ARA-C01 Accounts and Security Practice Question
A security architect is designing a Snowflake environment for a company with strict data governance requirements. They need to implement column-level security to mask sensitive data based on the user's role and also track which columns are being accessed by which users. Which two Snowflake features should the architect use to achieve these goals? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse row-level security with column-level security and assuming that Object Tagging or Secure Views can provide access tracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Data Masking
The requirements are to mask sensitive data based on role and to track column access. Dynamic Data Masking provides column-level masking based on the user's role, satisfying the first requirement. Access History records which columns are accessed by which queries and users, satisfying the second requirement. Row Access Policies filter rows, Object Tagging is for classification, and Secure Views do not provide the needed masking or auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dynamic Data Masking
Why this is correct
Dynamic Data Masking allows you to apply masking policies to columns so that users see masked values unless they have the appropriate role. This directly addresses the requirement to mask sensitive data based on role. Masking policies are evaluated at query time and can reference CURRENT_ROLE(), making them ideal for column-level security.
- ✗
Secure Views
Why it's wrong here
Secure Views can hide the underlying data and logic, but they do not provide column-level masking based on role, nor do they track column access. They are used to prevent exposure of underlying tables and to optimize performance, but they do not fulfill the specific requirements of dynamic masking and access auditing.
- ✗
Object Tagging
Why it's wrong here
Object Tagging allows you to assign tags to objects for classification and governance, but it does not mask data or track access. It can be used to identify sensitive columns, but it does not enforce masking or provide access history. It is a metadata feature, not an enforcement or auditing mechanism for column access.
- ✗
Row Access Policies
Why it's wrong here
Row Access Policies filter rows based on conditions, not columns. They are used to restrict which rows a user can see, not to mask column values or track column access. While they are a security feature, they do not meet the requirements of column-level masking and access tracking.
- ✓
Access History
Why this is correct
Access History captures which columns were read or written by a query, along with the user and role. This feature provides the auditing capability to track column-level access. It records the objects and columns accessed, enabling the architect to monitor who accessed which sensitive columns.
About these practice questions
One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.