Courseiva

DEA-C02 · topic practice

Data Governance practice questions

This domain covers Snowflake governance primitives: access auditing via ACCOUNT_USAGE and ACCESS_HISTORY, Object Tagging, masking and row access policies, and secure data sharing. Questions present audit queries, policy designs, or sharing scenarios and ask you to interpret lineage output, pick correct governance combinations, or identify performance and correctness trade-offs.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Data Governance

What the exam tests

What to know about Data Governance

Be able to query ACCESS_HISTORY to explain column lineage, attach tags for cost and classification, and combine masking with sharing. The critical skill is designing Row Access Policies whose mapping-table joins stay performant and deterministic while enforcing least-privilege access.

Reading ACCESS_HISTORY and base_objects_accessed to trace column-level data lineage across queries

Applying Object Tagging for cost attribution, classification, and tag-based masking policies

Combining Dynamic Data Masking with Secure Data Sharing to expose masked subsets to third parties

Designing Row Access Policies that join mapping tables and evaluating their query performance impact

Watch out for

Common Data Governance exam traps

  • ▸Assuming base_objects_accessed shows only direct tables, ignoring that it captures upstream base tables behind views and CTEs
  • ▸Confusing tag-based masking with direct masking policies, or expecting tags alone to mask data without a masking policy attached
  • ▸Writing Row Access Policies with non-deterministic or heavy subqueries against mapping tables, causing scan and join overhead per row

Practice set

Data Governance questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following are true regarding Snowflake Access History?

Which THREE of the following are requirements when using Data Governance with Snowflake's native features?

Question 3mediummultiple choice
Read the full Data Governance explanation →

When considering data lineage, which component is most effective for tracking the movement of data from raw landing tables to curated marts?

Which TWO of the following are true regarding the relationship between Tags and Masking Policies?

Question 5mediummultiple choice
Read the full Data Governance explanation →

A data engineer needs to ensure that PII data in the 'EMAIL' column is obscured for all non-admin users while allowing analysts to perform aggregate counts. Which approach is most efficient and adheres to least privilege?

Which THREE of the following are required to successfully implement Row-Level Security (RLS) in Snowflake?

Question 7mediummultiple choice
Read the full Data Governance explanation →

What is the primary function of the 'TAG_REFERENCES' table function in Snowflake?

Which TWO requirements must be met before a user can successfully apply a Dynamic Masking Policy to a column in a table? (Choose two.)

A data engineer is using Snowflake's Data Classification feature to identify and protect sensitive information. Which THREE steps are part of the standard workflow for classifying data in Snowflake? (Choose three.)

Question 10hardmultiple choice
Read the full Data Governance explanation →

A data engineer needs to implement a solution where access to a column containing salary information is restricted based on the user's department. Users in the 'HR' department should see actual salaries, while all others should see a fixed value of 0. The solution must be scalable and not require changes when new departments are added. Which Snowflake feature should be used?

Question 11hardmultiple choice
Read the full Data Governance explanation →

A data engineer needs to ensure that a row access policy on a table enforces that users from the 'HR' department can only see rows where the 'DEPARTMENT' column equals 'HR'. The policy uses a mapping table that is updated frequently. The engineer wants to minimize performance impact and ensure the policy is applied correctly. Which approach should the engineer take?

Question 12hardmultiple choice
Read the full Data Governance explanation →

A data engineer needs to ensure that a row access policy on the SALES table filters rows based on the region of the querying user, but the policy must not filter rows for users with the ACCOUNTADMIN role. The engineer creates a mapping table that maps roles to regions. Which approach correctly implements this requirement?

A data engineer is implementing a data governance strategy in Snowflake and needs to ensure that sensitive data is properly protected and auditable. The engineer plans to use a combination of Snowflake features. Which two of the following are required to enable tag-based masking policies? (Choose two.)

Question 14mediummultiple choice
Read the full Data Governance explanation →

A financial institution stores transaction data in a Snowflake table that includes a column 'ACCOUNT_NUMBER'. The data engineering team wants to prevent analysts from seeing the full account number, but analysts must still be able to join on this column. The security team requires that the masking be applied automatically based on the analyst's role, without modifying existing queries. Which Snowflake feature should be used?

Question 15easymultiple choice
Read the full Data Governance explanation →

A data engineer is configuring a masking policy on a column that contains phone numbers. The policy should show the full phone number only to users with the role PII_READER and otherwise show a partially masked value. Which masking policy expression correctly implements this?

Question 16easymultiple choice
Read the full Data Governance explanation →

A Snowflake administrator needs to know which columns in a table have been assigned a specific tag named PII_LEVEL so that a governance report can be produced. Which approach most directly returns the columns carrying that tag?

Question 17mediummultiple choice
Read the full Data Governance explanation →

A data engineer at a financial services company has been asked to implement dynamic data masking on sensitive columns in a table called ACCOUNTS. The masking policy should allow members of the role FINANCE_ANALYST to see full account numbers, while all other roles see only the last four digits. The engineer creates a masking policy and applies it to the ACCOUNT_NUMBER column. After testing, the engineer notices that users with the ACCOUNTADMIN role can see the full account number even though they are not in FINANCE_ANALYST. What should the engineer do to ensure that ACCOUNTADMIN users also see masked data?

Question 18mediummultiple choice
Read the full Data Governance explanation →

A data engineer is configuring a masking policy on a column containing credit card numbers. The policy should show the full number only to users with the role 'PAYMENT_ADMIN' and show a partially masked version (e.g., last four digits) to all other users. Which masking policy expression correctly implements this?

Question 19hardmultiple choice
Read the full Data Governance explanation →

A data engineer needs to enforce a policy that restricts access to rows in a SALES table based on the region of the sales representative. The policy must dynamically evaluate the current user's region attribute, which is stored as a tag on the user object. Which Snowflake feature should the engineer use to implement this requirement?

A data engineer is responsible for implementing a data governance strategy using Snowflake tags. The engineer needs to ensure that tags are applied consistently and that tag-based masking policies are enforced. Which two of the following statements are true regarding Snowflake tags and their usage? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Data Governance sessions

Start a Data Governance only practice session

Every question in these sessions is drawn from the Data Governance domain — nothing else.

Related practice questions

Related DEA-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the DEA-C02 exam test about Data Governance?
Be able to query ACCESS_HISTORY to explain column lineage, attach tags for cost and classification, and combine masking with sharing. The critical skill is designing Row Access Policies whose mapping-table joins stay performant and deterministic while enforcing least-privilege access.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Data Governance questions in a focused session?
Yes — the session launcher on this page draws every question from the Data Governance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other DEA-C02 topics?
Use the topic links above to move to related areas, or go back to the DEA-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the DEA-C02 exam covers. They are not copied from any real exam or dump site.