Courseiva
Data Governance →mediumMultiple Choice

DEA-C02 Data Governance Practice Question

A data engineer needs to categorize columns across multiple databases with custom business tags such as COST_CENTER and DATA_OWNER, and then enforce that only users with the TAG_ADMIN role can modify those tags. Which Snowflake feature should the engineer use to meet this requirement?

⚠ Common exam trap

The trap here is conflating Data Classification's system tags with custom business tags, when only object tagging supports user-defined tags and the APPLY TAG privilege model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Object tagging with a tag created via CREATE TAG, assigning tags to columns with ALTER TABLE ... SET TAG, and granting the APPLY TAG privilege only to TAG_ADMIN.

Object tagging is Snowflake's mechanism for attaching custom metadata labels to columns and other objects. Tags are created with CREATE TAG, applied with ALTER TABLE ... SET TAG, and their modification is governed by the APPLY TAG privilege on the tag itself. Granting APPLY TAG only to TAG_ADMIN restricts who can change the tags, satisfying both categorization and access-control needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A masking policy that returns the tag value for authorized roles and NULL for others.

    Why it's wrong here

    Masking policies transform column values at query time; they do not assign or store metadata tags on objects. Using a masking policy to simulate tagging would not create queryable tag metadata, would not integrate with tag-based governance views, and would not provide the APPLY TAG privilege model. The requirement is about metadata categorization and controlled tag assignment, which is the domain of object tagging, not masking.

  • ✓

    Object tagging with a tag created via CREATE TAG, assigning tags to columns with ALTER TABLE ... SET TAG, and granting the APPLY TAG privilege only to TAG_ADMIN.

    Why this is correct

    Snowflake's native object tagging allows custom tags to be created with CREATE TAG, applied to columns, tables, and other objects, and governed through the APPLY TAG privilege on the tag. By granting APPLY TAG only to TAG_ADMIN, the engineer ensures only that role can assign or change the tag on objects. This directly satisfies both the categorization and the access-control requirements using a single governance feature.

  • ✗

    Snowflake Data Classification, which automatically detects and tags columns with system tags.

    Why it's wrong here

    Data Classification uses system-defined tags such as SNOWFLAKE.CORE.SEMANTIC_CATEGORY and SNOWFLAKE.CORE.PRIVACY_CATEGORY, and it is designed for automatic discovery of sensitive data rather than custom business tags like COST_CENTER or DATA_OWNER. It also does not provide a mechanism to restrict tag modification to a specific role in the way the requirement describes. Custom governance tags require the object tagging feature instead.

  • ✗

    Access control policies created with CREATE ACCESS POLICY and bound to the target columns.

    Why it's wrong here

    Snowflake does not have a CREATE ACCESS POLICY object for column-level tagging. Access control in Snowflake is handled through role-based privileges, masking policies, row access policies, and object tagging. There is no native object called an access policy that would categorize columns with custom business tags. This option describes a feature that does not exist in Snowflake, so it cannot meet the requirement.

About these practice questions

Courseiva writes every DEA-C02 question from scratch — 229 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.