B is the right answer as per this website https://docs.oracle.com/cd/B10500_01/server.920/a96521/privs.htm#21327 this website has same wording Specifying the GRANT OPTION Specify WITH GRANT OPTION to enable the grantee to grant the object privileges to other users and roles. The user whose schema contains an object is automatically granted all associated object privileges with the GRANT OPTION. This special privilege allows the grantee several expanded privileges: The grantee can grant the object privilege to any users in the database, with or without the GRANT OPTION, or to any role in the database. If both of the following are true, the grantee can create views on the table and grant the corresponding privileges on the views to any user or role in the database. The grantee receives object privileges for the table with the GRANT OPTION. The grantee has the CREATE VIEW or CREATE ANY VIEW system privilege.
tom100men 👍 2 Selected: B
Specify WITH GRANT OPTION to enable the grantee to grant the object privileges to other users and roles. The user whose schema contains an object is automatically granted all associated object privileges with the GRANT OPTION. This special privilege allows the grantee several expanded privileges: The grantee can grant the object privilege to any users in the database, with or without the GRANT OPTION, or to any role in the database. If both of the following are true, the grantee can create views on the table and grant the corresponding privileges on the views to any user or role in the database. The grantee receives object privileges for the table with the GRANT OPTION. The grantee has the CREATE VIEW or CREATE ANY VIEW system privilege. The GRANT OPTION is not valid when granting an object privilege to a role. Oracle prevents the propagation of object privileges through roles so that grantees of a role cannot propagate object privileges received by means of roles.
tom100men 👍 1
A is wrong - only object privileges https://docs.oracle.com/en/database/oracle/oracle-database/19/sqlrf/GRANT.html
billysunday1 👍 1 Selected: A
A. It can be used for system and object privileges. This option allows the grantee to further grant the privilege or role to another user or role, unless the role is a GLOBAL role, which includes both system and object privileges . F. It can be used to pass on privileges to other users by the grantee. When a user is granted privileges or a role with the WITH GRANT OPTION, they can then grant those same privileges or roles to other users or roles. This does not apply to roles, as roles cannot be granted WITH GRANT OPTION .

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

B is right because Oracle's documentation on privileges states that the special grant-option privilege lets the grantee "grant the object privilege to any users in the database, with or without the GRANT OPTION" — the grantee chooses whether to pass the option along or hand over a plain, non-transferable privilege. Note also that the owner of the schema containing the object automatically holds all associated object privileges with the grant option, so no extra system privilege is needed. D is right because the same expanded privilege stops short of PUBLIC: a grantee who received an object privilege with the grant option may pass it to users (and roles), but cannot pass it on to PUBLIC. Together, B and D describe exactly the two documented facts the exam is checking: who the grantee may pass the privilege to, and the PUBLIC exception that limits it. This is why the pair, not a single letter, is the answer to a "Choose two" item.

Why the Other Options Are Wrong

A is wrong because WITH GRANT OPTION applies only to object privileges such as SELECT or UPDATE on a table or view; system privileges and roles are extended with WITH ADMIN OPTION instead, and the grant-option syntax is not accepted there. C is wrong because the grantee needs nothing like GRANT ANY OBJECT PRIVILEGE — the authority to re-grant comes from holding the object privilege itself with the grant option, and the object owner has that authority automatically. E is wrong because the grant option is attached to a grantee user who passes an object privilege onward, not to a role as the recipient; role-related administration uses WITH ADMIN OPTION, and the exam treats the clause as unavailable when the grantee is a role rather than a user. So the only two statements consistent with Oracle's documented behavior are the ones about passing the privilege to any user and about the PUBLIC restriction.

Community Comment Notes

Learners split mainly between A/E-style reasoning and the doc-based reading of B. As tom100men notes, the documented wording is that WITH GRANT OPTION enables the grantee to grant object privileges to other users and roles, and he also points out that "A is wrong - only object privileges", citing Oracle's GRANT page. billysunday1 argues the opposite — that the option covers both system and object privileges — which is the classic WITH ADMIN OPTION confusion that makes A such a popular distractor. bca123 asks "WHAT ABOUT D, THAT ALSO CORRECT SEEMS", and Thameur01 also settles on D while adding that the holder can pass privileges to other users, both of which line up with the PUBLIC restriction described above. The takeaway from the thread: verify the clause against Oracle's privilege documentation rather than instinct about system privileges.

Official Reference

Exam Strategy

For any WITH GRANT OPTION question, first delete options mentioning system privileges or roles — those belong to WITH ADMIN OPTION — then judge the survivors by who the grantee may and may not pass the privilege to. Remember that a "Choose two" item expects exactly two letters, so never submit only B even if it looks complete.

Frequently Asked Questions

Why is WITH GRANT OPTION invalid for system privileges in Oracle?

System privileges and roles are extended with WITH ADMIN OPTION instead; WITH GRANT OPTION applies to object privileges such as SELECT, INSERT or UPDATE on a table or view.

Can a grantee holding WITH GRANT OPTION pass the privilege to PUBLIC?

No. The documented grant-option privilege lets the grantee grant the object privilege to any user in the database, but not to PUBLIC, which makes option D true.

More 1Z0-071 FAQ →

Related Analysis

← Back to 1Z0-071 Study Guide