Courseiva

COF-C03 Account Management and Data Governance Practice Question

A security administrator has created a masking policy that replaces the value of a column with a SHA2 hash for users without the role 'HR_ROLE'. The policy is applied to the 'SSN' column of the 'EMPLOYEES' table. A user with the role 'ANALYST_ROLE' queries the table and sees the hashed values. However, when the same user runs a query that includes the 'SSN' column in a WHERE clause, the query returns no results even though matching records exist. What is the most likely cause of this behavior?

⚠ Common exam trap

The trap here is assuming that masking policies only affect the output of a query and not the evaluation of predicates like WHERE clauses, leading to confusion when queries return no rows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The masking policy is applied to the column, but the user does not have the privilege to see the original values, so the WHERE clause is evaluated against the masked values, which do not match the search condition.

The correct answer is that the WHERE clause is evaluated against masked values. Masking policies transform data at query time, so any filtering or joining on the masked column uses the masked representation. This is a critical concept: masking does not prevent the column from being used in predicates, but it changes the data used for those predicates, which can lead to unexpected results if the user expects to filter on original values.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user lacks the SELECT privilege on the table, so the query returns no rows.

    Why it's wrong here

    If the user lacked SELECT privilege, the query would fail with an authorization error, not return no rows. The scenario states the user can query the table and see hashed values, so they have SELECT privilege.

  • ✓

    The masking policy is applied to the column, but the user does not have the privilege to see the original values, so the WHERE clause is evaluated against the masked values, which do not match the search condition.

    Why this is correct

    Masking policies are applied at query runtime before any filtering occurs. When a user without the unmasking role queries the column, they see the masked value. If they then use that masked value in a WHERE clause, the comparison is against the masked data, not the original. This can lead to unexpected empty results if the search term is the original value.

  • ✗

    The masking policy is not applied to the WHERE clause, so the original values are used for filtering, but the user cannot see them, resulting in an error.

    Why it's wrong here

    Masking policies are applied to all references of the column in the query, including in WHERE clauses. The query would not error; it would simply filter on masked values. The user sees the masked values in the output, confirming the policy is active.

  • ✗

    The user's role has not been granted the USAGE privilege on the masking policy, so the policy is bypassed and the original values are used, but the user cannot see them due to column-level security.

    Why it's wrong here

    USAGE privilege on a masking policy is not required for the policy to take effect. Masking policies are applied based on the conditions defined within them, typically role-based. The user sees masked values, so the policy is being enforced.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.