Courseiva

CCNA Sf De Data Governance Questions

42 questions · Sf De Data Governance topic · All types, answers revealed

1
MCQhard

A data engineer is implementing a data classification process using Snowflake's Data Classification feature. The engineer wants to automatically classify columns containing sensitive data and then use the results to apply masking policies. After running the classification, the engineer notices that some columns that should be classified as 'EMAIL' are not being tagged. The engineer has verified that the data contains valid email addresses. What is the most likely reason for the missing classification?

A.The Data Classification feature requires that the column name contains the word 'EMAIL' to classify it as EMAIL.
B.The Data Classification feature only samples a subset of rows, and the sample did not include enough email addresses to meet the threshold.
C.The Data Classification feature cannot classify columns that contain NULL values.
D.The Data Classification feature is only available for columns in the PUBLIC schema.
AnswerB

Data Classification samples a limited number of rows to infer the semantic category. If the sample does not contain a sufficient number of email addresses (e.g., due to low frequency or sampling randomness), the column may not be classified as EMAIL. This is a common reason for missed classifications. The engineer can adjust the sampling or manually tag the column. This option correctly identifies the sampling limitation as the likely cause.

Why this answer

Data Classification uses sampling to analyze column data. If the sample does not contain a sufficient number of email addresses, the column may not be classified as EMAIL. This is a known limitation.

The other options are incorrect because classification does not depend on column names, can handle NULLs, and is not restricted to a specific schema.

Exam trap

The trap here is assuming that Data Classification scans all rows or relies on column names, when it actually samples data and uses pattern recognition.

2
MCQeasy

A data engineer needs to prevent any future column additions to a critical ORDERS table from containing unprotected PII. The goal is to automatically classify new columns and receive alerts when sensitive data is detected. Which Snowflake feature should be configured to achieve this?

A.Data Classification with automatic tagging and notifications
B.Object Tagging with manual tag assignment
C.Dynamic Data Masking policies on the table
D.Row Access Policies on the table
AnswerA

Data Classification scans tables and views to identify PII and other sensitive data. When enabled on a table, it automatically tags columns and can send notifications via email or integration when new sensitive columns are detected, ensuring ongoing protection.

Why this answer

Data Classification is designed to automatically scan and classify columns containing sensitive data, including PII. It can be configured to send notifications when new sensitive columns are detected, providing ongoing governance without manual effort. This directly addresses the need to protect future column additions.

Exam trap

The trap here is assuming that masking policies or tags alone provide automatic detection of new sensitive columns, when only Data Classification offers that capability.

3
MCQeasy

What is the primary purpose of a 'Secure View' in Snowflake from a governance perspective?

A.To increase the performance of complex joins.
B.To hide the underlying view definition and schema metadata.
C.To automatically mask PII in the output.
D.To allow users to modify the base tables.
AnswerB

Secure views provide a layer of obfuscation where the view definition and internal query structure are hidden from all users except those with specific ownership privileges. This prevents users from reverse-engineering the logic used to create the view, which is a key requirement for secure multi-tenant or external data sharing.

Why this answer

A Secure View is designed to prevent users from seeing the underlying logic or source data of the view, even if they have been granted select access. By hiding the view definition and internal metadata, organizations can expose specific data subsets to external partners or internal teams without risking the disclosure of proprietary business rules or underlying table structures that might contain sensitive information.

Exam trap

Candidates often think Secure Views improve query performance through caching, whereas their primary purpose is strictly security and obfuscating underlying view definitions.

4
Multi-Selectmedium

A data engineer is responsible for implementing data governance in Snowflake. The organization requires that all access to sensitive data be auditable and that data usage can be attributed to specific users and roles. Which two Snowflake features should the engineer use to meet these requirements? (Choose two.)

Select 2 answers
A.Query History in the ACCOUNT_USAGE schema to see all queries executed in the account.
B.Tag-based masking policies to enforce access controls based on tags.
C.Access History in the ACCOUNT_USAGE schema to track read and write access to columns.
D.Data Classification to automatically tag sensitive columns and track their usage.
E.Object Dependencies in the ACCOUNT_USAGE schema to map relationships between tables and views.
AnswersA, C

Query History captures all queries executed, including the user, role, and SQL text. It can be used to attribute data usage to specific users and roles. While it does not directly record column-level access, it provides a comprehensive audit trail of query activity. Combined with other features, it helps meet the requirement for auditable access.

Why this answer

Access History and Query History in the ACCOUNT_USAGE schema both provide detailed audit trails of data access. Access History records column-level read and write access, while Query History captures all queries with user and role information. Together, they enable comprehensive auditing and attribution of data usage to specific users and roles, meeting the governance requirements.

Exam trap

The trap here is assuming that data classification or masking policies provide auditing; they enforce controls but do not record access events.

5
MCQhard

Refer to the exhibit. A security administrator executes this query to audit access to a sensitive table. What specific information is captured in the 'base_objects_accessed' column regarding the data lineage of this query?

A.It lists only the immediate view name that the user referenced in their SELECT statement.
B.It displays the metadata of the warehouse used to execute the query for the table.
C.It identifies the specific columns and rows that were filtered out by the query optimizer.
D.It identifies the underlying tables that provided the data, even if the user queried a view.
AnswerD

The 'base_objects_accessed' column performs a recursive look-through of views to identify the original source tables. This ensures that even if sensitive data is hidden behind multiple layers of views, the security administrator can still track exactly which underlying physical tables were accessed by the user.

Why this answer

The ACCESS_HISTORY view is a powerful tool for tracking data movement and consumption. The 'base_objects_accessed' field specifically records the underlying source tables (the 'base' objects) that provided the data, even if the user queried a view or a series of nested views. This is vital for accurate compliance reporting and understanding the ultimate source of truth.

Exam trap

Candidates mistakenly believe 'base_objects_accessed' refers to the view itself, failing to realize it specifically tracks the underlying physical tables that actually contain the queried data.

6
MCQhard

A financial services firm stores account balances in a Snowflake table ACCOUNTS. A row access policy is defined so that analysts see only rows where REGION = CURRENT_REGION(). The firm also attaches a masking policy to the BALANCE column that returns NULL for users without the FINANCE role. An analyst with the ANALYST role queries SELECT REGION, BALANCE FROM ACCOUNTS. What will the analyst see?

A.An error is raised because a table cannot have both a row access policy and a masking policy attached.
B.Only rows matching the analyst's region, with BALANCE values returned as NULL because the analyst lacks the FINANCE role.
C.All rows in ACCOUNTS, but BALANCE values are NULL for every row.
D.Only rows matching the analyst's region, with actual BALANCE values visible because row access policies take precedence.
AnswerB

Row access policies and masking policies operate independently and both are enforced. The row access policy filters the result set to rows where REGION matches CURRENT_REGION(), while the masking policy on BALANCE transforms the value to NULL for roles outside FINANCE. The analyst therefore sees only their region's rows, and every BALANCE in those rows is NULL. This is the expected combined behavior when both policy types are attached.

Why this answer

Row access policies and masking policies are complementary and both are enforced at query time. The row access policy constrains which rows are visible based on the region predicate, while the masking policy rewrites the BALANCE value for roles not granted the FINANCE role. The analyst therefore sees a region-filtered result set in which BALANCE is NULL, demonstrating defense in depth.

Exam trap

The trap here is believing that one policy type overrides the other, when in fact row filtering and column masking are applied independently and combine in the result.

7
MCQeasy

An organization wants to classify their data to identify PII. Which feature should they use to automatically tag columns containing sensitive information?

A.Row Access Policies.
B.Data Classification.
C.Dynamic Data Masking.
D.Query Profile.
AnswerB

Snowflake Data Classification is designed to discover and classify sensitive data like PII. It utilizes built-in system tags to label columns, which can then be used to trigger automated security controls, ensuring that sensitive data is protected according to organizational compliance standards without requiring extensive manual effort.

Why this answer

Object Tagging is the primary governance feature for metadata management. When combined with Snowflake's Data Classification capability, it can automatically scan and suggest tags for columns based on their content, such as PII or financial data. This automation reduces manual labor and ensures that governance policies are consistently applied across large, complex schemas, which is fundamental to maintaining a high-quality data catalog.

Exam trap

Candidates often confuse 'Object Tagging' with 'Data Classification'. While related, tagging is the manual mechanism, whereas Classification is the automated service that scans and suggests those tags for PII.

8
MCQmedium

Which governance tool allows an administrator to audit who accessed a specific table and when?

A.QUERY_HISTORY.
B.ACCESS_HISTORY.
C.OBJECT_DEPENDENCIES.
D.The Security Dashboard.
AnswerB

ACCESS_HISTORY provides a detailed, audit-ready log of data access. It tracks which users accessed which tables, views, and columns. This is the standard tool for governance teams to verify compliance with data privacy regulations and ensure that only authorized roles are interacting with protected data assets.

Why this answer

The ACCESS_HISTORY view within the SNOWFLAKE.ACCOUNT_USAGE schema is the definitive source for auditing data access. It captures comprehensive details, including the query ID, the user, the objects queried, and the columns accessed. This level of granularity is essential for compliance reporting and security monitoring, enabling administrators to identify potential data breaches or unauthorized access patterns across the entire account.

Exam trap

Candidates often confuse ACCOUNT_USAGE views like ACCESS_HISTORY with INFORMATION_SCHEMA views, forgetting that ACCOUNT_USAGE has latency and records historical account-wide activity rather than current session metadata.

9
MCQmedium

A data engineer needs to audit all tag assignments across the account to ensure that no sensitive columns are missing required tags. Which Snowflake view should the engineer query to retrieve a list of all tags applied to columns, including the tag name, value, and the object it is applied to?

A.SNOWFLAKE.ACCOUNT_USAGE.TAGS
B.SNOWFLAKE.ACCOUNT_USAGE.TAG_REFERENCES
C.SNOWFLAKE.ACCOUNT_USAGE.POLICY_REFERENCES
D.SNOWFLAKE.ACCOUNT_USAGE.COLUMNS
AnswerB

TAG_REFERENCES is the account usage view that lists all tag references, including the tag name, tag value, and the object (such as a column) to which the tag is applied. It is the correct source for auditing tag assignments across the account.

Why this answer

To audit tag assignments, the TAG_REFERENCES view is the correct choice. It provides a comprehensive list of all tag references, including the tag name, value, and the object (e.g., column) it is applied to. The TAGS view only provides tag metadata, while COLUMNS and POLICY_REFERENCES do not include tag assignments.

Exam trap

The trap here is confusing the TAGS view, which lists tag definitions, with TAG_REFERENCES, which lists where tags are applied.

10
Multi-Selectmedium

A data engineer is setting up Snowflake Data Classification on a table containing customer feedback. The engineer wants to ensure that the classification process identifies columns with potentially sensitive information and tags them appropriately. Which two actions are required to enable Data Classification on the table? (Choose two.)

Select 2 answers
A.Grant the role used for classification the USAGE privilege on the database and schema containing the table.
B.Enable the ACCOUNTADMIN role to run the classification process.
C.Set the CLASSIFICATION_PROFILE parameter on the table to enable automatic classification.
D.Grant the role used for classification the SELECT privilege on the table to be classified.
E.Create a custom classifier that defines the patterns for sensitive data before running classification.
AnswersA, D

To run Data Classification, the role must have USAGE privileges on the database and schema, as well as SELECT on the table. Without USAGE, the role cannot access the objects to perform the classification. This privilege is a prerequisite and is typically granted to the role that will execute the classification process. Therefore, this action is required.

Why this answer

To perform Data Classification, the role must have USAGE on the database and schema, and SELECT on the table. These privileges allow the classification process to access and sample the data. Custom classifiers and specific roles like ACCOUNTADMIN are not required.

Thus, the two correct actions are granting USAGE and SELECT.

Exam trap

The trap here is assuming that ACCOUNTADMIN is required or that a custom classifier must be created, when basic privileges are sufficient.

11
MCQmedium

A Snowflake data engineer has been tasked with implementing dynamic data masking on a CUSTOMERS table so that the SSN column is fully redacted for all users except those with the role PII_ADMIN. The engineer wants the masking to apply automatically whenever the column is queried, without changing any application SQL. Which Snowflake object should the engineer create and attach to the SSN column?

A.A masking policy created with CREATE MASKING POLICY and applied to the SSN column using ALTER TABLE ... MODIFY COLUMN ... SET MASKING POLICY.
B.A row access policy created with CREATE ROW ACCESS POLICY and attached to the CUSTOMERS table.
C.A secure view that selects all columns from CUSTOMERS but replaces SSN with a constant for non-admins.
D.A tag-based classification using ALTER TABLE ... SET TAG on the SSN column.
AnswerA

A masking policy is the native Snowflake column-level security object designed for this exact scenario. Creating it with CREATE MASKING POLICY and attaching it via ALTER TABLE ... MODIFY COLUMN ... SET MASKING POLICY makes the policy evaluate on every query of the SSN column, returning the raw value only to roles listed in the policy body (such as PII_ADMIN) and a redacted value to everyone else. No application SQL changes are needed.

Why this answer

Dynamic column redaction in Snowflake is implemented with masking policies, which are schema-level objects attached directly to a column. Once attached, the policy expression evaluates on every query, returning the original value to authorized roles and a masked value to others, with no application changes required. This satisfies both the automatic enforcement requirement and the role-based exception for PII_ADMIN.

Exam trap

The trap here is assuming that tagging a sensitive column or building a secure view is equivalent to enforcing dynamic masking, when only an attached masking policy actually rewrites the value at query time.

12
MCQeasy

What is the primary purpose of the 'SNOWFLAKE.ACCOUNT_USAGE' schema in a governance context?

A.To store backup copies of sensitive data.
B.To provide audit-ready metadata on system and user activity.
C.To manage the deployment of data masking policies.
D.To increase the performance of analytical queries.
AnswerB

ACCOUNT_USAGE contains views that track every query, access event, and configuration change. This data is essential for governance audits, as it provides a transparent and immutable history of what happened in the account, allowing for detailed investigation and reporting required by modern data compliance standards.

Why this answer

The ACCOUNT_USAGE schema provides historical metadata about account activity, which is the backbone of governance and auditing. It allows organizations to query past actions to ensure compliance with internal security policies, track data usage, and identify potential risks. Without these views, administrators would lack the necessary visibility to satisfy external regulatory requirements like SOC2 or GDPR, which demand detailed accountability for data access.

Exam trap

Test-takers often confuse ACCOUNT_USAGE with INFORMATION_SCHEMA, incorrectly believing ACCOUNT_USAGE provides real-time, instantaneous metadata without any data latency.

13
MCQmedium

A data engineer is implementing a data governance strategy and needs to ensure that all tables containing sensitive data are automatically identified and tagged. The engineer wants to use Snowflake's native classification capabilities and then apply masking policies based on those tags. Which sequence of steps should the engineer follow?

A.Manually apply tags, then create masking policies that reference those tags.
B.Create masking policies first, then run Data Classification to tag columns.
C.Use Access History to identify sensitive columns, then manually tag them.
D.Run Data Classification, review results, then create and attach masking policies to tagged columns.
AnswerD

Data Classification automatically scans tables and identifies sensitive columns, applying system tags. After reviewing the results, the engineer can create masking policies and attach them to the tagged columns. This sequence leverages automation and ensures policies are applied where needed.

Why this answer

Data Classification is the native feature that automatically scans and tags sensitive columns. Once tagged, the engineer can review the tags and then create masking policies attached to those columns. This ensures that policies are applied to the correct columns without manual discovery.

Exam trap

The trap here is assuming that masking policies can be applied based on tags automatically, or that tags themselves enforce masking, when in fact policies must be manually attached to columns after classification.

14
MCQhard

A financial institution uses Snowflake to store customer transactions. A data engineer needs to implement a policy that restricts access to rows in the TRANSACTIONS table based on the department of the user. The department information is stored in a lookup table named USER_DEPARTMENT. The policy must be applied dynamically without modifying the TRANSACTIONS table. Which Snowflake feature should the engineer use?

A.Implement a Row Access Policy that uses a mapping table to determine the user's department and filters rows accordingly.
B.Create a secure view that joins TRANSACTIONS with USER_DEPARTMENT and filters rows based on the current user's department.
C.Use a Column-level Security policy with a masking policy that returns NULL for rows not belonging to the user's department.
D.Create a dynamic data masking policy that checks the user's department and masks the entire row if the department does not match.
AnswerA

A Row Access Policy is a schema-level object that can be added to a table to filter rows based on conditions evaluated at query time. It can reference a mapping table like USER_DEPARTMENT to dynamically determine the user's department and restrict rows. This meets the requirement of dynamic filtering without altering the table structure. It is the correct feature for row-level security in Snowflake.

Why this answer

Row Access Policies are designed to filter rows based on user attributes or mapping tables. They attach to tables and enforce filtering at query time, making them ideal for dynamic row-level security. Secure views can be bypassed if base table access is granted, and masking policies only affect column values, not row visibility.

Thus, a Row Access Policy is the correct solution.

Exam trap

The trap here is assuming that masking policies can filter rows, when they only mask column values, or that secure views are sufficient without revoking base table access.

15
MCQhard

A data engineer needs to audit all grants of the 'SYSADMIN' role to users across the Snowflake account. The engineer has access to the ACCOUNTADMIN role and wants to retrieve this information efficiently. Which Snowflake view should be queried?

A.SNOWFLAKE.ACCOUNT_USAGE.GRANTS_TO_USERS
B.SNOWFLAKE.ACCOUNT_USAGE.USERS
C.SNOWFLAKE.ACCOUNT_USAGE.ROLES
D.SNOWFLAKE.ACCOUNT_USAGE.GRANTS_TO_ROLES
AnswerA

The GRANTS_TO_USERS view in the ACCOUNT_USAGE schema contains a record of all role grants to users, including the role name, grantee name, and grant date. Querying this view with a filter on the ROLE column for 'SYSADMIN' will return the required audit information. It is the correct and efficient source for this data.

Why this answer

To audit which users have been granted the SYSADMIN role, the GRANTS_TO_USERS view in the ACCOUNT_USAGE schema is the correct source. It records all role-to-user grants, including the role name and grantee. Filtering on the ROLE column for 'SYSADMIN' yields the required list.

Other views either lack grant information or focus on different objects.

Exam trap

The trap here is confusing grants to users with grants to roles, which track different relationships and are stored in separate views.

16
MCQmedium

An auditor requests proof of who has accessed a specific table containing sensitive data. Which Snowflake view in the ACCOUNT_USAGE schema provides this data?

A.QUERY_HISTORY.
B.ACCESS_HISTORY.
C.TABLE_STORAGE_METRICS.
D.OBJECT_PRIVILEGES.
AnswerB

ACCESS_HISTORY is specifically designed for auditing data access at the column level. It records the relationships between users, the queries they run, and the tables or columns those queries accessed. This is the primary tool for governance teams to generate compliance reports and prove data security.

Why this answer

The ACCESS_HISTORY view in the ACCOUNT_USAGE schema is the definitive source for auditing data access. It logs every query that touches a column in a table, providing a comprehensive trail that is crucial for regulatory compliance. Understanding how to query the ACCOUNT_USAGE schema is a core skill for data engineers responsible for maintaining an audit-ready environment and documenting data lineage for sensitive assets.

Exam trap

Test-takers frequently select METERING_HISTORY or QUERY_HISTORY, confusing warehouse cost tracking and general query logs with granular data access auditing.

17
MCQeasy

A data engineer needs to ensure that all queries against a table containing sensitive data are logged for compliance purposes. Which Snowflake feature should the engineer use to capture the query text and the user who executed it?

A.Login History in the ACCOUNT_USAGE schema.
B.Access History in the ACCOUNT_USAGE schema.
C.Query History in the ACCOUNT_USAGE schema.
D.Warehouse Metering History in the ACCOUNT_USAGE schema.
AnswerC

Query History in the ACCOUNT_USAGE schema captures detailed information about every query executed, including the query text, the user who ran it, and the execution time. This is the standard Snowflake feature for auditing query activity and meets the requirement to log queries against the sensitive table.

Why this answer

Query History in ACCOUNT_USAGE is the correct feature to log query text and user information for compliance. It provides a complete record of all queries executed in the account. Access History is for column-level access, Login History is for authentication events, and Warehouse Metering History is for cost tracking.

Only Query History captures the necessary details.

Exam trap

The trap here is confusing Access History with Query History, assuming that Access History logs full query text when it only tracks column-level access.

18
MCQmedium

A company requires that data masking policies be applied automatically whenever a column is tagged with 'PII'. How can this be achieved?

A.Write a stored procedure to trigger on every DDL statement.
B.Use tag-based masking policies.
C.Use a Row Access Policy with a conditional tag check.
D.Manually apply the masking policy every time a table is created.
AnswerB

Tag-based masking policies allow you to define a masking policy and associate it with a specific tag. When the tag is applied to a column, the masking policy is automatically applied. This streamlines governance, reduces maintenance, and ensures consistency across large, evolving datasets in the enterprise.

Why this answer

Tag-based masking policies provide a direct link between metadata tagging and security enforcement. By associating a masking policy with a specific tag, any column assigned that tag automatically inherits the associated masking behavior. This automation is crucial for governance, as it prevents manual errors and ensures that sensitive data is never exposed simply because someone forgot to manually attach a policy to a new column.

Exam trap

Candidates often assume they need to write complex stored procedures or triggers to apply masking. They overlook the native, declarative 'tag-based' feature designed to automate this exact process.

19
MCQmedium

A Snowflake account has a tag-based masking policy on column CUSTOMER.SSN. An analyst runs a query that applies the SYSTEM$GET_TAG function to that column. The analyst has been granted the APPLY MASKING POLICY privilege on the tag, but not the USAGE privilege on the tag. What does the analyst see for the SSN column value?

A.NULL, because the masking policy cannot be resolved without tag access.
B.An error, because the analyst lacks USAGE on the tag required to evaluate the masking policy.
C.The unmasked SSN value, because APPLY MASKING POLICY overrides tag visibility.
D.The masked SSN value, because the masking policy is enforced regardless of tag privileges.
AnswerD

Tag-based masking policies are enforced based on the tag assignment and the masking policy's conditions, independent of the user's privileges on the tag itself. The analyst lacks USAGE on the tag, so they cannot see the tag metadata, but the masking policy still applies to the column when queried. Thus the SSN appears masked.

Why this answer

Masking policies attached to tags are enforced regardless of whether the querying user can read the tag. A user without USAGE on the tag cannot see tag metadata but still receives masked data because the policy is evaluated at query time against the column. APPLY MASKING POLICY is an administrative privilege for managing tag-policy associations, not for bypassing enforcement.

Exam trap

The trap here is assuming that lacking USAGE on a tag disables its masking policy or causes an error, when in fact the policy remains enforced.

20
MCQmedium

A financial services firm stores customer records in a table called TRANSACTIONS. The compliance team requires that a specific column, CREDIT_CARD_NUMBER, be transformed so that only the last four digits are visible to all users except members of the role PAYMENT_ADMIN. Additionally, the transformation must occur at query time without modifying the stored data. Which Snowflake feature should the data engineer use to meet this requirement?

A.A tag-based masking policy using the TAG_STRING system function.
B.A row access policy applied to the TRANSACTIONS table.
C.A masking policy applied to the CREDIT_CARD_NUMBER column.
D.A secure view that selects only the last four digits of the column.
AnswerC

A masking policy is a schema-level object that can be attached to a column and evaluates at query time. It can inspect the user's role and conditionally return a masked value, such as showing only the last four digits, while storing the original data unchanged. This directly satisfies the requirement for dynamic, role-based transformation without altering the underlying table data.

Why this answer

The requirement is to dynamically mask a column based on the user's role while preserving the original data. A masking policy attached to the column evaluates at query time and can return different values depending on the role. It does not alter stored data, and it can show only the last four digits for non-privileged roles while revealing the full value for PAYMENT_ADMIN.

This is the standard Snowflake method for column-level dynamic data masking.

Exam trap

The trap here is confusing row-level filtering with column-level masking, or assuming that a secure view alone can provide role-based conditional masking without a masking policy.

21
MCQeasy

A data engineer needs to ensure that only users with the role FINANCE_ANALYST can view the SALARY column in the EMPLOYEES table. All other users should see a masked value. Which Snowflake feature should the engineer use?

A.Row Access Policy
B.Object Tag
C.Masking Policy
D.Secure View
AnswerC

A masking policy is applied to a column and can conditionally mask its values based on the user's role. By creating a masking policy that returns the actual salary for FINANCE_ANALYST and a masked value for others, the engineer can meet the requirement. This is the standard Snowflake feature for column-level security and dynamic data masking.

Why this answer

A masking policy is the correct feature for column-level security. It allows conditional masking based on the user's role, ensuring that only FINANCE_ANALYST sees the actual salary. Row access policies filter rows, secure views can be bypassed, and tags are for metadata.

Thus, a masking policy is the right choice.

Exam trap

The trap here is confusing row-level security with column-level security, or assuming that tags enforce access control.

22
MCQeasy

In Snowflake's object tagging hierarchy, if a tag is applied at the Schema level and a different value for the same tag is applied at the Table level, what is the resulting behavior for the Table?

A.The Table-level tag value overrides the Schema-level tag value.
B.The Schema-level tag value overrides the Table-level tag value.
C.Snowflake returns an error due to a conflict in the tag lineage.
D.Both tag values are combined into a comma-separated string for the Table.
AnswerA

Snowflake follows a 'bottom-up' precedence rule for object tagging. A tag explicitly applied to a lower-level object, such as a table, will always take precedence over the same tag inherited from a higher-level container like a schema or database, allowing for specific overrides of general governance policies.

Why this answer

Snowflake utilizes a hierarchy for tag inheritance where the most specific assignment takes precedence. This allows organizations to set broad defaults at the database or schema level while still permitting exceptions at the table or column level. Understanding this precedence is essential for troubleshooting why certain objects may or may not appear in audit reports.

Exam trap

Candidates often guess that the higher-level (Schema) tag takes precedence, failing to recognize that Snowflake's object tagging follows a 'most specific wins' hierarchy for inheritance.

23
MCQmedium

A financial services company stores transaction records in a Snowflake table that includes a column named 'SSN'. The data engineering team has been asked to implement a governance control that automatically detects and tags any column containing Social Security Numbers across the entire account, without manually inspecting every table. Which Snowflake feature should the team use to achieve this requirement?

A.Object tagging with manual tag assignments
B.Access History view in ACCOUNT_USAGE
C.Data Classification with a custom classification profile
D.Dynamic Data Masking with a masking policy
AnswerC

Data Classification scans table columns and applies system tags like SNOWFLAKE.CORE.SSN based on semantic and pattern matching. By creating a custom classification profile that includes SSN detection, the team can automatically tag all relevant columns account-wide. This satisfies the requirement for automatic detection and tagging without manual intervention.

Why this answer

Data Classification is designed to automatically scan and classify columns based on sensitive data patterns. By using a custom classification profile, the team can ensure SSNs are detected and tagged with system tags across the account, meeting the governance requirement without manual effort.

Exam trap

The trap here is confusing Data Classification with Dynamic Data Masking, which protects data but does not automatically detect or tag columns.

24
MCQeasy

What is the primary function of a 'Tag' in Snowflake's governance framework?

A.To hide data from unauthorized users.
B.To classify data and facilitate governance policy application.
C.To store physical data for backup purposes.
D.To increase the performance of queries.
AnswerB

Tags allow for the classification of data assets, enabling administrators to identify sensitive information and apply policies programmatically. This is a fundamental component of data governance, as it provides a structured way to manage and protect data across large, complex schemas without requiring manual column-level configuration.

Why this answer

Tags are metadata objects that allow you to label other objects, such as tables or columns, to facilitate discovery, cost tracking, and governance policy application. By tagging sensitive data, organizations can automate the application of masking or row access policies, ensuring that security controls scale alongside the data volume and reducing the burden of manual oversight for data engineers.

Exam trap

Candidates often assume tags directly enforce security, failing to realize that tags are merely metadata labels that require a separate policy (like masking) to actually perform the enforcement.

25
MCQmedium

Which of the following is true when considering the order of operations for policy application in Snowflake?

A.Masking policies are applied before Row Access Policies.
B.Row Access Policies are evaluated before Masking policies.
C.Policies are applied in a random order.
D.The evaluation order is defined by the table owner.
AnswerB

Snowflake evaluates Row Access Policies first to determine which rows a user can access, then applies Masking policies to the columns within those allowed rows. This sequential order is essential for maintaining strict security boundaries, as it prevents users from performing operations on rows they are not authorized to see.

Why this answer

Row Access Policies are evaluated before Dynamic Data Masking policies. This ensures that the rows themselves are filtered based on the user's access rights before any masking occurs. This order is critical for security; if masking were applied first, it might leak information about the rows that should have been filtered out, violating the principle of least privilege and strict data boundary enforcement.

Exam trap

Candidates often guess that masking policies apply first, confusing the sequence and overlooking how premature masking could leak row existence information.

26
MCQmedium

An organization wants to track PII data usage across the environment. Which Snowflake feature provides the most comprehensive audit trail of access to objects containing sensitive information?

A.Query History.
B.Access History.
C.Data Sharing history.
D.Login History.
AnswerB

Access History provides a detailed audit of which columns and tables were accessed by a query. This is essential for governance, as it allows administrators to identify if unauthorized roles are attempting to access sensitive data, providing the foundation for automated security alerting and compliance reporting.

Why this answer

Access History is a native Snowflake feature that records granular information about which users accessed which columns in which tables. This is vital for compliance audits and data governance, as it provides a verifiable record of data consumption. By combining Access History with Object Tagging, organizations can effectively monitor sensitive data flows and ensure compliance with regulatory standards like GDPR or CCPA.

Exam trap

Test-takers often confuse Object Tagging with Access History, assuming tags alone automatically log who queried sensitive data.

27
MCQhard

A data engineer wants to share a subset of data with a third party while ensuring sensitive columns are masked. Which governance combination is best?

A.Create a secure view and apply masking policies to the base table columns.
B.Create a standard view with CASE statements for masking.
C.Grant direct access to the base table.
D.Physically clone the table and remove sensitive rows.
AnswerA

Applying masking policies to the base table ensures that even if the underlying data is accessed via a view, the masking rules are still enforced. Using a secure view provides the added benefit of hiding the underlying schema metadata, making this the most secure approach for external data sharing.

Why this answer

The best practice is to combine a Secure View with a Dynamic Data Masking policy. The Secure View provides a clean abstraction layer, while the Masking Policy ensures that the data itself remains protected regardless of how the view is queried. This combination allows for precise data sharing while adhering to strict compliance standards, protecting the organization from data leaks during the sharing process.

Exam trap

Candidates often assume that applying a masking policy to a view is sufficient, forgetting that the policy must be applied to the underlying base table columns to ensure universal data protection.

28
MCQmedium

Which approach is most effective for managing governance policies across a large, multi-schema data warehouse environment?

A.Create policies within each individual schema.
B.Deploy policies to a centralized database and schema.
C.Use a single shared role for all policy management.
D.Manually recreate all policies in every environment.
AnswerB

Centralizing governance objects enables a single source of truth for security policies. This simplifies the management of privileges and makes auditing significantly easier, as all policies are located in one place. It also allows for clear separation of duties between the security team and the data engineering team.

Why this answer

Centralizing governance objects in a dedicated 'GOVERNANCE' database is the best practice. By keeping policies, tags, and data classification results in a single, well-controlled schema, organizations ensure consistency and ease of maintenance. This centralized approach simplifies access control for the security team and allows for easier auditing of policy changes compared to scattering governance artifacts across disparate, business-specific databases or schemas.

Exam trap

Candidates often suggest creating policies in every schema to keep them 'local'. This creates a management nightmare, making it impossible to audit or update governance policies consistently across the environment.

29
Multi-Selectmedium

Which TWO of the following are true regarding the use of Snowflake Data Classification?

Select 2 answers
A.Data classification can only be applied to existing tables.
B.The process uses system-defined tags to label sensitive data.
C.Classification results are stored in the user's local file system.
D.Classification requires the data to be in a flat file format.
E.Users can review and modify the tags suggested by the classification process.
AnswersB, E

Snowflake's data classification service uses a set of predefined system tags, such as 'SNOWFLAKE.CORE.EMAIL' or 'SNOWFLAKE.CORE.PHONE', to identify and label columns. These tags help categorize data automatically, allowing administrators to apply governance policies based on these labels rather than manually tagging every column in the database.

Why this answer

Snowflake Data Classification automatically identifies PII and sensitive data within tables, assigning system tags to columns. This process significantly reduces the manual effort required for governance. It works by scanning sample data and applying semantic labels, which can then be used to trigger automated protection measures like masking policies.

Understanding how this automates compliance is essential for any modern data engineer managing large, dynamic datasets.

Exam trap

Candidates often assume data classification automatically enforces security policies, forgetting that classification only suggests tags and requires manual or automated policy association.

30
MCQmedium

What is the primary benefit of using Snowflake's Object Tagging for cost attribution?

A.It automatically reduces the storage costs by compressing data.
B.It allows costs to be associated with specific business projects.
C.It enables query results to be cached more efficiently.
D.It replaces the need for Resource Monitors.
AnswerB

By applying tags to databases or schemas, organizations can monitor usage and associate costs with specific projects or departments. This visibility is essential for cost management, as it allows leadership to identify high-cost areas and optimize resource consumption based on actual business value and departmental activity.

Why this answer

Object Tagging allows organizations to assign costs to specific business units, projects, or applications by labeling the tables and schemas they use. This is critical for internal showback/chargeback models. By tracking resource usage at the tagged object level, finance teams can accurately map Snowflake costs to specific departments, encouraging better resource management and accountability across the organization's data footprint.

Exam trap

Candidates often assume object tags directly compute warehouse compute costs, missing that tags only label objects for cost attribution while actual warehouse costs are tracked via WAREHOUSE_METERING_HISTORY.

31
MCQmedium

An organization wants to track all data access in their Snowflake account for compliance. They need to know which columns were accessed by which queries, and they want to retain this information for at least one year. Which Snowflake feature should they use to meet this requirement?

A.Login History
B.Object Dependencies
C.Access History
D.Query History
AnswerC

Access History captures column-level access information for queries, including which columns were read and written. It is designed for auditing and compliance, and the data is retained for 365 days. This meets the requirement of tracking column access and retaining for one year. Therefore, Access History is the correct feature.

Why this answer

Access History is specifically designed to provide column-level access auditing, capturing which columns were read or written by queries. It retains data for 365 days, satisfying the one-year retention requirement. Query History lacks column-level detail and has a shorter retention.

Login History and Object Dependencies do not track data access. Thus, Access History is the correct feature.

Exam trap

The trap here is assuming that Query History includes column-level access details, when it only records query metadata.

32
MCQmedium

A financial services firm must enforce a policy that only users with the role 'COMPLIANCE_OFFICER' can view rows where the 'ACCOUNT_STATUS' column equals 'DELINQUENT' in the 'LOANS' table. All other users should see only non-delinquent rows. Which Snowflake feature should the data engineer implement to meet this requirement?

A.A network policy that restricts access to the LOANS table based on IP address.
B.A secure view that joins the LOANS table with a role-mapping table and filters rows.
C.A row access policy on the LOANS table that checks the current role and filters rows accordingly.
D.A masking policy on the ACCOUNT_STATUS column that returns NULL for non-compliance roles.
AnswerC

Row access policies are designed to filter rows based on conditions such as the current role. By defining a policy that returns TRUE only when the role is COMPLIANCE_OFFICER or when ACCOUNT_STATUS is not 'DELINQUENT', the engineer enforces exactly the required row-level security. This is the standard Snowflake mechanism for row-level filtering.

Why this answer

Row access policies are the correct Snowflake feature for row-level security. They evaluate conditions such as CURRENT_ROLE() and filter rows accordingly. Masking policies only obfuscate column values, secure views can be bypassed if base table access exists, and network policies operate at the network layer.

Only a row access policy attached to the table enforces the required filtering for all queries.

Exam trap

The trap here is confusing column-level masking with row-level filtering, assuming that masking a column can hide entire rows.

33
MCQhard

A healthcare company implements a Row Access Policy (RAP) on a PATIENTS table to restrict doctor access to only their assigned patients. The RAP references a mapping table. What is the most critical performance consideration when designing this policy for a table with billions of rows?

A.Applying the policy to the mapping table itself to prevent circular references.
B.Ensuring the mapping table is small and uses columns that allow for effective pruning.
C.Using a CASE statement instead of a WHERE clause within the policy definition.
D.Granting the OWNERSHIP privilege of the mapping table to the PUBLIC role.
AnswerB

The performance of a Row Access Policy depends heavily on how well Snowflake can prune data. If the mapping table is large or poorly structured, the policy evaluation can become a bottleneck. Keeping mapping tables lean and indexed via clustering ensures that the join logic does not force unnecessary data scanning.

Why this answer

When Row Access Policies involve joins to mapping tables, Snowflake's optimizer must execute these checks efficiently to avoid full table scans. Using a memoizable function or ensuring the mapping table is small and clustered correctly helps the pruning process. Governance at scale requires balancing strict security logic with the underlying query performance to ensure user experience is maintained.

Exam trap

Candidates often focus on the complexity of the policy logic, ignoring that the join with a large mapping table is the primary bottleneck for performance on massive datasets.

34
MCQmedium

A data steward at a financial services company needs to automatically detect and tag columns containing Social Security numbers across all schemas in the PROD database. The steward wants the tagging to be applied without manually inspecting each table and to leverage Snowflake's built-in classifiers. Which approach should the steward use?

A.Enable Snowflake Access History and use it to identify columns that have been queried with SSN patterns.
B.Use Snowflake Data Classification with a system-defined SSN semantic category and apply it to the PROD database.
C.Write a stored procedure that queries INFORMATION_SCHEMA.COLUMNS for column names containing 'SSN' and applies a tag.
D.Create a custom tag called SSN_TAG and manually apply it to every column that appears to contain SSN data.
AnswerB

Snowflake Data Classification includes built-in semantic categories such as SSN that automatically identify and tag columns containing Social Security numbers. By applying classification to the entire PROD database, the steward can scan all schemas and tables without manual effort. The system assigns tags like SNOWFLAKE.CORE.SSN to matching columns, enabling automated governance.

Why this answer

Snowflake Data Classification automatically scans tables and views to identify sensitive data using system-defined semantic categories, including SSN. Applying it to a database scans all contained schemas and tables, tagging columns that match the SSN pattern. This meets the requirement for automatic detection and tagging without manual intervention, leveraging native governance features.

Exam trap

The trap here is assuming that column name pattern matching or manual tagging is sufficient for sensitive data detection, when only Data Classification analyzes actual data values and applies system-defined tags.

35
MCQmedium

A data engineer needs to ensure that PII data in the 'SALES' table is obscured for non-admin users while maintaining original data types for downstream analytical models. Which approach provides the most scalable governance?

A.Create separate secure views for every user role requiring masked access.
B.Apply a masking policy to the columns and grant the APPLY MASKING POLICY privilege.
C.Use row-level security to filter rows containing PII data for authorized users.
D.Physically transform the data during the ETL process and store it in a new table.
AnswerB

Applying a masking policy directly to columns provides a centralized way to enforce data governance. By granting the APPLY MASKING POLICY privilege to a governance role, you ensure that security policies are managed by the data security team rather than the database owners, following the principle of least privilege.

Why this answer

Dynamic Data Masking allows policies to be applied to columns based on the user's role without duplicating data. By leveraging masking policies, you maintain a single source of truth while ensuring sensitive information is protected at query runtime. This method is highly scalable as a single policy can be assigned to multiple columns across different tables, simplifying maintenance and ensuring consistent security posture across the enterprise.

Exam trap

Candidates often suggest creating separate views or physical copies of tables, which is inefficient and violates the principle of a single source of truth for governance.

36
MCQmedium

A data engineer needs to identify all columns across a multi-database Snowflake account that have been assigned the 'PII_Type' tag to ensure compliance with a new privacy regulation. Which approach provides the most comprehensive and efficient result for this account-level audit?

A.Query the INFORMATION_SCHEMA.TAG_REFERENCES table function in every database.
B.Use the SYSTEM$GET_TAG function on every table in the account sequentially.
C.Query the TAG_REFERENCES view within the SNOWFLAKE.ACCOUNT_USAGE schema.
D.Execute a SHOW TAGS command and filter for the 'PII_Type' string in the output.
AnswerC

The ACCOUNT_USAGE.TAG_REFERENCES view contains a comprehensive record of all tag associations across the entire Snowflake account, including those in different databases. This view is the standard for account-wide governance and auditing, allowing for a single query to return all objects tagged with specific compliance-related labels.

Why this answer

Snowflake object tagging allows for fine-grained metadata management across the account. Using the ACCOUNT_USAGE.TAG_REFERENCES view is the most efficient way to track PII tags globally, as it aggregates data from all databases. This centralized approach ensures that data engineers can maintain compliance and auditability without needing to query individual database schemas, which is crucial for scalable governance strategies.

Exam trap

Candidates frequently select the Information Schema instead of Account Usage, forgetting that Information Schema only contains data for the current database, not the entire account.

37
MCQmedium

Which object allows a data engineer to assign a security policy based on a user's geographical location attribute?

A.Masking Policy.
B.Row Access Policy.
C.Secure View.
D.Tag-based masking.
AnswerB

Row Access Policies allow for conditional logic that incorporates context functions like CURRENT_USER or session attributes. This enables the implementation of fine-grained access control where rows are only visible if the user's location satisfies specific regulatory requirements or internal business rules defined within the policy's SQL expression.

Why this answer

Row Access Policies are the correct mechanism here. By using a policy that evaluates the current user's session context—specifically looking at attributes like their IP address or a custom 'location' attribute—the policy can filter out rows that the user is not authorized to see based on residency or regional compliance regulations like GDPR, ensuring data sovereignty is upheld throughout the organization.

Exam trap

Candidates often suggest 'Masking Policies' for location-based filtering. Masking hides data content but does not filter out entire rows, which is the specific requirement for location-based access control.

38
MCQmedium

A data engineer needs to categorize columns across multiple databases with custom business tags such as COST_CENTER and DATA_OWNER, and then enforce that only users with the TAG_ADMIN role can modify those tags. Which Snowflake feature should the engineer use to meet this requirement?

A.A masking policy that returns the tag value for authorized roles and NULL for others.
B.Object tagging with a tag created via CREATE TAG, assigning tags to columns with ALTER TABLE ... SET TAG, and granting the APPLY TAG privilege only to TAG_ADMIN.
C.Snowflake Data Classification, which automatically detects and tags columns with system tags.
D.Access control policies created with CREATE ACCESS POLICY and bound to the target columns.
AnswerB

Snowflake's native object tagging allows custom tags to be created with CREATE TAG, applied to columns, tables, and other objects, and governed through the APPLY TAG privilege on the tag. By granting APPLY TAG only to TAG_ADMIN, the engineer ensures only that role can assign or change the tag on objects. This directly satisfies both the categorization and the access-control requirements using a single governance feature.

Why this answer

Object tagging is Snowflake's mechanism for attaching custom metadata labels to columns and other objects. Tags are created with CREATE TAG, applied with ALTER TABLE ... SET TAG, and their modification is governed by the APPLY TAG privilege on the tag itself.

Granting APPLY TAG only to TAG_ADMIN restricts who can change the tags, satisfying both categorization and access-control needs.

Exam trap

The trap here is conflating Data Classification's system tags with custom business tags, when only object tagging supports user-defined tags and the APPLY TAG privilege model.

39
MCQmedium

A retail company has a Snowflake account with many databases and schemas. The data governance team needs to discover all columns that contain personal data such as names, email addresses, and phone numbers, and automatically assign a system tag so that a masking policy can be applied later. They want to minimize manual effort and ensure the classification is consistent. Which Snowflake feature should they use to achieve this?

A.Manually run SHOW COLUMNS in each database and schema, then apply tags using ALTER TABLE ... SET TAG.
B.Use Snowflake Data Classification to automatically scan and tag columns with system tags like SNOWFLAKE.CORE.PRIVACY_CATEGORY.
C.Enable Access History and then use the ACCESS_HISTORY view to identify columns containing personal data.
D.Create a stored procedure that queries INFORMATION_SCHEMA.COLUMNS and uses pattern matching to assign tags.
AnswerB

Snowflake Data Classification automatically scans tables and views, identifies sensitive data using native and custom classifiers, and assigns system tags such as SNOWFLAKE.CORE.PRIVACY_CATEGORY. This directly addresses the need to discover and tag personal data across many databases with minimal manual effort. The system tags can then be used to drive masking policies, making this the correct approach.

Why this answer

Snowflake Data Classification is designed to automatically scan and classify data, applying system tags that indicate privacy categories. This reduces manual effort and ensures consistent tagging across the account. The other options either require manual work, rely on incomplete methods, or use auditing features that do not detect sensitive data content.

Thus, Data Classification is the correct choice.

Exam trap

The trap here is confusing auditing views like ACCESS_HISTORY with data classification capabilities, assuming that access patterns reveal sensitive data.

40
MCQeasy

A data engineer needs to ensure that a column containing credit card numbers is masked for all users except those with the PAYMENT_ADMIN role. The masking should be applied consistently across all tables that use a specific tag. Which Snowflake feature should the engineer use?

A.A row access policy that filters rows based on the user's role.
B.A standard masking policy attached directly to each column containing credit card numbers.
C.A secure view that excludes the credit card column for non-admin users.
D.A tag-based masking policy that is associated with a tag and automatically applies to all columns with that tag.
AnswerD

Tag-based masking policies allow you to associate a masking policy with a tag. When the tag is applied to a column, the masking policy is automatically enforced. This ensures consistent protection across all tables that use the tag, and new columns tagged later are automatically covered. It meets the requirement for consistent masking based on a tag.

Why this answer

Tag-based masking policies associate a masking policy with a tag, so that any column assigned that tag automatically inherits the masking behavior. This provides consistent, scalable protection across all tables, including future columns. It eliminates the need to manually attach policies to each column, ensuring that credit card numbers are masked for unauthorized users.

Exam trap

The trap here is choosing manual column attachment or secure views when the requirement specifies consistency across all tables using a tag, which is exactly what tag-based masking provides.

41
Multi-Selecthard

A data engineer is tasked with implementing a data governance strategy that includes classifying sensitive data and applying tags. The engineer plans to use Snowflake's Data Classification and tag-based masking. Which two statements are true regarding the interaction between Data Classification and tags? (Choose two.)

Select 2 answers
A.Tag-based masking policies cannot be applied to system tags; only user-defined tags support masking.
B.Data Classification can only tag columns with user-defined tags, not system tags.
C.Data Classification requires that all tags be manually created before classification can run.
D.Tag-based masking policies can be applied to system tags created by Data Classification.
E.Data Classification automatically assigns system tags to columns based on the classification results.
AnswersD, E

Snowflake allows masking policies to be attached to system tags, including those created by Data Classification. This enables automatic masking of columns that are classified as sensitive, such as those tagged with SEMANTIC_CATEGORY = 'PII'. The masking policy is then enforced whenever the tag is present on a column.

Why this answer

Data Classification automatically assigns system tags to columns based on its analysis, and these system tags can have masking policies attached to them. This integration allows for automatic masking of sensitive data identified by classification. Manual tag creation is not required, and system tags are indeed used and can support masking.

Exam trap

The trap here is assuming that system tags cannot have masking policies or that Data Classification requires manual tags, when in fact system tags are central and support masking.

42
MCQhard

A data engineer is implementing row access policies to enforce data segregation for a multi-tenant application. The table ORDERS contains a column TENANT_ID. The engineer creates a row access policy that uses a mapping table TENANT_MAPPING to associate users with their allowed TENANT_ID values. After applying the policy, the engineer notices that queries against ORDERS are returning no rows for some users who should have access. The mapping table is correctly populated. What is the most likely cause of the issue?

A.The row access policy is defined with a subquery that returns multiple rows for a given user, causing the policy to evaluate to false.
B.The row access policy uses a mapping table that is not qualified with the database and schema, and the user's session does not have the correct current database and schema set.
C.The row access policy uses CURRENT_USER() to filter, but the mapping table maps roles to tenants, not users.
D.The row access policy is defined with a subquery that references the mapping table, but the policy owner does not have the necessary privileges to access the mapping table.
AnswerB

If the policy references the mapping table without fully qualifying it (e.g., using just TENANT_MAPPING instead of DB.SCHEMA.TENANT_MAPPING), the resolution depends on the session's current database and schema. Users with different session contexts might resolve the table incorrectly, leading to no matching rows. This is a common pitfall. Fully qualifying objects in policies ensures consistent behavior regardless of session settings, which is why this is the most likely cause.

Why this answer

Row access policies that reference other tables must use fully qualified names to avoid dependency on session context. If the mapping table is not fully qualified, users with different current database or schema settings may not find the table or may resolve to a different table, resulting in no rows. Fully qualifying the table name ensures that the policy behaves consistently for all users.

Exam trap

The trap here is overlooking session context dependency in policy definitions, assuming that unqualified object references will always resolve correctly.

Ready to test yourself?

Try a timed practice session using only Sf De Data Governance questions.