Courseiva
Data Governance →easyMultiple Choice

DEA-C02 Data Governance Practice Question

A data engineer needs to ensure that a column containing credit card numbers is masked for all users except those with the PAYMENT_ADMIN role. The masking should be applied consistently across all tables that use a specific tag. Which Snowflake feature should the engineer use?

⚠ Common exam trap

The trap here is choosing manual column attachment or secure views when the requirement specifies consistency across all tables using a tag, which is exactly what tag-based masking provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A tag-based masking policy that is associated with a tag and automatically applies to all columns with that tag.

Tag-based masking policies associate a masking policy with a tag, so that any column assigned that tag automatically inherits the masking behavior. This provides consistent, scalable protection across all tables, including future columns. It eliminates the need to manually attach policies to each column, ensuring that credit card numbers are masked for unauthorized users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A row access policy that filters rows based on the user's role.

    Why it's wrong here

    Row access policies filter rows, not columns. They cannot mask column values. While they can restrict which rows a user sees, they do not obfuscate credit card numbers. The requirement is to mask the column data, so a row access policy is the wrong feature.

  • ✗

    A standard masking policy attached directly to each column containing credit card numbers.

    Why it's wrong here

    A standard masking policy must be manually attached to each column, which is error-prone and does not ensure consistency across all tables. The requirement is to apply masking based on a tag, so that any column with that tag is automatically protected. Manual attachment would require ongoing maintenance and could miss new columns.

  • ✗

    A secure view that excludes the credit card column for non-admin users.

    Why it's wrong here

    A secure view can hide columns, but it requires creating and maintaining separate views for different user groups. It does not automatically apply to all tables with a tag. This approach is not scalable and does not ensure consistent masking across the environment. Tag-based masking is designed for this purpose.

  • ✓

    A tag-based masking policy that is associated with a tag and automatically applies to all columns with that tag.

    Why this is correct

    Tag-based masking policies allow you to associate a masking policy with a tag. When the tag is applied to a column, the masking policy is automatically enforced. This ensures consistent protection across all tables that use the tag, and new columns tagged later are automatically covered. It meets the requirement for consistent masking based on a tag.

About these practice questions

This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.