DEA-C02 · domain
Data Governance
This domain covers Snowflake governance primitives: access auditing via ACCOUNT_USAGE and ACCESS_HISTORY, Object Tagging, masking and row access policies, and secure data sharing. Questions present audit queries, policy designs, or sharing scenarios and ask you to interpret lineage output, pick correct governance combinations, or identify performance and correctness trade-offs.
Focused practice
Practice Data Governance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Data Governance
Be able to query ACCESS_HISTORY to explain column lineage, attach tags for cost and classification, and combine masking with sharing. The critical skill is designing Row Access Policies whose mapping-table joins stay performant and deterministic while enforcing least-privilege access.
Reading ACCESS_HISTORY and base_objects_accessed to trace column-level data lineage across queries
Applying Object Tagging for cost attribution, classification, and tag-based masking policies
Combining Dynamic Data Masking with Secure Data Sharing to expose masked subsets to third parties
Designing Row Access Policies that join mapping tables and evaluating their query performance impact
Watch out for
Common Data Governance exam traps
- ▸Assuming base_objects_accessed shows only direct tables, ignoring that it captures upstream base tables behind views and CTEs
- ▸Confusing tag-based masking with direct masking policies, or expecting tags alone to mask data without a masking policy attached
- ▸Writing Row Access Policies with non-deterministic or heavy subqueries against mapping tables, causing scan and join overhead per row
Question index
All Data Governance questions (42)
Click any question to see the full explanation, or start a practice session above.
A data engineer is implementing a data classification process using Snowflake's Data Classification feature. The engineer wants to automatically classify columns containing sensitive data and then use the results to apply masking policies. After running the classification, the engineer notices that some columns that should be classified as 'EMAIL' are not being tagged. The engineer has verified that the data contains valid email addresses. What is the most likely reason for the missing classification?
Hard2A data engineer needs to prevent any future column additions to a critical ORDERS table from containing unprotected PII. The goal is to automatically classify new columns and receive alerts when sensitive data is detected. Which Snowflake feature should be configured to achieve this?
Easy3What is the primary purpose of a 'Secure View' in Snowflake from a governance perspective?
Easy4A data engineer is responsible for implementing data governance in Snowflake. The organization requires that all access to sensitive data be auditable and that data usage can be attributed to specific users and roles. Which two Snowflake features should the engineer use to meet these requirements? (Choose two.)
Medium5Refer to the exhibit. A security administrator executes this query to audit access to a sensitive table. What specific information is captured in the 'base_objects_accessed' column regarding the data lineage of this query?
Hard6A financial services firm stores account balances in a Snowflake table ACCOUNTS. A row access policy is defined so that analysts see only rows where REGION = CURRENT_REGION(). The firm also attaches a masking policy to the BALANCE column that returns NULL for users without the FINANCE role. An analyst with the ANALYST role queries SELECT REGION, BALANCE FROM ACCOUNTS. What will the analyst see?
Hard7An organization wants to classify their data to identify PII. Which feature should they use to automatically tag columns containing sensitive information?
Easy8Which governance tool allows an administrator to audit who accessed a specific table and when?
Medium9A data engineer needs to audit all tag assignments across the account to ensure that no sensitive columns are missing required tags. Which Snowflake view should the engineer query to retrieve a list of all tags applied to columns, including the tag name, value, and the object it is applied to?
Medium10A data engineer is setting up Snowflake Data Classification on a table containing customer feedback. The engineer wants to ensure that the classification process identifies columns with potentially sensitive information and tags them appropriately. Which two actions are required to enable Data Classification on the table? (Choose two.)
Medium11A Snowflake data engineer has been tasked with implementing dynamic data masking on a CUSTOMERS table so that the SSN column is fully redacted for all users except those with the role PII_ADMIN. The engineer wants the masking to apply automatically whenever the column is queried, without changing any application SQL. Which Snowflake object should the engineer create and attach to the SSN column?
Medium12What is the primary purpose of the 'SNOWFLAKE.ACCOUNT_USAGE' schema in a governance context?
Easy13A data engineer is implementing a data governance strategy and needs to ensure that all tables containing sensitive data are automatically identified and tagged. The engineer wants to use Snowflake's native classification capabilities and then apply masking policies based on those tags. Which sequence of steps should the engineer follow?
Medium14A financial institution uses Snowflake to store customer transactions. A data engineer needs to implement a policy that restricts access to rows in the TRANSACTIONS table based on the department of the user. The department information is stored in a lookup table named USER_DEPARTMENT. The policy must be applied dynamically without modifying the TRANSACTIONS table. Which Snowflake feature should the engineer use?
Hard15A data engineer needs to audit all grants of the 'SYSADMIN' role to users across the Snowflake account. The engineer has access to the ACCOUNTADMIN role and wants to retrieve this information efficiently. Which Snowflake view should be queried?
Hard16An auditor requests proof of who has accessed a specific table containing sensitive data. Which Snowflake view in the ACCOUNT_USAGE schema provides this data?
Medium17A data engineer needs to ensure that all queries against a table containing sensitive data are logged for compliance purposes. Which Snowflake feature should the engineer use to capture the query text and the user who executed it?
Easy18A company requires that data masking policies be applied automatically whenever a column is tagged with 'PII'. How can this be achieved?
Medium19A Snowflake account has a tag-based masking policy on column CUSTOMER.SSN. An analyst runs a query that applies the SYSTEM$GET_TAG function to that column. The analyst has been granted the APPLY MASKING POLICY privilege on the tag, but not the USAGE privilege on the tag. What does the analyst see for the SSN column value?
Medium20A financial services firm stores customer records in a table called TRANSACTIONS. The compliance team requires that a specific column, CREDIT_CARD_NUMBER, be transformed so that only the last four digits are visible to all users except members of the role PAYMENT_ADMIN. Additionally, the transformation must occur at query time without modifying the stored data. Which Snowflake feature should the data engineer use to meet this requirement?
Medium21A data engineer needs to ensure that only users with the role FINANCE_ANALYST can view the SALARY column in the EMPLOYEES table. All other users should see a masked value. Which Snowflake feature should the engineer use?
Easy22In Snowflake's object tagging hierarchy, if a tag is applied at the Schema level and a different value for the same tag is applied at the Table level, what is the resulting behavior for the Table?
Easy23A financial services company stores transaction records in a Snowflake table that includes a column named 'SSN'. The data engineering team has been asked to implement a governance control that automatically detects and tags any column containing Social Security Numbers across the entire account, without manually inspecting every table. Which Snowflake feature should the team use to achieve this requirement?
Medium24What is the primary function of a 'Tag' in Snowflake's governance framework?
Easy25Which of the following is true when considering the order of operations for policy application in Snowflake?
Medium26An organization wants to track PII data usage across the environment. Which Snowflake feature provides the most comprehensive audit trail of access to objects containing sensitive information?
Medium27A data engineer wants to share a subset of data with a third party while ensuring sensitive columns are masked. Which governance combination is best?
Hard28Which approach is most effective for managing governance policies across a large, multi-schema data warehouse environment?
Medium29Which TWO of the following are true regarding the use of Snowflake Data Classification?
Medium30What is the primary benefit of using Snowflake's Object Tagging for cost attribution?
Medium31An organization wants to track all data access in their Snowflake account for compliance. They need to know which columns were accessed by which queries, and they want to retain this information for at least one year. Which Snowflake feature should they use to meet this requirement?
Medium32A financial services firm must enforce a policy that only users with the role 'COMPLIANCE_OFFICER' can view rows where the 'ACCOUNT_STATUS' column equals 'DELINQUENT' in the 'LOANS' table. All other users should see only non-delinquent rows. Which Snowflake feature should the data engineer implement to meet this requirement?
Medium33A healthcare company implements a Row Access Policy (RAP) on a PATIENTS table to restrict doctor access to only their assigned patients. The RAP references a mapping table. What is the most critical performance consideration when designing this policy for a table with billions of rows?
Hard34A data steward at a financial services company needs to automatically detect and tag columns containing Social Security numbers across all schemas in the PROD database. The steward wants the tagging to be applied without manually inspecting each table and to leverage Snowflake's built-in classifiers. Which approach should the steward use?
Medium35A data engineer needs to ensure that PII data in the 'SALES' table is obscured for non-admin users while maintaining original data types for downstream analytical models. Which approach provides the most scalable governance?
Medium36A data engineer needs to identify all columns across a multi-database Snowflake account that have been assigned the 'PII_Type' tag to ensure compliance with a new privacy regulation. Which approach provides the most comprehensive and efficient result for this account-level audit?
Medium37Which object allows a data engineer to assign a security policy based on a user's geographical location attribute?
Medium38A data engineer needs to categorize columns across multiple databases with custom business tags such as COST_CENTER and DATA_OWNER, and then enforce that only users with the TAG_ADMIN role can modify those tags. Which Snowflake feature should the engineer use to meet this requirement?
Medium39A retail company has a Snowflake account with many databases and schemas. The data governance team needs to discover all columns that contain personal data such as names, email addresses, and phone numbers, and automatically assign a system tag so that a masking policy can be applied later. They want to minimize manual effort and ensure the classification is consistent. Which Snowflake feature should they use to achieve this?
Medium40A data engineer needs to ensure that a column containing credit card numbers is masked for all users except those with the PAYMENT_ADMIN role. The masking should be applied consistently across all tables that use a specific tag. Which Snowflake feature should the engineer use?
Easy41A data engineer is tasked with implementing a data governance strategy that includes classifying sensitive data and applying tags. The engineer plans to use Snowflake's Data Classification and tag-based masking. Which two statements are true regarding the interaction between Data Classification and tags? (Choose two.)
Hard42A data engineer is implementing row access policies to enforce data segregation for a multi-tenant application. The table ORDERS contains a column TENANT_ID. The engineer creates a row access policy that uses a mapping table TENANT_MAPPING to associate users with their allowed TENANT_ID values. After applying the policy, the engineer notices that queries against ORDERS are returning no rows for some users who should have access. The mapping table is correctly populated. What is the most likely cause of the issue?
HardOther domains
All DEA-C02 exam domains
Frequently asked questions
- What does the Data Governance domain cover on the DEA-C02 exam?
- Be able to query ACCESS_HISTORY to explain column lineage, attach tags for cost and classification, and combine masking with sharing. The critical skill is designing Row Access Policies whose mapping-table joins stay performant and deterministic while enforcing least-privilege access.
- How many questions are in this domain?
- This page lists all 42 Data Governance questions in the DEA-C02 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.