DEA-C02 Data Governance Practice Question
A data steward at a financial services company needs to automatically detect and tag columns containing Social Security numbers across all schemas in the PROD database. The steward wants the tagging to be applied without manually inspecting each table and to leverage Snowflake's built-in classifiers. Which approach should the steward use?
⚠ Common exam trap
The trap here is assuming that column name pattern matching or manual tagging is sufficient for sensitive data detection, when only Data Classification analyzes actual data values and applies system-defined tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Snowflake Data Classification with a system-defined SSN semantic category and apply it to the PROD database.
Snowflake Data Classification automatically scans tables and views to identify sensitive data using system-defined semantic categories, including SSN. Applying it to a database scans all contained schemas and tables, tagging columns that match the SSN pattern. This meets the requirement for automatic detection and tagging without manual intervention, leveraging native governance features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Snowflake Access History and use it to identify columns that have been queried with SSN patterns.
Why it's wrong here
Access History records query access to tables and columns but does not classify or tag data based on content. It tracks who accessed what, not what type of data exists. Using it to detect SSN columns would be indirect and unreliable, as it depends on past query patterns rather than actual data inspection. It also does not apply tags automatically.
- ✓
Use Snowflake Data Classification with a system-defined SSN semantic category and apply it to the PROD database.
Why this is correct
Snowflake Data Classification includes built-in semantic categories such as SSN that automatically identify and tag columns containing Social Security numbers. By applying classification to the entire PROD database, the steward can scan all schemas and tables without manual effort. The system assigns tags like SNOWFLAKE.CORE.SSN to matching columns, enabling automated governance.
- ✗
Write a stored procedure that queries INFORMATION_SCHEMA.COLUMNS for column names containing 'SSN' and applies a tag.
Why it's wrong here
Querying column names for 'SSN' only detects columns with that string in their name, missing columns like 'TAX_ID' or 'SOCIAL_SECURITY_NUMBER' that contain SSN data but lack obvious naming. This method does not analyze data patterns and cannot reliably identify sensitive information. It also requires custom code maintenance and does not use Snowflake's native classification capabilities.
- ✗
Create a custom tag called SSN_TAG and manually apply it to every column that appears to contain SSN data.
Why it's wrong here
Manual tagging is labor-intensive and error-prone, especially across a large database. It does not leverage Snowflake's built-in classifiers and cannot automatically detect SSN patterns. The steward would need to inspect each table individually, which contradicts the requirement for automatic detection. This approach also lacks the semantic categorization that Data Classification provides.
About these practice questions
One of 229 original DEA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.