COF-C03 · domain
Account Management and Data Governance
This domain covers Snowflake roles, privileges, and data protection features. Questions present exhibits showing role hierarchies, masking or row access policies, and access failures, then ask you to diagnose why a user sees or cannot see data. You must know how USAGE, SELECT, and schema-level grants interact, plus where access history and Time Travel fit into governance.
Focused practice
Practice Account Management and Data Governance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Account Management and Data Governance
Be able to trace a privilege chain from role to table and explain what a policy returns to a given role. The most important thing: USAGE on a database does not expose objects; you also need USAGE on the schema and SELECT on the table.
Diagnosing missing SELECT or schema USAGE grants in a role hierarchy
Reading masking policies and row access policies in query results
Using ACCESS_HISTORY and ACCOUNT_USAGE views to audit table access
Applying Time Travel and Fail-safe concepts for data recovery and retention
Watch out for
Common Account Management and Data Governance exam traps
- ▸Assuming database USAGE alone grants table visibility; schema and table SELECT privileges are also required.
- ▸Confusing masking policy output with row filtering; masked values appear, rows are not removed.
- ▸Treating Time Travel as permanent archival storage rather than a bounded retention window.
Question index
All Account Management and Data Governance questions (47)
Click any question to see the full explanation, or start a practice session above.
A Snowflake account has a custom role named DATA_ENGINEER. The administrator wants to ensure that DATA_ENGINEER can create databases and warehouses but cannot manage users or roles. Which predefined role should DATA_ENGINEER be granted to achieve this?
Medium2A compliance officer needs to confirm which roles have been granted to a specific user across the account, including grants made through role hierarchies. Which Snowflake command should be used to retrieve this information?
Easy3A user is assigned the 'SECURITYADMIN' role. Which of the following tasks can this user perform?
Hard4A governance team is designing a strategy to classify and protect data across many databases in a Snowflake account. They want a scalable approach that applies protection consistently without editing each table definition manually. Which two capabilities should the team use to accomplish this goal? (Choose two.)
Hard5A company requires all data at rest within Snowflake to be encrypted using a customer-provided key. Which feature should they implement?
Medium6Which object type in Snowflake is required to store a compiled masking policy before it can be applied to a table column?
Easy7A data administrator needs to identify which users have failed to log in successfully over the last 30 days due to authentication errors. Which Snowflake object should they query?
Medium8A security administrator has created a masking policy that replaces the value of a column with a SHA2 hash for users without the role 'HR_ROLE'. The policy is applied to the 'SSN' column of the 'EMPLOYEES' table. A user with the role 'ANALYST_ROLE' queries the table and sees the hashed values. However, when the same user runs a query that includes the 'SSN' column in a WHERE clause, the query returns no results even though matching records exist. What is the most likely cause of this behavior?
Hard9A security administrator needs to ensure that a set of sensitive columns in an existing table are automatically masked for all users except those with the role 'HR_ADMIN'. The masking must be applied without modifying the underlying data. Which Snowflake feature should be used?
Medium10Refer to the exhibit. A user with the role 'ANALYST_ROLE' cannot see tables inside the 'sales_db.public' schema despite having 'USAGE' on the database. What is the most likely reason for this access issue?
Hard11A data governance team wants to classify data in a table using tags. They create a tag 'PII' and apply it to the 'ssn' column. Later, they need to ensure that only users with the 'PII_READER' role can see the actual values, while all other users see a masked value. They decide to use a tag-based masking policy. Which statement accurately describes how tag-based masking policies work in Snowflake?
Hard12A Snowflake administrator needs to grant a new analyst the ability to view all tables in the 'SALES' database and query them, but should not be able to modify any data or schema objects. Which sequence of privileges should the administrator grant to meet this requirement with least privilege?
Easy13Which feature in Snowflake allows you to track and audit all SQL queries executed across the entire account?
Easy14Refer to the exhibit. If a user with the 'ANALYST' role queries a table protected by this policy, what will they see?
Hard15Refer to the exhibit. What happens if a user with the 'ANALYST' role queries the 'ssn' column protected by this policy?
Hard16A security administrator needs to ensure that all data loaded into Snowflake is encrypted using a customer-managed key. Which feature should be configured?
Medium17A governance team is implementing data classification in Snowflake and wants to use tags to drive both discovery and enforcement. Which TWO capabilities are provided by Snowflake tags in this context? (Choose two.)
Medium18An organization wants to restrict access to Snowflake based on the source IP address of the client application. Which object should the administrator configure to enforce this network-level security?
Medium19A security team at a healthcare company must guarantee that query results returned from a table named PATIENT_RECORDS are filtered based on the department of the user executing the query, without requiring any changes to existing SQL statements. The policy must evaluate a mapping table that lists each user and their department. Which Snowflake object should be created to meet this requirement?
Medium20A company's security team wants to ensure that when a user with the role PII_ANALYST queries a table, only rows where the region column equals 'US' are returned, but they do not want to create separate copies of the table for each region. Which Snowflake feature should they implement?
Medium21A data administrator wants to ensure that all data access is audited. Where can they find a list of all tables accessed by a specific user?
Medium22An administrator needs to grant the role 'ANALYST' the ability to see all queries executed in the account for auditing purposes. Which privilege should be granted to 'ANALYST'?
Medium23When designing a role-based access control (RBAC) model, which THREE of the following are recommended best practices?
Medium24A company has a table named customer_orders that contains a column storing the customer's full name. A masking policy has been applied to that column. The policy uses CURRENT_ROLE() to compare the executing role against a list of roles allowed to see the raw value. A user with a role that is not in the allowed list runs a query that includes the column in an ORDER BY clause. What does the user see?
Hard25What is the primary purpose of a 'Tag' in Snowflake from a data governance perspective?
Easy26A user with the role 'SYSADMIN' wants to grant the privilege to create databases to a custom role 'DB_CREATOR'. Which command should the SYSADMIN execute?
Easy27An administrator discovers that a former employee's user account still exists and is still granted the ANALYST_ROLE. The administrator needs to immediately prevent the account from authenticating while preserving the account and its historical query metadata for an ongoing audit. Which action should the administrator take?
Medium28Which of the following describes the correct order of precedence for role inheritance in Snowflake?
Easy29Which of the following describes the purpose of 'Time Travel' from a data governance perspective?
Easy30A data steward needs to ensure that a column containing email addresses is masked for all users except those with the role 'COMPLIANCE_OFFICER'. The masking should show a fixed string '****' for unauthorized users. Which Snowflake feature should be used?
Hard31An organization requires that specific sensitive columns in a table be masked for all users except those in the 'DATA_STEWARD' role. Which mechanism should the architect implement to enforce this policy efficiently?
Medium32A user with the role DATA_ANALYST has been granted the USAGE privilege on a database and schema, but when they try to query a table in that schema, they receive an error that the table does not exist. The table exists and is owned by the role DATA_ENGINEER. What is the most likely cause of this issue?
Medium33A user with the role 'ANALYST' needs to be able to see the definition of a secure view named 'sales_view' in the 'sales_db' database. The view owner has granted SELECT on the view to ANALYST. However, when ANALYST runs SHOW VIEWS, the view definition is not visible. What is the most likely cause?
Medium34What is the primary function of the 'SECURITYADMIN' role in Snowflake's RBAC model?
Medium35What is the primary role of the 'ORGANIZATIONADMIN' role in Snowflake?
Medium36What is the consequence of applying a Row Access Policy to a table that already contains existing data?
Hard37A company wants to enforce that all data in a specific schema is protected by a data classification tag before it can be queried by analysts. The security team has created a tag named DATA_CLASS and a masking policy associated with that tag. Analysts report they can still see raw values in some columns. What is the most likely cause?
Medium38A governance team needs to implement data classification and access control for a new table containing sensitive data. They want to (1) tag columns with a sensitivity level, and (2) enforce that only users with a specific role can see the unmasked data. Which two Snowflake features should they use together to achieve these goals? (Choose two.)
Hard39A data governance lead is configuring tag-based masking so that columns tagged with a PII classification are automatically protected. The lead creates a tag named PII_CLASSIFICATION and a masking policy, then applies the tag to several columns. Later, an analyst queries a tagged column and sees unmasked values. The masking policy was attached to the tag using ALTER TAG ... SET MASKING POLICY. What is the most likely cause?
Hard40Which administrative role should be used to manage the lifecycle of warehouses and databases, while strictly avoiding the management of users and roles?
Medium41An administrator needs to restrict access to sensitive PII data. Which TWO of the following are valid approaches to implement governance in Snowflake?
Medium42A data steward needs to review the history of changes made to a table, including which columns were added or dropped and when, for an audit that covers the past 60 days. The table is in a database that has a data retention period of 90 days. Which Snowflake feature should the steward use to retrieve this information?
Easy43Refer to the exhibit. User 'jdoe' holds the 'manager' role. Which privileges does 'jdoe' possess regarding roles and data access?
Hard44A data engineer needs to ensure that sensitive PII columns are masked for all users except for a specific group of HR analysts. Which Snowflake feature is the most efficient and scalable solution to implement this requirement?
Medium45Which of the following describes the purpose of 'Object Tagging' in Snowflake?
Medium46An administrator wants to ensure that a specific role can only access Snowflake from the corporate office IP range. Which tool should they use?
Medium47A security administrator for a Snowflake account needs to grant the role FINANCE_ANALYST to a user named Priya. The administrator also wants Priya to be able to grant FINANCE_ANALYST to other users in the future. Which SQL statement should the administrator execute?
MediumOther domains
All COF-C03 exam domains
Frequently asked questions
- What does the Account Management and Data Governance domain cover on the COF-C03 exam?
- Be able to trace a privilege chain from role to table and explain what a policy returns to a given role. The most important thing: USAGE on a database does not expose objects; you also need USAGE on the schema and SELECT on the table.
- How many questions are in this domain?
- This page lists all 47 Account Management and Data Governance questions in the COF-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Account Management and Data Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.