Be able to query ACCESS_HISTORY to explain column lineage, attach tags for cost and classification, and combine masking with sharing. The critical skill is designing Row Access Policies whose mapping-table joins stay performant and deterministic while enforcing least-privilege access.
Start practicing
Data Governance — choose a session length
Free · No account required
Domain overview
This domain covers Snowflake governance primitives: access auditing via ACCOUNT_USAGE and ACCESS_HISTORY, Object Tagging, masking and row access policies, and secure data sharing. Questions present audit queries, policy designs, or sharing scenarios and ask you to interpret lineage output, pick correct governance combinations, or identify performance and correctness trade-offs.
Exam objectives
Reading ACCESS_HISTORY and base_objects_accessed to trace column-level data lineage across queries
Applying Object Tagging for cost attribution, classification, and tag-based masking policies
Combining Dynamic Data Masking with Secure Data Sharing to expose masked subsets to third parties
Designing Row Access Policies that join mapping tables and evaluating their query performance impact
Assuming base_objects_accessed shows only direct tables, ignoring that it captures upstream base tables behind views and CTEs
Confusing tag-based masking with direct masking policies, or expecting tags alone to mask data without a masking policy attached
Writing Row Access Policies with non-deterministic or heavy subqueries against mapping tables, causing scan and join overhead per row
Click any question to see the full explanation and answer options, or start a focused practice session above.
A data engineer needs to ensure that PII data in the 'SALES' table is obscured for non-admin users while maintaining original data types for downstream analytical models. Which approach provides the most scalable governance?
2An organization wants to classify their data to identify PII. Which feature should they use to automatically tag columns containing sensitive information?
3Which object allows a data engineer to assign a security policy based on a user's geographical location attribute?
4A company requires that data masking policies be applied automatically whenever a column is tagged with 'PII'. How can this be achieved?
5Which governance tool allows an administrator to audit who accessed a specific table and when?
6Which approach is most effective for managing governance policies across a large, multi-schema data warehouse environment?
7What is the primary purpose of the 'SNOWFLAKE.ACCOUNT_USAGE' schema in a governance context?
8An organization wants to track PII data usage across the environment. Which Snowflake feature provides the most comprehensive audit trail of access to objects containing sensitive information?
9Which TWO of the following are true regarding the use of Snowflake Data Classification?
10What is the primary purpose of a 'Secure View' in Snowflake from a governance perspective?
11An auditor requests proof of who has accessed a specific table containing sensitive data. Which Snowflake view in the ACCOUNT_USAGE schema provides this data?
12What is the primary function of a 'Tag' in Snowflake's governance framework?
13Which of the following is true when considering the order of operations for policy application in Snowflake?
14What is the primary benefit of using Snowflake's Object Tagging for cost attribution?
15A data engineer wants to share a subset of data with a third party while ensuring sensitive columns are masked. Which governance combination is best?
16A data engineer needs to identify all columns across a multi-database Snowflake account that have been assigned the 'PII_Type' tag to ensure compliance with a new privacy regulation. Which approach provides the most comprehensive and efficient result for this account-level audit?
17A healthcare company implements a Row Access Policy (RAP) on a PATIENTS table to restrict doctor access to only their assigned patients. The RAP references a mapping table. What is the most critical performance consideration when designing this policy for a table with billions of rows?
18In Snowflake's object tagging hierarchy, if a tag is applied at the Schema level and a different value for the same tag is applied at the Table level, what is the resulting behavior for the Table?
19Refer to the exhibit. A security administrator executes this query to audit access to a sensitive table. What specific information is captured in the 'base_objects_accessed' column regarding the data lineage of this query?
20A data engineer needs to prevent any future column additions to a critical ORDERS table from containing unprotected PII. The goal is to automatically classify new columns and receive alerts when sensitive data is detected. Which Snowflake feature should be configured to achieve this?
21A data engineer is implementing a data governance strategy and needs to ensure that all tables containing sensitive data are automatically identified and tagged. The engineer wants to use Snowflake's native classification capabilities and then apply masking policies based on those tags. Which sequence of steps should the engineer follow?
22A financial services company stores transaction records in a Snowflake table that includes a column named 'SSN'. The data engineering team has been asked to implement a governance control that automatically detects and tags any column containing Social Security Numbers across the entire account, without manually inspecting every table. Which Snowflake feature should the team use to achieve this requirement?
23A Snowflake account has a tag-based masking policy on column CUSTOMER.SSN. An analyst runs a query that applies the SYSTEM$GET_TAG function to that column. The analyst has been granted the APPLY MASKING POLICY privilege on the tag, but not the USAGE privilege on the tag. What does the analyst see for the SSN column value?
24A Snowflake data engineer has been tasked with implementing dynamic data masking on a CUSTOMERS table so that the SSN column is fully redacted for all users except those with the role PII_ADMIN. The engineer wants the masking to apply automatically whenever the column is queried, without changing any application SQL. Which Snowflake object should the engineer create and attach to the SSN column?
25A data engineer needs to audit all grants of the 'SYSADMIN' role to users across the Snowflake account. The engineer has access to the ACCOUNTADMIN role and wants to retrieve this information efficiently. Which Snowflake view should be queried?
26A financial services firm stores account balances in a Snowflake table ACCOUNTS. A row access policy is defined so that analysts see only rows where REGION = CURRENT_REGION(). The firm also attaches a masking policy to the BALANCE column that returns NULL for users without the FINANCE role. An analyst with the ANALYST role queries SELECT REGION, BALANCE FROM ACCOUNTS. What will the analyst see?
27A data engineer is tasked with implementing a data governance strategy that includes classifying sensitive data and applying tags. The engineer plans to use Snowflake's Data Classification and tag-based masking. Which two statements are true regarding the interaction between Data Classification and tags? (Choose two.)
28A data engineer needs to categorize columns across multiple databases with custom business tags such as COST_CENTER and DATA_OWNER, and then enforce that only users with the TAG_ADMIN role can modify those tags. Which Snowflake feature should the engineer use to meet this requirement?
29A data engineer needs to audit all tag assignments across the account to ensure that no sensitive columns are missing required tags. Which Snowflake view should the engineer query to retrieve a list of all tags applied to columns, including the tag name, value, and the object it is applied to?
30A financial services firm must enforce a policy that only users with the role 'COMPLIANCE_OFFICER' can view rows where the 'ACCOUNT_STATUS' column equals 'DELINQUENT' in the 'LOANS' table. All other users should see only non-delinquent rows. Which Snowflake feature should the data engineer implement to meet this requirement?
31A retail company has a Snowflake account with many databases and schemas. The data governance team needs to discover all columns that contain personal data such as names, email addresses, and phone numbers, and automatically assign a system tag so that a masking policy can be applied later. They want to minimize manual effort and ensure the classification is consistent. Which Snowflake feature should they use to achieve this?
32A data engineer needs to ensure that all queries against a table containing sensitive data are logged for compliance purposes. Which Snowflake feature should the engineer use to capture the query text and the user who executed it?
33A financial institution uses Snowflake to store customer transactions. A data engineer needs to implement a policy that restricts access to rows in the TRANSACTIONS table based on the department of the user. The department information is stored in a lookup table named USER_DEPARTMENT. The policy must be applied dynamically without modifying the TRANSACTIONS table. Which Snowflake feature should the engineer use?
34A data steward at a financial services company needs to automatically detect and tag columns containing Social Security numbers across all schemas in the PROD database. The steward wants the tagging to be applied without manually inspecting each table and to leverage Snowflake's built-in classifiers. Which approach should the steward use?
35A data engineer is implementing row access policies to enforce data segregation for a multi-tenant application. The table ORDERS contains a column TENANT_ID. The engineer creates a row access policy that uses a mapping table TENANT_MAPPING to associate users with their allowed TENANT_ID values. After applying the policy, the engineer notices that queries against ORDERS are returning no rows for some users who should have access. The mapping table is correctly populated. What is the most likely cause of the issue?
36A data engineer is setting up Snowflake Data Classification on a table containing customer feedback. The engineer wants to ensure that the classification process identifies columns with potentially sensitive information and tags them appropriately. Which two actions are required to enable Data Classification on the table? (Choose two.)
37A data engineer needs to ensure that only users with the role FINANCE_ANALYST can view the SALARY column in the EMPLOYEES table. All other users should see a masked value. Which Snowflake feature should the engineer use?
38An organization wants to track all data access in their Snowflake account for compliance. They need to know which columns were accessed by which queries, and they want to retain this information for at least one year. Which Snowflake feature should they use to meet this requirement?
39A data engineer is responsible for implementing data governance in Snowflake. The organization requires that all access to sensitive data be auditable and that data usage can be attributed to specific users and roles. Which two Snowflake features should the engineer use to meet these requirements? (Choose two.)
40A data engineer needs to ensure that a column containing credit card numbers is masked for all users except those with the PAYMENT_ADMIN role. The masking should be applied consistently across all tables that use a specific tag. Which Snowflake feature should the engineer use?
41A financial services firm stores customer records in a table called TRANSACTIONS. The compliance team requires that a specific column, CREDIT_CARD_NUMBER, be transformed so that only the last four digits are visible to all users except members of the role PAYMENT_ADMIN. Additionally, the transformation must occur at query time without modifying the stored data. Which Snowflake feature should the data engineer use to meet this requirement?
42A data engineer is implementing a data classification process using Snowflake's Data Classification feature. The engineer wants to automatically classify columns containing sensitive data and then use the results to apply masking policies. After running the classification, the engineer notices that some columns that should be classified as 'EMAIL' are not being tagged. The engineer has verified that the data contains valid email addresses. What is the most likely reason for the missing classification?
Be able to query ACCESS_HISTORY to explain column lineage, attach tags for cost and classification, and combine masking with sharing. The critical skill is designing Row Access Policies whose mapping-table joins stay performant and deterministic while enforcing least-privilege access.
The Courseiva DEA-C02 question bank contains 42 questions in the Data Governance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Governance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included