Courseiva

COF-C03 Account Management and Data Governance Practice Question

A security administrator needs to ensure that a set of sensitive columns in an existing table are automatically masked for all users except those with the role 'HR_ADMIN'. The masking must be applied without modifying the underlying data. Which Snowflake feature should be used?

⚠ Common exam trap

Many exam-takers confuse object tagging with data masking; tags classify data but do not enforce masking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic Data Masking

Dynamic Data Masking is the correct feature because it applies masking policies to columns, dynamically masking data based on the user's role at query time without altering stored data. It provides fine-grained control and is designed for this exact scenario of protecting sensitive columns from unauthorized users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Secure Views

    Why it's wrong here

    Secure Views hide the view definition and can restrict access, but they do not automatically mask column values. You would need to manually build logic into the view to mask data, which is less flexible and does not meet the requirement of automatic masking without modifying data.

  • ✗

    Object Tagging

    Why it's wrong here

    Object tagging allows you to assign metadata tags to objects for classification and tracking, but it does not enforce data masking. Tags alone do not change query results or restrict access to column values. Therefore, it cannot automatically mask sensitive columns for users without HR_ADMIN.

  • ✗

    Row Access Policies

    Why it's wrong here

    Row Access Policies filter rows based on conditions, not columns. They are used to restrict which rows a user can see, not to mask column values. Applying a row access policy would not obfuscate the sensitive column data for unauthorized users.

  • ✓

    Dynamic Data Masking

    Why this is correct

    Dynamic Data Masking uses masking policies to obfuscate column values at query time based on the user's role. It does not alter the stored data. Applying a masking policy to the sensitive columns and granting the policy's exemption to HR_ADMIN achieves the requirement without data changes.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.