COF-C03 Account Management and Data Governance Practice Question
A data engineer needs to ensure that sensitive PII columns are masked for all users except for a specific group of HR analysts. Which Snowflake feature is the most efficient and scalable solution to implement this requirement?
⚠ Common exam trap
Candidates often suggest using Row Access Policies or separate tables for different roles, which creates unnecessary data redundancy and significant maintenance challenges compared to using DDM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement Dynamic Data Masking policies on the sensitive columns.
Dynamic Data Masking (DDM) allows centralized management of data access policies based on the user's role. By attaching a masking policy to a column, Snowflake automatically evaluates the user's role at query runtime. This approach is superior to static masking or manual view management because it centralizes governance, minimizes data duplication, and ensures that security policies remain consistent regardless of how the user accesses the underlying table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create secure views for every user role in the account.
Why it's wrong here
Maintaining secure views for every unique role creates significant technical debt and management overhead. As schemas evolve, keeping views synchronized with the underlying base table becomes error-prone and complex, making it an inefficient solution compared to dynamic masking policies which apply directly to column definitions.
- ✓
Implement Dynamic Data Masking policies on the sensitive columns.
Why this is correct
Dynamic Data Masking provides a centralized and scalable way to protect sensitive data. By defining a policy that checks for the HR role, security administrators can ensure that data is masked for general users while remaining visible to HR, all without modifying the physical data stored in the tables.
- ✗
Use the UNMASK function in every query selecting sensitive data.
Why it's wrong here
Snowflake does not provide an UNMASK function for ad-hoc queries. Relying on users to manually handle sensitive data exposure during query execution violates the principle of least privilege and provides no automated enforcement of data governance standards across the organization's analytical workloads.
- ✗
Apply Row-Level Security to hide rows containing sensitive PII.
Why it's wrong here
Row-Level Security (Row Access Policies) restricts access to entire rows, not individual columns. If a user needs access to a row for non-sensitive data but must have PII masked, Row Access Policies would block the entire record, failing to meet the requirement of providing masked data access.
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.