Courseiva
Accounts and Security →hardMultiple Choice

ARA-C01 Accounts and Security Practice Question

A healthcare organization uses Snowflake to store sensitive patient data. They need to implement column-level security that allows users with the role 'DOCTOR' to see full patient IDs, while users with the role 'RESEARCHER' should see only the last four digits. The organization wants a centralized, reusable solution that can be applied to multiple columns across different tables. Which Snowflake feature should the architect use?

⚠ Common exam trap

A common mix-up: candidates confuse column-level masking with row-level security or metadata tagging, when the requirement is specifically for dynamic masking of column values based on role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic Data Masking with a masking policy that checks the current role and applies the appropriate masking.

Dynamic Data Masking with a masking policy is the correct feature because it allows column-level masking based on the current role. The policy can be written to show full data to the DOCTOR role and masked data to others. Masking policies are centralized and can be applied to multiple columns, making them reusable. Secure views, row access policies, and object tagging do not provide the required dynamic column-level masking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Row Access Policies that limit which rows are visible based on the user's role.

    Why it's wrong here

    Row Access Policies control which rows a user can see, not which columns or how column data is masked. They are used for row-level security. In this scenario, the requirement is to mask part of a column's value based on role, which is column-level security. Row Access Policies would not achieve the desired masking of patient IDs.

  • ✓

    Dynamic Data Masking with a masking policy that checks the current role and applies the appropriate masking.

    Why this is correct

    Dynamic Data Masking uses masking policies that can be attached to columns. The policy can evaluate the current role and conditionally mask the data. By creating a policy that returns the full value for the DOCTOR role and a masked value for others, the organization achieves column-level security. Masking policies are centralized and can be reused across multiple columns, satisfying the requirement for a reusable solution.

  • ✗

    Object Tagging with a tag that indicates the sensitivity level, combined with a policy that enforces access.

    Why it's wrong here

    Object Tagging is used for metadata and classification, but it does not enforce data masking or access control by itself. While tags can be used in conjunction with policies, the primary feature for dynamic column-level masking is Dynamic Data Masking. Object Tagging alone would not mask the data; it would only label it, requiring additional logic to enforce masking.

  • ✗

    Secure Views that filter the data based on the current role.

    Why it's wrong here

    Secure Views can restrict access to data, but they are not designed for column-level masking. A secure view would require creating separate views for each role or using conditional logic within the view definition, which is not as centralized or reusable as masking policies. Additionally, secure views hide the view definition, but they do not provide dynamic masking based on role at the column level.

About these practice questions

This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.