COF-C03 Account Management and Data Governance Practice Question
A security team at a healthcare company must guarantee that query results returned from a table named PATIENT_RECORDS are filtered based on the department of the user executing the query, without requiring any changes to existing SQL statements. The policy must evaluate a mapping table that lists each user and their department. Which Snowflake object should be created to meet this requirement?
⚠ Common exam trap
Candidates often confuse row-level filtering with column-level masking, since both are policy objects attached to a table but only one removes rows from the result set.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A row access policy attached to the PATIENT_RECORDS table that references a mapping table.
Row access policies are the Snowflake feature designed to filter rows at query time based on the execution context, such as the current user or role. Because the policy is evaluated dynamically and can join against a mapping table, it enforces per-department visibility transparently: existing SQL statements continue to work, and users see only the rows their department is authorized to view.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A secure view defined over PATIENT_RECORDS that joins the mapping table.
Why it's wrong here
A secure view can restrict what a caller sees, but Snowflake does not guarantee that predicates from an outer query are pushed into the view, and the view owner's privileges are used for the underlying objects. It would also require users to query the view instead of the base table, which conflicts with the requirement that existing SQL statements remain unchanged.
- ✗
A masking policy applied to the DEPARTMENT column of the PATIENT_RECORDS table.
Why it's wrong here
A masking policy rewrites the value returned for a column at query time, so it can obscure a department name but it cannot remove entire rows from the result set. Because the requirement is to filter rows so users only see records belonging to their own department, a column-level masking policy does not satisfy the filtering behavior described in the scenario.
- ✗
A network policy that limits access to the PATIENT_RECORDS table by department IP ranges.
Why it's wrong here
Network policies restrict where connections originate from at the account or user level based on IP address ranges. They have no concept of the department stored in a mapping table and cannot filter individual rows of a result set, so they cannot enforce the per-department row visibility this scenario requires.
- ✓
A row access policy attached to the PATIENT_RECORDS table that references a mapping table.
Why this is correct
A row access policy is a schema-level object that is attached to a table and evaluated at query time, returning a boolean expression that determines which rows are visible. By referencing a mapping table that correlates the CURRENT_USER() or CURRENT_ROLE() with a department, the policy filters rows automatically without any change to the SQL that users execute.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.