Courseiva
Data Governance →mediumMultiple Choice

DEA-C02 Data Governance Practice Question

A data engineer needs to ensure that PII data in the 'SALES' table is obscured for non-admin users while maintaining original data types for downstream analytical models. Which approach provides the most scalable governance?

⚠ Common exam trap

Candidates often suggest creating separate views or physical copies of tables, which is inefficient and violates the principle of a single source of truth for governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a masking policy to the columns and grant the APPLY MASKING POLICY privilege.

Dynamic Data Masking allows policies to be applied to columns based on the user's role without duplicating data. By leveraging masking policies, you maintain a single source of truth while ensuring sensitive information is protected at query runtime. This method is highly scalable as a single policy can be assigned to multiple columns across different tables, simplifying maintenance and ensuring consistent security posture across the enterprise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create separate secure views for every user role requiring masked access.

    Why it's wrong here

    Creating views for every role leads to a 'view explosion' problem, making maintenance difficult as schema changes occur. Security overhead increases significantly, and performance optimizations like query result caching may be less effective compared to native masking policies that apply directly to the base table column.

  • ✓

    Apply a masking policy to the columns and grant the APPLY MASKING POLICY privilege.

    Why this is correct

    Applying a masking policy directly to columns provides a centralized way to enforce data governance. By granting the APPLY MASKING POLICY privilege to a governance role, you ensure that security policies are managed by the data security team rather than the database owners, following the principle of least privilege.

  • ✗

    Use row-level security to filter rows containing PII data for authorized users.

    Why it's wrong here

    Row-level security restricts access to entire rows, not specific columns within a row. If an analyst requires access to sales figures but not the customer name, row-level security would hide the entire record, preventing the analyst from performing necessary aggregations on the sales metrics.

  • ✗

    Physically transform the data during the ETL process and store it in a new table.

    Why it's wrong here

    Physical transformation creates data silos and increases storage costs. It also makes data recovery or ad-hoc analysis of raw data impossible for authorized personnel. Governance best practices favor keeping data in its original state while using Snowflake's native policy features to control access and visibility at runtime.

About these practice questions

This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.