COF-C03 Account Management and Data Governance Practice Question
An organization requires that specific sensitive columns in a table be masked for all users except those in the 'DATA_STEWARD' role. Which mechanism should the architect implement to enforce this policy efficiently?
⚠ Common exam trap
Candidates often assume that creating multiple views with different permissions is the correct approach, failing to realize that DDM is more efficient, centralized, and avoids the maintenance overhead of managing numerous views.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a masking policy using the IS_ROLE_IN_SESSION function.
Dynamic Data Masking (DDM) provides a centralized way to protect sensitive data by applying masking policies to columns. By using the IS_ROLE_IN_SESSION function within the policy, the system evaluates the user's active role dynamically during query execution. This ensures that only members of the DATA_STEWARD role see unmasked data, while others see the masked output, maintaining governance consistency without needing to physically alter the underlying data storage or create multiple filtered views.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a row-level security policy to the table.
Why it's wrong here
Row-level security restricts access to entire rows based on user attributes, not specific column values. While useful for limiting visibility to entire records, it does not provide the column-level obfuscation required to mask sensitive fields like SSNs or emails while still allowing access to other columns in the same row.
- ✗
Create secure views that use a CASE statement to filter columns.
Why it's wrong here
While secure views can mimic masking, they are harder to maintain at scale compared to DDM policies. If the table schema changes or more columns need protection, views require manual updates and complex SQL management, whereas masking policies can be applied to many columns across different tables centrally.
- ✓
Apply a masking policy using the IS_ROLE_IN_SESSION function.
Why this is correct
Dynamic Data Masking policies are the native Snowflake feature for this requirement. Using IS_ROLE_IN_SESSION allows the policy to check the current session's role effectively. This is the standard, scalable approach for enforcing column-level security across an account, ensuring that sensitive data is protected regardless of how it is queried.
- ✗
Use data replication to create a separate table for stewards.
Why it's wrong here
Data replication is designed for business continuity and disaster recovery, not for fine-grained access control. Creating a separate table for specific roles introduces synchronization overhead and risks data inconsistency, making it an inefficient and dangerous approach for implementing column-level security policies within a production Snowflake environment.
About these practice questions
One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Snowflake exam blueprint
This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.