COF-C03 Account Management and Data Governance Practice Question
A security administrator needs to ensure that a set of sensitive columns in an existing table are automatically masked for all users except those with the role 'HR_ADMIN'. The masking must be applied without modifying the underlying data. Which Snowflake feature should be used?
⚠ Common exam trap
Many exam-takers confuse object tagging with data masking; tags classify data but do not enforce masking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Data Masking
Dynamic Data Masking is the correct feature because it applies masking policies to columns, dynamically masking data based on the user's role at query time without altering stored data. It provides fine-grained control and is designed for this exact scenario of protecting sensitive columns from unauthorized users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secure Views
Why it's wrong here
Secure Views hide the view definition and can restrict access, but they do not automatically mask column values. You would need to manually build logic into the view to mask data, which is less flexible and does not meet the requirement of automatic masking without modifying data.
- ✗
Object Tagging
Why it's wrong here
Object tagging allows you to assign metadata tags to objects for classification and tracking, but it does not enforce data masking. Tags alone do not change query results or restrict access to column values. Therefore, it cannot automatically mask sensitive columns for users without HR_ADMIN.
- ✗
Row Access Policies
Why it's wrong here
Row Access Policies filter rows based on conditions, not columns. They are used to restrict which rows a user can see, not to mask column values. Applying a row access policy would not obfuscate the sensitive column data for unauthorized users.
- ✓
Dynamic Data Masking
Why this is correct
Dynamic Data Masking uses masking policies to obfuscate column values at query time based on the user's role. It does not alter the stored data. Applying a masking policy to the sensitive columns and granting the policy's exemption to HR_ADMIN achieves the requirement without data changes.
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.