Courseiva
Data Governance →hardMultiple Choice

DEA-C02 Data Governance Practice Question

A financial institution uses Snowflake to store customer transactions. A data engineer needs to implement a policy that restricts access to rows in the TRANSACTIONS table based on the department of the user. The department information is stored in a lookup table named USER_DEPARTMENT. The policy must be applied dynamically without modifying the TRANSACTIONS table. Which Snowflake feature should the engineer use?

⚠ Common exam trap

The trap here is assuming that masking policies can filter rows, when they only mask column values, or that secure views are sufficient without revoking base table access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a Row Access Policy that uses a mapping table to determine the user's department and filters rows accordingly.

Row Access Policies are designed to filter rows based on user attributes or mapping tables. They attach to tables and enforce filtering at query time, making them ideal for dynamic row-level security. Secure views can be bypassed if base table access is granted, and masking policies only affect column values, not row visibility. Thus, a Row Access Policy is the correct solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a Row Access Policy that uses a mapping table to determine the user's department and filters rows accordingly.

    Why this is correct

    A Row Access Policy is a schema-level object that can be added to a table to filter rows based on conditions evaluated at query time. It can reference a mapping table like USER_DEPARTMENT to dynamically determine the user's department and restrict rows. This meets the requirement of dynamic filtering without altering the table structure. It is the correct feature for row-level security in Snowflake.

  • ✗

    Create a secure view that joins TRANSACTIONS with USER_DEPARTMENT and filters rows based on the current user's department.

    Why it's wrong here

    A secure view can restrict data, but it requires users to query the view instead of the base table. If users have access to the base table, they can bypass the view. The requirement is to apply the policy dynamically without modifying the table, implying that access to the table itself should be filtered. A row access policy is more appropriate because it attaches directly to the table and enforces filtering regardless of how the table is queried.

  • ✗

    Use a Column-level Security policy with a masking policy that returns NULL for rows not belonging to the user's department.

    Why it's wrong here

    Column-level Security and masking policies are designed to mask column values, not to filter rows. They cannot restrict which rows are returned; they only alter the data within columns. Using a masking policy to simulate row filtering would still return all rows, just with some values masked, which does not meet the requirement of restricting access to specific rows. Therefore, this option is incorrect.

  • ✗

    Create a dynamic data masking policy that checks the user's department and masks the entire row if the department does not match.

    Why it's wrong here

    Dynamic data masking policies operate on columns and cannot mask entire rows. They can only transform column values. There is no mechanism to mask a row as a whole; masking is column-specific. To restrict rows, a row access policy is needed. This option misunderstands the scope of masking policies and would not achieve the desired row-level filtering.

About these practice questions

This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.