Courseiva
Data Governance →mediumMultiple Choice

DEA-C02 Data Governance Practice Question

A company requires that data masking policies be applied automatically whenever a column is tagged with 'PII'. How can this be achieved?

⚠ Common exam trap

Candidates often assume they need to write complex stored procedures or triggers to apply masking. They overlook the native, declarative 'tag-based' feature designed to automate this exact process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use tag-based masking policies.

Tag-based masking policies provide a direct link between metadata tagging and security enforcement. By associating a masking policy with a specific tag, any column assigned that tag automatically inherits the associated masking behavior. This automation is crucial for governance, as it prevents manual errors and ensures that sensitive data is never exposed simply because someone forgot to manually attach a policy to a new column.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Write a stored procedure to trigger on every DDL statement.

    Why it's wrong here

    Stored procedures cannot natively intercept and act on DDL statements automatically without complex event-driven architecture. Relying on custom scripts for governance is fragile, prone to failure, and does not provide the robust, native enforcement that tag-based masking offers within the Snowflake security framework.

  • ✓

    Use tag-based masking policies.

    Why this is correct

    Tag-based masking policies allow you to define a masking policy and associate it with a specific tag. When the tag is applied to a column, the masking policy is automatically applied. This streamlines governance, reduces maintenance, and ensures consistency across large, evolving datasets in the enterprise.

  • ✗

    Use a Row Access Policy with a conditional tag check.

    Why it's wrong here

    Row Access Policies filter rows, not columns. While they can check for tags, they are not the appropriate mechanism for masking column-level data. Attempting to use row-level logic for column-level masking would lead to unnecessary complexity and performance overhead without achieving the desired obfuscation effect.

  • ✗

    Manually apply the masking policy every time a table is created.

    Why it's wrong here

    Manual processes are inherently unscalable and prone to human error. In a large-scale data environment, manual security application leads to 'security drift,' where new tables go unprotected. Automated tag-based policies ensure that compliance is enforced by design, not by the diligence of individual data engineers.

About these practice questions

This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.