COF-C03 Practice Question: Snowflake AI Data Cloud Features and Architecture
A Snowflake administrator needs to provide a data analyst with the ability to read data from a specific table but prevent the analyst from seeing any personally identifiable information (PII) columns. The administrator decides to use a masking policy. Which statement accurately describes the behavior of a masking policy in Snowflake?
⚠ Common exam trap
It's easy for candidates to confuse masking policies with row access policies or believing that masking alters the stored data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A masking policy is applied at the column level and can conditionally alter the data returned based on the user's role.
Masking policies in Snowflake are column-level security objects that dynamically mask data based on the user's role. They allow the administrator to hide PII from the analyst while still granting access to the table. The policy can be conditional, so different roles see different values. This meets the requirement without altering the stored data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A masking policy permanently replaces the sensitive data in the table with masked values for all users.
Why it's wrong here
Masking policies do not alter the stored data; they dynamically mask data at query time. The underlying data remains unchanged, and authorized users can still see the original values. Permanent replacement would be data obfuscation, not masking. The administrator wants to preserve the original data for other roles.
- ✗
A masking policy is applied at the table level and hides entire rows that contain sensitive data.
Why it's wrong here
Masking policies are not applied at the table level; they are attached to individual columns. They do not hide entire rows; instead, they mask the values within the specified column. Row-level filtering is achieved through row access policies. The administrator needs column-level masking, not row hiding.
- ✗
A masking policy can only be applied to columns of type VARCHAR and not to numeric or date columns.
Why it's wrong here
Masking policies can be applied to columns of various data types, including numeric, date, and timestamp, not just VARCHAR. Snowflake supports masking policies on most data types. The restriction to VARCHAR is incorrect and would limit the administrator's ability to mask PII such as phone numbers stored as numbers or dates of birth.
- ✓
A masking policy is applied at the column level and can conditionally alter the data returned based on the user's role.
Why this is correct
Masking policies in Snowflake are column-level security features that can transform data at query time based on the role of the user executing the query. They allow conditional masking, such as showing full data to privileged roles and masked data to others. This precisely matches the administrator's requirement to hide PII from the analyst while allowing access to other columns.
About these practice questions
Courseiva writes every COF-C03 question from scratch — 280 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.