COF-C03 Account Management and Data Governance Practice Question
A governance team is designing a strategy to classify and protect data across many databases in a Snowflake account. They want a scalable approach that applies protection consistently without editing each table definition manually. Which two capabilities should the team use to accomplish this goal? (Choose two.)
⚠ Common exam trap
The trap here is treating an encryption feature such as Tri-Secret Secure as a data classification and masking mechanism, when it protects data at rest rather than controlling query output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the ACCOUNT_USAGE.TAG_REFERENCES view to audit which columns carry governance tags.
Tag-based masking and tag reference auditing together form a scalable governance pattern. Associating masking policies with tags means protection follows the tag wherever it is applied, and TAG_REFERENCES provides the visibility needed to confirm coverage and identify gaps. Manual per-column policies and broad role grants do not scale, and encryption features address a different control objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant the SECURITYADMIN role to all analysts so they can manage their own masking policies.
Why it's wrong here
Granting SECURITYADMIN broadly violates least privilege and gives analysts the ability to alter users, roles, and grants account-wide. It does not provide a scalable protection mechanism and actively increases risk. Managing masking policies should remain with a small governance group, and analysts should receive only the data access they require through roles.
- ✓
Use the ACCOUNT_USAGE.TAG_REFERENCES view to audit which columns carry governance tags.
Why this is correct
TAG_REFERENCES in the ACCOUNT_USAGE schema records tag assignments across the account, including the object, column, and tag involved. Governance teams query it to verify coverage, find untagged sensitive columns, and produce audit evidence. It complements tag-based masking by providing visibility into where tags are applied, which is essential for a scalable classification program.
- ✗
Apply a separate masking policy to every sensitive column using ALTER TABLE for each column.
Why it's wrong here
Attaching a distinct masking policy to each column manually does not scale and is exactly the manual editing the team wants to avoid. It also creates maintenance overhead because policy changes must be repeated across many objects. Tag-based masking is the intended alternative for consistent, centralized protection across many tables.
- ✗
Enable Tri-Secret Secure to automatically classify and mask sensitive columns.
Why it's wrong here
Tri-Secret Secure is a security feature that combines a Snowflake-managed key with a customer-managed key for encryption at rest. It protects data cryptographically but does not classify columns or apply masking policies, so it does not fulfill the governance team's requirement to classify and mask sensitive data consistently across many tables.
- ✓
Create tags and associate masking policies with them, then apply the tags to columns across tables.
Why this is correct
Tag-based masking lets a governance team define a tag, attach a masking policy to that tag, and then apply the tag to any number of columns. Protection scales because the policy follows the tag, so adding a new tagged column automatically inherits the masking behavior without editing each table definition or creating a separate policy per column.
About these practice questions
This COF-C03 question is part of Courseiva's 280-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.