COF-C03 Account Management and Data Governance Practice Question
An administrator needs to restrict access to sensitive PII data. Which TWO of the following are valid approaches to implement governance in Snowflake?
⚠ Common exam trap
Candidates frequently confuse row access policies and data masking with traditional database views or warehouse-level resource monitors used for cost control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a Row Access Policy to the table.
Snowflake provides several layers of defense-in-depth to secure sensitive information. Row Access Policies filter which rows a user can see, while Dynamic Data Masking transforms column data based on user privileges. Using these in combination allows architects to build a highly restrictive environment where users only interact with the exact data subsets and column values they are authorized to access, complying with strict regulatory data privacy standards.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply a Row Access Policy to the table.
Why this is correct
Row Access Policies are a native governance feature that restricts the number of rows returned by a query based on the current user's role or attributes. This is a primary tool for ensuring users only view data relevant to their specific department or geographic region.
- ✓
Implement column-level Dynamic Data Masking.
Why this is correct
Dynamic Data Masking is the standard Snowflake method for obfuscating specific sensitive columns, such as email addresses or social security numbers, based on the user's role. It is highly efficient because it applies the transformation at runtime without modifying the underlying raw data stored.
- ✗
Use physical data partitioning to store PII in separate tables.
Why it's wrong here
While physically separating data can work, it creates significant maintenance overhead and breaks query simplicity. It is generally considered an anti-pattern in Snowflake because it prevents users from performing joins across the full dataset and increases the risk of data drift between tables.
- ✗
Assign the ACCOUNTADMIN role to all data stewards.
Why it's wrong here
Assigning the ACCOUNTADMIN role to data stewards violates the principle of least privilege. ACCOUNTADMIN has unrestricted access to all data and system configurations. Governance best practices dictate that stewards should have only the minimum permissions necessary to manage policies and access, not full system control.
- ✗
Export data to an encrypted S3 bucket for security.
Why it's wrong here
Exporting data to an external location for governance is counter-productive because it moves data outside of Snowflake's integrated security control plane. This creates a data security silo, complicates audit logging, and increases the attack surface, whereas Snowflake's native policies are designed for this exact purpose.
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.