DEA-C02 Data Governance Practice Question
A data engineer needs to prevent any future column additions to a critical ORDERS table from containing unprotected PII. The goal is to automatically classify new columns and receive alerts when sensitive data is detected. Which Snowflake feature should be configured to achieve this?
⚠ Common exam trap
The trap here is assuming that masking policies or tags alone provide automatic detection of new sensitive columns, when only Data Classification offers that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Classification with automatic tagging and notifications
Data Classification is designed to automatically scan and classify columns containing sensitive data, including PII. It can be configured to send notifications when new sensitive columns are detected, providing ongoing governance without manual effort. This directly addresses the need to protect future column additions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Classification with automatic tagging and notifications
Why this is correct
Data Classification scans tables and views to identify PII and other sensitive data. When enabled on a table, it automatically tags columns and can send notifications via email or integration when new sensitive columns are detected, ensuring ongoing protection.
- ✗
Object Tagging with manual tag assignment
Why it's wrong here
Object Tagging allows manual assignment of tags to objects, but it does not automatically classify new columns or send alerts. It relies on human intervention and cannot ensure that future columns are protected without additional automation, which is not provided natively.
- ✗
Dynamic Data Masking policies on the table
Why it's wrong here
Dynamic Data Masking policies mask data at query time based on user roles, but they do not automatically detect or classify new columns. They require manual policy assignment and do not provide alerts for new sensitive data, so they fail to meet the requirement of automatic classification.
- ✗
Row Access Policies on the table
Why it's wrong here
Row Access Policies filter rows based on conditions but do not classify columns or detect sensitive data. They are used for row-level security, not for identifying PII or alerting on new columns, so they are irrelevant to the scenario.
About these practice questions
One of 229 original DEA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.