COF-C03 Account Management and Data Governance Practice Question
A company has a table named customer_orders that contains a column storing the customer's full name. A masking policy has been applied to that column. The policy uses CURRENT_ROLE() to compare the executing role against a list of roles allowed to see the raw value. A user with a role that is not in the allowed list runs a query that includes the column in an ORDER BY clause. What does the user see?
⚠ Common exam trap
The trap here is believing that a masked column can still influence sorting on its raw value, when the policy replaces the column reference everywhere.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user sees the masked value in the result set and the sort is performed on the masked value.
A masking policy rewrites every reference to the protected column for unauthorized users, including references in ORDER BY. The user therefore sees the masked value and sorting is based on that masked value. The policy is not bypassed by placing the column in a sort clause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user sees the raw value in the result set but the sort is performed on the masked value.
Why it's wrong here
A masking policy is applied consistently to the column wherever it is referenced. If the user is not authorized, the raw value is never exposed in the result set. It is not possible for the result set to show the raw value while sorting on the masked value, because the policy replaces the column reference in all parts of the query.
- ✓
The user sees the masked value in the result set and the sort is performed on the masked value.
Why this is correct
When a masking policy is attached to a column, every reference to that column in a query is replaced by the policy expression for users who are not authorized to see the raw data. This includes references in the select list, WHERE clause, and ORDER BY clause. Therefore the user sees the masked value and the ordering is computed on the masked representation, not the original name.
- ✗
The user sees the masked value in the result set, but the sort is performed on the raw value because ORDER BY is evaluated before masking.
Why it's wrong here
Masking is applied as part of query processing, and the policy expression replaces the column reference before the sort is evaluated. There is no separate phase where ORDER BY uses the raw value. The user who is not authorized sees only the masked value, and the ordering reflects that masked value, not the underlying raw data.
- ✗
The query fails because masking policies cannot be applied to columns used in ORDER BY.
Why it's wrong here
Masking policies do not prohibit a column from being used in ORDER BY. The policy still applies and returns the masked value, which is then used for sorting. The query does not fail simply because a masked column appears in an ORDER BY clause, so this option misstates the behavior of column-level security.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.