ARA-C01 Accounts and Security Practice Question
Which of the following describes the correct behavior of a Masking Policy applied to a column that is also referenced in a Row Access Policy?
⚠ Common exam trap
Candidates often assume the masking policy applies first to hide data before row access evaluation, failing to realize Snowflake evaluates the row access policy first to determine which rows are visible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Row Access Policy is evaluated first.
Snowflake enforces policies in a specific sequence. When both Row Access and Masking Policies are present, the Row Access Policy is evaluated first to determine the visible rows, and then the Masking Policy is applied to the visible data. This ensures that the security constraints are applied logically and cumulatively. This behavior is crucial for preventing information leakage, ensuring that users cannot bypass row-level filters by using column-level masking logic or vice versa, providing a consistent security model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Masking Policy is evaluated first.
Why it's wrong here
Evaluation order in Snowflake is fixed; Row Access Policies always take precedence to determine which rows are even accessible. Applying a masking policy first would be logically incorrect because the system must first identify the subset of data to return before applying any field-level obfuscation to those specific results.
- ✓
The Row Access Policy is evaluated first.
Why this is correct
Snowflake evaluates the Row Access Policy first to determine the rows that the user is permitted to see. Once the result set is filtered at the row level, the Masking Policies are applied to the columns to ensure that sensitive data is appropriately obfuscated for the current user's session.
- ✗
Only the Masking Policy is applied.
Why it's wrong here
Both policies remain active and are applied in sequence. Snowflake's security architecture is designed to enforce both simultaneously to ensure comprehensive data protection. Ignoring the Row Access Policy would expose potentially restricted rows, violating the security requirements and creating a significant vulnerability within the data access layer.
- ✗
Only the Row Access Policy is applied.
Why it's wrong here
Masking and Row Access Policies serve complementary purposes and are both evaluated when defined on a table. Relying solely on the row-level filter would fail to protect sensitive column values within the allowed rows, leaving sensitive data vulnerable and failing to meet the organization's comprehensive data privacy requirements.
About these practice questions
This ARA-C01 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This ARA-C01 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ARA-C01 exam.