Courseiva
Data Governance →mediumMultiple Choice

DEA-C02 Data Governance Practice Question

A Snowflake data engineer has been tasked with implementing dynamic data masking on a CUSTOMERS table so that the SSN column is fully redacted for all users except those with the role PII_ADMIN. The engineer wants the masking to apply automatically whenever the column is queried, without changing any application SQL. Which Snowflake object should the engineer create and attach to the SSN column?

⚠ Common exam trap

The trap here is assuming that tagging a sensitive column or building a secure view is equivalent to enforcing dynamic masking, when only an attached masking policy actually rewrites the value at query time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A masking policy created with CREATE MASKING POLICY and applied to the SSN column using ALTER TABLE ... MODIFY COLUMN ... SET MASKING POLICY.

Dynamic column redaction in Snowflake is implemented with masking policies, which are schema-level objects attached directly to a column. Once attached, the policy expression evaluates on every query, returning the original value to authorized roles and a masked value to others, with no application changes required. This satisfies both the automatic enforcement requirement and the role-based exception for PII_ADMIN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A masking policy created with CREATE MASKING POLICY and applied to the SSN column using ALTER TABLE ... MODIFY COLUMN ... SET MASKING POLICY.

    Why this is correct

    A masking policy is the native Snowflake column-level security object designed for this exact scenario. Creating it with CREATE MASKING POLICY and attaching it via ALTER TABLE ... MODIFY COLUMN ... SET MASKING POLICY makes the policy evaluate on every query of the SSN column, returning the raw value only to roles listed in the policy body (such as PII_ADMIN) and a redacted value to everyone else. No application SQL changes are needed.

  • ✗

    A row access policy created with CREATE ROW ACCESS POLICY and attached to the CUSTOMERS table.

    Why it's wrong here

    Row access policies filter which rows are visible based on a predicate, they do not redact or transform column values. Attaching a row access policy to CUSTOMERS would hide entire customer records from unauthorized users rather than obscuring the SSN value within visible rows. The requirement is to redact the SSN column for non-admins while still returning the rest of the row, so a row access policy does not satisfy the scenario.

  • ✗

    A secure view that selects all columns from CUSTOMERS but replaces SSN with a constant for non-admins.

    Why it's wrong here

    A secure view can hide the underlying definition, but it requires applications to query the view instead of the base table, which violates the requirement that no SQL changes be made. It also does not automatically apply to direct queries against CUSTOMERS. A masking policy is attached to the column itself and applies regardless of how the column is accessed, making the secure view approach unnecessary and operationally fragile here.

  • ✗

    A tag-based classification using ALTER TABLE ... SET TAG on the SSN column.

    Why it's wrong here

    Tags are metadata labels used for classification, tracking, and policy association, but a tag alone does not redact data. Setting a tag on the SSN column would help identify it as sensitive, yet queries would still return the raw SSN unless a masking policy is separately attached. Tags are useful for governance discovery and for tag-based masking in some patterns, but by themselves they do not enforce dynamic redaction at query time.

About these practice questions

One of 229 original DEA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.