DEA-C02 Data Governance Practice Question
A Snowflake account has a tag-based masking policy on column CUSTOMER.SSN. An analyst runs a query that applies the SYSTEM$GET_TAG function to that column. The analyst has been granted the APPLY MASKING POLICY privilege on the tag, but not the USAGE privilege on the tag. What does the analyst see for the SSN column value?
⚠ Common exam trap
The trap here is assuming that lacking USAGE on a tag disables its masking policy or causes an error, when in fact the policy remains enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The masked SSN value, because the masking policy is enforced regardless of tag privileges.
Masking policies attached to tags are enforced regardless of whether the querying user can read the tag. A user without USAGE on the tag cannot see tag metadata but still receives masked data because the policy is evaluated at query time against the column. APPLY MASKING POLICY is an administrative privilege for managing tag-policy associations, not for bypassing enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NULL, because the masking policy cannot be resolved without tag access.
Why it's wrong here
The masking policy is resolved at the object level, not by the user's tag privileges. Lack of USAGE on the tag does not cause the masking policy to fail or return NULL. The policy still applies and returns the masked representation as defined, such as a fixed string or partial value.
- ✗
An error, because the analyst lacks USAGE on the tag required to evaluate the masking policy.
Why it's wrong here
USAGE on a tag is required to view or assign the tag, not to evaluate a masking policy that is already attached to it. The masking policy evaluation does not require the querying user to have USAGE on the tag. The query succeeds and returns the masked value rather than an error.
- ✗
The unmasked SSN value, because APPLY MASKING POLICY overrides tag visibility.
Why it's wrong here
APPLY MASKING POLICY controls the ability to associate a masking policy with a tag, not the ability to bypass masking. Without USAGE on the tag, the analyst cannot see the tag's value, but masking is still applied based on the tag assignment. The privilege that determines whether masking is enforced is USAGE on the tag, not APPLY MASKING POLICY.
- ✓
The masked SSN value, because the masking policy is enforced regardless of tag privileges.
Why this is correct
Tag-based masking policies are enforced based on the tag assignment and the masking policy's conditions, independent of the user's privileges on the tag itself. The analyst lacks USAGE on the tag, so they cannot see the tag metadata, but the masking policy still applies to the column when queried. Thus the SSN appears masked.
About these practice questions
Courseiva writes every DEA-C02 question from scratch — 229 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.