DEA-C02 Data Governance Practice Question
A data engineer needs to ensure that only users with the role FINANCE_ANALYST can view the SALARY column in the EMPLOYEES table. All other users should see a masked value. Which Snowflake feature should the engineer use?
⚠ Common exam trap
Many exam-takers confuse row-level security with column-level security, or assuming that tags enforce access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Masking Policy
A masking policy is the correct feature for column-level security. It allows conditional masking based on the user's role, ensuring that only FINANCE_ANALYST sees the actual salary. Row access policies filter rows, secure views can be bypassed, and tags are for metadata. Thus, a masking policy is the right choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Row Access Policy
Why it's wrong here
Row Access Policies filter rows based on conditions, not columns. They control which rows a user can see, not which columns. To restrict access to a specific column, a masking policy is needed. Using a row access policy here would not achieve the goal of hiding the SALARY column for unauthorized users, as it would still return the column with all rows visible.
- ✗
Object Tag
Why it's wrong here
Object tags are metadata labels used for governance and classification, but they do not enforce access control. Tagging the SALARY column with a tag does not automatically mask it. While tags can be used in conjunction with masking policies, the tag itself does not provide the masking functionality. Therefore, this option does not solve the requirement.
- ✓
Masking Policy
Why this is correct
A masking policy is applied to a column and can conditionally mask its values based on the user's role. By creating a masking policy that returns the actual salary for FINANCE_ANALYST and a masked value for others, the engineer can meet the requirement. This is the standard Snowflake feature for column-level security and dynamic data masking.
- ✗
Secure View
Why it's wrong here
A secure view can be used to present a modified version of the table, but it requires users to query the view instead of the table. If users have access to the base table, they can bypass the view. Additionally, managing access to the view and table adds complexity. A masking policy directly on the column is more straightforward and enforces the restriction regardless of how the table is accessed.
About these practice questions
One of 229 original DEA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.