COF-C03 Account Management and Data Governance Practice Question
A data governance team wants to classify data in a table using tags. They create a tag 'PII' and apply it to the 'ssn' column. Later, they need to ensure that only users with the 'PII_READER' role can see the actual values, while all other users see a masked value. They decide to use a tag-based masking policy. Which statement accurately describes how tag-based masking policies work in Snowflake?
⚠ Common exam trap
A common mix-up: candidates confuse the APPLY TAG privilege with the enforcement of tag-based masking, when enforcement is automatic once the tag and policy are linked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A tag-based masking policy is applied to a tag, and any column with that tag automatically inherits the masking policy, provided the tag is set at the column level and the policy is attached to the tag.
Tag-based masking policies provide a scalable way to protect sensitive data by associating a masking policy with a tag. When a column is tagged, the policy automatically applies. This decouples the masking logic from individual column alterations. The policy attached to the tag defines the masking condition, often using IS_ROLE_IN_SESSION to allow specific roles to see unmasked data. This approach simplifies governance across many tables and columns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A tag-based masking policy is only enforced when the tag is set on the column and the user querying the data has the APPLY TAG privilege on the tag.
Why it's wrong here
The APPLY TAG privilege allows a role to set tags on objects, but it does not affect whether masking is enforced. Masking enforcement depends on the policy attached to the tag and the user's role relative to the policy condition. Users do not need APPLY TAG to be subject to masking; they simply see masked data unless exempted by the policy.
- ✓
A tag-based masking policy is applied to a tag, and any column with that tag automatically inherits the masking policy, provided the tag is set at the column level and the policy is attached to the tag.
Why this is correct
Tag-based masking policies are attached to a tag object. When a column is assigned that tag, the masking policy associated with the tag is automatically applied to the column. This allows centralized management: changing the policy on the tag affects all tagged columns. The policy must be attached to the tag using ALTER TAG ... SET MASKING POLICY, and the tag must be set on the column.
- ✗
A tag-based masking policy requires that the tag be applied at the table level, and the policy then masks all columns in the table that contain sensitive data.
Why it's wrong here
Tags are applied at the column level for masking purposes, not the table level. Applying a tag to a table does not automatically mask columns; the tag must be set on each column individually. Tag-based masking policies do not scan table contents to determine sensitive columns; they rely on explicit column tagging.
- ✗
A tag-based masking policy can only be used with tags that are defined at the account level, not at the schema or database level.
Why it's wrong here
Tags can be created at the account, database, or schema level. Tag-based masking policies work with tags regardless of their scope, as long as the tag is set on the column and the policy is attached to the tag. The scope of the tag does not restrict the use of tag-based masking; it only affects visibility and management.
About these practice questions
This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.