Courseiva

COF-C03 · domain

Account Management and Data Governance

This domain covers Snowflake roles, privileges, and data protection features. Questions present exhibits showing role hierarchies, masking or row access policies, and access failures, then ask you to diagnose why a user sees or cannot see data. You must know how USAGE, SELECT, and schema-level grants interact, plus where access history and Time Travel fit into governance.

47 questions9 easy25 medium13 hard

Focused practice

Practice Account Management and Data Governance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Account Management and Data Governance

Be able to trace a privilege chain from role to table and explain what a policy returns to a given role. The most important thing: USAGE on a database does not expose objects; you also need USAGE on the schema and SELECT on the table.

Diagnosing missing SELECT or schema USAGE grants in a role hierarchy

Reading masking policies and row access policies in query results

Using ACCESS_HISTORY and ACCOUNT_USAGE views to audit table access

Applying Time Travel and Fail-safe concepts for data recovery and retention

Watch out for

Common Account Management and Data Governance exam traps

  • ▸Assuming database USAGE alone grants table visibility; schema and table SELECT privileges are also required.
  • ▸Confusing masking policy output with row filtering; masked values appear, rows are not removed.
  • ▸Treating Time Travel as permanent archival storage rather than a bounded retention window.

Question index

All Account Management and Data Governance questions (47)

Click any question to see the full explanation, or start a practice session above.

1

A Snowflake account has a custom role named DATA_ENGINEER. The administrator wants to ensure that DATA_ENGINEER can create databases and warehouses but cannot manage users or roles. Which predefined role should DATA_ENGINEER be granted to achieve this?

Medium
2

A compliance officer needs to confirm which roles have been granted to a specific user across the account, including grants made through role hierarchies. Which Snowflake command should be used to retrieve this information?

Easy
3

A user is assigned the 'SECURITYADMIN' role. Which of the following tasks can this user perform?

Hard
4

A governance team is designing a strategy to classify and protect data across many databases in a Snowflake account. They want a scalable approach that applies protection consistently without editing each table definition manually. Which two capabilities should the team use to accomplish this goal? (Choose two.)

Hard
5

A company requires all data at rest within Snowflake to be encrypted using a customer-provided key. Which feature should they implement?

Medium
6

Which object type in Snowflake is required to store a compiled masking policy before it can be applied to a table column?

Easy
7

A data administrator needs to identify which users have failed to log in successfully over the last 30 days due to authentication errors. Which Snowflake object should they query?

Medium
8

A security administrator has created a masking policy that replaces the value of a column with a SHA2 hash for users without the role 'HR_ROLE'. The policy is applied to the 'SSN' column of the 'EMPLOYEES' table. A user with the role 'ANALYST_ROLE' queries the table and sees the hashed values. However, when the same user runs a query that includes the 'SSN' column in a WHERE clause, the query returns no results even though matching records exist. What is the most likely cause of this behavior?

Hard
9

A security administrator needs to ensure that a set of sensitive columns in an existing table are automatically masked for all users except those with the role 'HR_ADMIN'. The masking must be applied without modifying the underlying data. Which Snowflake feature should be used?

Medium
10

Refer to the exhibit. A user with the role 'ANALYST_ROLE' cannot see tables inside the 'sales_db.public' schema despite having 'USAGE' on the database. What is the most likely reason for this access issue?

Hard
11

A data governance team wants to classify data in a table using tags. They create a tag 'PII' and apply it to the 'ssn' column. Later, they need to ensure that only users with the 'PII_READER' role can see the actual values, while all other users see a masked value. They decide to use a tag-based masking policy. Which statement accurately describes how tag-based masking policies work in Snowflake?

Hard
12

A Snowflake administrator needs to grant a new analyst the ability to view all tables in the 'SALES' database and query them, but should not be able to modify any data or schema objects. Which sequence of privileges should the administrator grant to meet this requirement with least privilege?

Easy
13

Which feature in Snowflake allows you to track and audit all SQL queries executed across the entire account?

Easy
14

Refer to the exhibit. If a user with the 'ANALYST' role queries a table protected by this policy, what will they see?

Hard
15

Refer to the exhibit. What happens if a user with the 'ANALYST' role queries the 'ssn' column protected by this policy?

Hard
16

A security administrator needs to ensure that all data loaded into Snowflake is encrypted using a customer-managed key. Which feature should be configured?

Medium
17

A governance team is implementing data classification in Snowflake and wants to use tags to drive both discovery and enforcement. Which TWO capabilities are provided by Snowflake tags in this context? (Choose two.)

Medium
18

An organization wants to restrict access to Snowflake based on the source IP address of the client application. Which object should the administrator configure to enforce this network-level security?

Medium
19

A security team at a healthcare company must guarantee that query results returned from a table named PATIENT_RECORDS are filtered based on the department of the user executing the query, without requiring any changes to existing SQL statements. The policy must evaluate a mapping table that lists each user and their department. Which Snowflake object should be created to meet this requirement?

Medium
20

A company's security team wants to ensure that when a user with the role PII_ANALYST queries a table, only rows where the region column equals 'US' are returned, but they do not want to create separate copies of the table for each region. Which Snowflake feature should they implement?

Medium
21

A data administrator wants to ensure that all data access is audited. Where can they find a list of all tables accessed by a specific user?

Medium
22

An administrator needs to grant the role 'ANALYST' the ability to see all queries executed in the account for auditing purposes. Which privilege should be granted to 'ANALYST'?

Medium
23

When designing a role-based access control (RBAC) model, which THREE of the following are recommended best practices?

Medium
24

A company has a table named customer_orders that contains a column storing the customer's full name. A masking policy has been applied to that column. The policy uses CURRENT_ROLE() to compare the executing role against a list of roles allowed to see the raw value. A user with a role that is not in the allowed list runs a query that includes the column in an ORDER BY clause. What does the user see?

Hard
25

What is the primary purpose of a 'Tag' in Snowflake from a data governance perspective?

Easy
26

A user with the role 'SYSADMIN' wants to grant the privilege to create databases to a custom role 'DB_CREATOR'. Which command should the SYSADMIN execute?

Easy
27

An administrator discovers that a former employee's user account still exists and is still granted the ANALYST_ROLE. The administrator needs to immediately prevent the account from authenticating while preserving the account and its historical query metadata for an ongoing audit. Which action should the administrator take?

Medium
28

Which of the following describes the correct order of precedence for role inheritance in Snowflake?

Easy
29

Which of the following describes the purpose of 'Time Travel' from a data governance perspective?

Easy
30

A data steward needs to ensure that a column containing email addresses is masked for all users except those with the role 'COMPLIANCE_OFFICER'. The masking should show a fixed string '****' for unauthorized users. Which Snowflake feature should be used?

Hard
31

An organization requires that specific sensitive columns in a table be masked for all users except those in the 'DATA_STEWARD' role. Which mechanism should the architect implement to enforce this policy efficiently?

Medium
32

A user with the role DATA_ANALYST has been granted the USAGE privilege on a database and schema, but when they try to query a table in that schema, they receive an error that the table does not exist. The table exists and is owned by the role DATA_ENGINEER. What is the most likely cause of this issue?

Medium
33

A user with the role 'ANALYST' needs to be able to see the definition of a secure view named 'sales_view' in the 'sales_db' database. The view owner has granted SELECT on the view to ANALYST. However, when ANALYST runs SHOW VIEWS, the view definition is not visible. What is the most likely cause?

Medium
34

What is the primary function of the 'SECURITYADMIN' role in Snowflake's RBAC model?

Medium
35

What is the primary role of the 'ORGANIZATIONADMIN' role in Snowflake?

Medium
36

What is the consequence of applying a Row Access Policy to a table that already contains existing data?

Hard
37

A company wants to enforce that all data in a specific schema is protected by a data classification tag before it can be queried by analysts. The security team has created a tag named DATA_CLASS and a masking policy associated with that tag. Analysts report they can still see raw values in some columns. What is the most likely cause?

Medium
38

A governance team needs to implement data classification and access control for a new table containing sensitive data. They want to (1) tag columns with a sensitivity level, and (2) enforce that only users with a specific role can see the unmasked data. Which two Snowflake features should they use together to achieve these goals? (Choose two.)

Hard
39

A data governance lead is configuring tag-based masking so that columns tagged with a PII classification are automatically protected. The lead creates a tag named PII_CLASSIFICATION and a masking policy, then applies the tag to several columns. Later, an analyst queries a tagged column and sees unmasked values. The masking policy was attached to the tag using ALTER TAG ... SET MASKING POLICY. What is the most likely cause?

Hard
40

Which administrative role should be used to manage the lifecycle of warehouses and databases, while strictly avoiding the management of users and roles?

Medium
41

An administrator needs to restrict access to sensitive PII data. Which TWO of the following are valid approaches to implement governance in Snowflake?

Medium
42

A data steward needs to review the history of changes made to a table, including which columns were added or dropped and when, for an audit that covers the past 60 days. The table is in a database that has a data retention period of 90 days. Which Snowflake feature should the steward use to retrieve this information?

Easy
43

Refer to the exhibit. User 'jdoe' holds the 'manager' role. Which privileges does 'jdoe' possess regarding roles and data access?

Hard
44

A data engineer needs to ensure that sensitive PII columns are masked for all users except for a specific group of HR analysts. Which Snowflake feature is the most efficient and scalable solution to implement this requirement?

Medium
45

Which of the following describes the purpose of 'Object Tagging' in Snowflake?

Medium
46

An administrator wants to ensure that a specific role can only access Snowflake from the corporate office IP range. Which tool should they use?

Medium
47

A security administrator for a Snowflake account needs to grant the role FINANCE_ANALYST to a user named Priya. The administrator also wants Priya to be able to grant FINANCE_ANALYST to other users in the future. Which SQL statement should the administrator execute?

Medium

Frequently asked questions

What does the Account Management and Data Governance domain cover on the COF-C03 exam?
Be able to trace a privilege chain from role to table and explain what a policy returns to a given role. The most important thing: USAGE on a database does not expose objects; you also need USAGE on the schema and SELECT on the table.
How many questions are in this domain?
This page lists all 47 Account Management and Data Governance questions in the COF-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Account Management and Data Governance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
snowflake-core SNOWFLAKE-CORE account mgmt data governance Practice Questions