DEA-C02 Data Governance Practice Question
Which object allows a data engineer to assign a security policy based on a user's geographical location attribute?
⚠ Common exam trap
Candidates often suggest 'Masking Policies' for location-based filtering. Masking hides data content but does not filter out entire rows, which is the specific requirement for location-based access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Row Access Policy.
Row Access Policies are the correct mechanism here. By using a policy that evaluates the current user's session context—specifically looking at attributes like their IP address or a custom 'location' attribute—the policy can filter out rows that the user is not authorized to see based on residency or regional compliance regulations like GDPR, ensuring data sovereignty is upheld throughout the organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Masking Policy.
Why it's wrong here
Masking policies are designed to hide or partially obscure column data at the cell level. They do not have the capability to filter entire rows based on environmental conditions like user location. They are strictly for data obfuscation, not for controlling row-level visibility or access control.
- ✓
Row Access Policy.
Why this is correct
Row Access Policies allow for conditional logic that incorporates context functions like CURRENT_USER or session attributes. This enables the implementation of fine-grained access control where rows are only visible if the user's location satisfies specific regulatory requirements or internal business rules defined within the policy's SQL expression.
- ✗
Secure View.
Why it's wrong here
While secure views can incorporate conditional logic to limit rows, they are less flexible than row access policies. Managing security logic inside many views is difficult compared to a centralized policy object that can be applied to multiple tables, ensuring consistent enforcement and simplified auditability.
- ✗
Tag-based masking.
Why it's wrong here
Tag-based masking allows for applying masking policies based on tags assigned to columns. It does not control row visibility. It is used to streamline the application of masking across many columns, but it cannot perform the row-level filtering required to restrict access based on geographical attributes.
About these practice questions
This DEA-C02 question is part of Courseiva's 229-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This DEA-C02 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C02 exam.