DEA-C02 Data Governance Practice Question
A data engineer is implementing a data governance strategy and needs to ensure that all tables containing sensitive data are automatically identified and tagged. The engineer wants to use Snowflake's native classification capabilities and then apply masking policies based on those tags. Which sequence of steps should the engineer follow?
⚠ Common exam trap
The trap here is assuming that masking policies can be applied based on tags automatically, or that tags themselves enforce masking, when in fact policies must be manually attached to columns after classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run Data Classification, review results, then create and attach masking policies to tagged columns.
Data Classification is the native feature that automatically scans and tags sensitive columns. Once tagged, the engineer can review the tags and then create masking policies attached to those columns. This ensures that policies are applied to the correct columns without manual discovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually apply tags, then create masking policies that reference those tags.
Why it's wrong here
Manual tagging is error-prone and does not automatically identify sensitive data. The requirement is to automatically identify and tag, so this approach fails to meet the automation goal. Additionally, masking policies cannot directly reference tags; they must be attached to columns.
- ✗
Create masking policies first, then run Data Classification to tag columns.
Why it's wrong here
Masking policies are attached to columns and do not depend on tags. Running classification after creating policies would not automatically apply those policies to newly tagged columns; manual attachment is still required. This order does not leverage classification to drive policy application.
- ✗
Use Access History to identify sensitive columns, then manually tag them.
Why it's wrong here
Access History records access to columns that already have tags; it does not identify sensitive data. Using it to find sensitive columns is not feasible. Manual tagging is also not automatic, so this approach does not meet the requirement.
- ✓
Run Data Classification, review results, then create and attach masking policies to tagged columns.
Why this is correct
Data Classification automatically scans tables and identifies sensitive columns, applying system tags. After reviewing the results, the engineer can create masking policies and attach them to the tagged columns. This sequence leverages automation and ensures policies are applied where needed.
About these practice questions
One of 229 original DEA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.