DEA-C02 Data Governance Practice Question
A company requires that data masking policies be applied automatically whenever a column is tagged with 'PII'. How can this be achieved?
⚠ Common exam trap
Candidates often assume they need to write complex stored procedures or triggers to apply masking. They overlook the native, declarative 'tag-based' feature designed to automate this exact process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use tag-based masking policies.
Tag-based masking policies provide a direct link between metadata tagging and security enforcement. By associating a masking policy with a specific tag, any column assigned that tag automatically inherits the associated masking behavior. This automation is crucial for governance, as it prevents manual errors and ensures that sensitive data is never exposed simply because someone forgot to manually attach a policy to a new column.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write a stored procedure to trigger on every DDL statement.
Why it's wrong here
Stored procedures cannot natively intercept and act on DDL statements automatically without complex event-driven architecture. Relying on custom scripts for governance is fragile, prone to failure, and does not provide the robust, native enforcement that tag-based masking offers within the Snowflake security framework.
- ✓
Use tag-based masking policies.
Why this is correct
Tag-based masking policies allow you to define a masking policy and associate it with a specific tag. When the tag is applied to a column, the masking policy is automatically applied. This streamlines governance, reduces maintenance, and ensures consistency across large, evolving datasets in the enterprise.
- ✗
Use a Row Access Policy with a conditional tag check.
Why it's wrong here
Row Access Policies filter rows, not columns. While they can check for tags, they are not the appropriate mechanism for masking column-level data. Attempting to use row-level logic for column-level masking would lead to unnecessary complexity and performance overhead without achieving the desired obfuscation effect.
- ✗
Manually apply the masking policy every time a table is created.
Why it's wrong here
Manual processes are inherently unscalable and prone to human error. In a large-scale data environment, manual security application leads to 'security drift,' where new tables go unprotected. Automated tag-based policies ensure that compliance is enforced by design, not by the diligence of individual data engineers.
About these practice questions
This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.