DEA-C02 Data Transformation Practice Question
To comply with privacy regulations, a data engineer must ensure that certain columns in a table are masked for unauthorized users during transformation. Which Snowflake feature provides a way to define re-usable masking logic that is automatically applied at query time?
⚠ Common exam trap
Candidates often confuse static table views or hardcoded column transformations with dynamic masking, missing that masking policies apply automatically based on user roles at query time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Data Masking Policies
Dynamic Data Masking is a security-focused transformation feature that allows engineers to protect sensitive data without changing the underlying stored values. By creating Masking Policies and applying them to columns, Snowflake ensures that the transformation (masking) happens dynamically based on the role and context of the user executing the query.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Row Access Policies
Why it's wrong here
Row Access Policies are used to filter which rows a user can see based on their role or other attributes (e.g., 'only see customers in your region'). While they are a security feature, they do not transform or mask individual column values; they determine the visibility of entire records in the result set.
- ✗
External Tables with encrypted files
Why it's wrong here
External tables allow Snowflake to query data stored in cloud storage without importing it. While the files themselves might be encrypted at rest, Snowflake must be able to decrypt them to process the data. This does not provide a mechanism for selective, role-based masking of specific columns within the SQL interface.
- ✓
Dynamic Data Masking Policies
Why this is correct
Dynamic Data Masking allows for the creation of policies that use SQL logic (like CASE statements) to determine how data should appear. When assigned to a column, the policy transforms the output for unauthorized roles (e.g., replacing a social security number with 'XXX-XX-XXXX') while keeping the raw data intact.
- ✗
Secure Views with hardcoded filters
Why it's wrong here
Secure views prevent users from seeing the underlying query logic and can include masking logic, but they are not as reusable or manageable as dedicated masking policies. Masking policies are attached directly to columns in the base table, ensuring that the protection applies regardless of which view or query accesses the data.
About these practice questions
This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.