DEA-C02 Data Governance Practice Question
A financial services firm stores customer records in a table called TRANSACTIONS. The compliance team requires that a specific column, CREDIT_CARD_NUMBER, be transformed so that only the last four digits are visible to all users except members of the role PAYMENT_ADMIN. Additionally, the transformation must occur at query time without modifying the stored data. Which Snowflake feature should the data engineer use to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse row-level filtering with column-level masking, or assuming that a secure view alone can provide role-based conditional masking without a masking policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A masking policy applied to the CREDIT_CARD_NUMBER column.
The requirement is to dynamically mask a column based on the user's role while preserving the original data. A masking policy attached to the column evaluates at query time and can return different values depending on the role. It does not alter stored data, and it can show only the last four digits for non-privileged roles while revealing the full value for PAYMENT_ADMIN. This is the standard Snowflake method for column-level dynamic data masking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A tag-based masking policy using the TAG_STRING system function.
Why it's wrong here
While tag-based masking policies exist, the TAG_STRING function is not a valid Snowflake function for retrieving tag values in this context. The requirement does not mention tags; it specifies role-based masking. Using a tag-based approach adds unnecessary complexity and does not directly address the need for a role condition on the CREDIT_CARD_NUMBER column.
- ✗
A row access policy applied to the TRANSACTIONS table.
Why it's wrong here
A row access policy filters which rows a user can see based on conditions, but it does not transform column values. It cannot obscure a portion of a column's content; it only includes or excludes entire rows. Since the requirement is to mask the credit card number while still returning the row, a row access policy is not appropriate.
- ✓
A masking policy applied to the CREDIT_CARD_NUMBER column.
Why this is correct
A masking policy is a schema-level object that can be attached to a column and evaluates at query time. It can inspect the user's role and conditionally return a masked value, such as showing only the last four digits, while storing the original data unchanged. This directly satisfies the requirement for dynamic, role-based transformation without altering the underlying table data.
- ✗
A secure view that selects only the last four digits of the column.
Why it's wrong here
A secure view can restrict access and hide the view definition, but it does not provide conditional, role-based masking within the same column for different users. To achieve role-based masking, you would still need a masking policy inside the view. A plain secure view cannot dynamically decide which users see the full value and which see the masked value without additional policy logic.
About these practice questions
This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.