ARA-C01 Accounts and Security Practice Question
Which feature is essential for ensuring that queries on PII (Personally Identifiable Information) columns are masked from unauthorized users?
⚠ Common exam trap
Candidates suggest creating restricted views or separate physical tables, which violates the requirement for dynamic, policy-driven column protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Data Masking (DDM).
Dynamic Data Masking is the correct feature for protecting sensitive data like PII. It allows an architect to apply a policy to a table column that masks the data based on the user's role. This ensures that unauthorized users see masked, non-sensitive versions of the data, while authorized users see the original raw values, providing a robust solution for compliance and data protection without duplicating data or creating complex views.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Row-Level Security (RLS).
Why it's wrong here
Row-Level Security is used to restrict the number of rows visible to a user based on their role or attributes, not for masking specific column values. While it is a valuable security control, it does not provide the column-level obfuscation required to protect PII within a dataset that a user is allowed to view.
- ✓
Dynamic Data Masking (DDM).
Why this is correct
Dynamic Data Masking is specifically designed to redact or obfuscate sensitive data at query time based on the active role of the user. This is the optimal way to handle PII as it ensures data integrity while allowing for functional access to the rest of the table's data, meeting compliance standards for data security.
- ✗
Data Encryption at Rest.
Why it's wrong here
Data encryption at rest is an automatic background feature that secures the raw files on disk. It does not provide any logical masking of column data within the query interface. Even with encryption at rest, a user who has SELECT access to a table will see the raw, unmasked data in their query results.
- ✗
Object Tagging.
Why it's wrong here
Object tagging is used for metadata management and tracking data lifecycle, such as marking a column as containing PII. It has no functional impact on data access or visibility. Tagging a column does not automatically enforce any security or masking rules, so it is insufficient for preventing unauthorized access to sensitive PII data.
About these practice questions
One of 209 original ARA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.