COF-C03 Account Management and Data Governance Practice Question
A governance team is implementing data classification in Snowflake and wants to use tags to drive both discovery and enforcement. Which TWO capabilities are provided by Snowflake tags in this context? (Choose two.)
⚠ Common exam trap
The trap here is treating tags as an access-control or encryption mechanism, when they are metadata labels that can drive masking but do not grant privileges or encrypt data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tags can be attached to tables, columns, and other objects to record classification metadata.
Snowflake tags record classification metadata on objects such as tables and columns, supporting discovery and reporting. They also integrate with masking policies through tag-based masking, so any column carrying the tag is automatically protected. Tags do not encrypt data, do not grant privileges, and cannot filter rows in a query, making those options incorrect for this governance use case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tags replace the need for role-based access control by granting privileges to users automatically.
Why it's wrong here
Tags do not grant privileges and do not substitute for role-based access control. They classify objects and can drive masking policies, but access to objects is still governed by grants to roles. Assuming tags grant access would create a serious misunderstanding of Snowflake's access model, where privileges are always explicitly granted to roles or users.
- ✗
Tags automatically encrypt the underlying column data at rest.
Why it's wrong here
Snowflake encrypts data at rest by default at the storage layer, independent of any tag. Tags are metadata and do not trigger encryption of specific columns. Attributing encryption to tags conflates a platform-wide storage control with a classification label. Tags can inform governance decisions, but they do not perform encryption of the data they mark.
- ✓
Tags can be attached to tables, columns, and other objects to record classification metadata.
Why this is correct
Snowflake tags are schema-level objects that can be assigned to a wide range of objects, including tables, columns, views, and warehouses. This makes them suitable for recording classification such as PII or sensitivity level directly on the object. The metadata is then queryable, enabling discovery and reporting, which is a core governance use case for tags in a classification program.
- ✗
Tags can be used in the WHERE clause of a query to filter rows based on the tag value.
Why it's wrong here
Tag values are metadata about objects, not row-level data, so they cannot be referenced in a query's WHERE clause to filter rows. Row filtering is accomplished with row access policies or view predicates. Using a tag to filter rows misunderstands the tag model, which operates at the object and column level rather than on individual data rows.
- ✓
A masking policy can be associated with a tag so that any column carrying the tag is automatically masked.
Why this is correct
Tag-based masking lets a masking policy be attached to a tag rather than to individual columns. Any column assigned that tag automatically inherits the masking behavior, which scales governance across many tables. This enforcement capability is a primary reason governance teams adopt tags for classification, since it links discovery metadata directly to a protective control.
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.