Courseiva

COF-C03 Account Management and Data Governance Practice Question

A data steward needs to ensure that a column containing email addresses is masked for all users except those with the role 'COMPLIANCE_OFFICER'. The masking should show a fixed string '****' for unauthorized users. Which Snowflake feature should be used?

⚠ Common exam trap

A common mix-up: candidates confuse row access policies with masking policies; row access policies filter rows, not mask column values.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Masking policy

A masking policy in Snowflake allows column-level security by dynamically masking data based on the user's role or other conditions. By applying a masking policy to the email column that returns '****' for all roles except 'COMPLIANCE_OFFICER', the data steward ensures that only authorized users see the actual email addresses. This is the correct feature for column-level masking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Masking policy

    Why this is correct

    A masking policy is a schema-level object that can be applied to a column to dynamically mask its data based on the user's role. You can define a policy that returns '****' for all roles except 'COMPLIANCE_OFFICER'. This precisely meets the requirement of column-level masking for unauthorized users.

  • ✗

    Object tagging

    Why it's wrong here

    Object tagging is used to assign metadata to objects for governance and tracking, but it does not mask data. Tags can be used in conjunction with masking policies, but alone they do not enforce any data protection. This option does not provide the required masking behavior.

  • ✗

    Secure view

    Why it's wrong here

    Secure views hide the view definition and can be used to restrict access to underlying data, but they do not provide column-level masking based on roles. They are typically used to prevent exposure of the query logic, not to dynamically mask data values for specific roles.

  • ✗

    Row access policy

    Why it's wrong here

    Row access policies filter rows based on conditions, such as user role. They do not mask column values; they restrict which rows are visible. In this scenario, the requirement is to mask a specific column's values, not to filter rows.

About these practice questions

This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.