COF-C03 Account Management and Data Governance Practice Question
A governance team needs to implement data classification and access control for a new table containing sensitive data. They want to (1) tag columns with a sensitivity level, and (2) enforce that only users with a specific role can see the unmasked data. Which two Snowflake features should they use together to achieve these goals? (Choose two.)
⚠ Common exam trap
Many candidates confuse row-level filtering with column-level masking, or assuming that tagging alone can enforce access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Object tagging
Object tagging is used to classify columns with sensitivity levels, providing metadata for governance. Masking policies enforce column-level access control by dynamically masking data based on the user's role. Together, they satisfy both requirements: tagging for classification and masking for access enforcement. Other features like row access policies or secure views do not provide the needed column-level masking and tagging combination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network policy
Why it's wrong here
A network policy restricts access based on IP addresses, not user roles or data content. It does not provide column-level masking or tagging. It is used for network-level security, such as allowing or blocking connections from certain IP ranges. It is unrelated to the requirements of data classification and column masking.
- ✗
Row access policy
Why it's wrong here
A row access policy filters rows based on conditions, not columns. It cannot mask or restrict access to specific column values. While it can restrict which rows a role sees, it does not provide column-level masking. Therefore, it does not meet the requirement to show unmasked data only to a specific role for certain columns.
- ✗
Secure view
Why it's wrong here
A secure view hides the view definition and prevents certain optimizations, but it does not inherently provide column-level masking based on role. While a secure view could include a CASE statement to mask data, it would not be as flexible or centralized as a masking policy. It also does not address the tagging requirement. Thus, it is not the best fit.
- ✓
Object tagging
Why this is correct
Object tagging allows the governance team to assign tags to columns, such as sensitivity level, for classification and tracking. Tags can be used to document data sensitivity and can be leveraged in policies. They are essential for the first requirement of tagging columns with a sensitivity level. Tags alone do not enforce access control, but they provide metadata for governance.
- ✓
Masking policy
Why this is correct
A masking policy is used to conditionally mask column data based on the user's role. It can use the CURRENT_ROLE() function to show unmasked data only to a specific role and masked data to others. This directly enforces the second requirement of restricting unmasked data to a specific role. Masking policies are applied to columns and are evaluated at query time.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.