Courseiva

COF-C03 · topic practice

Account Management and Data Governance practice questions

This domain covers Snowflake roles, privileges, and data protection features. Questions present exhibits showing role hierarchies, masking or row access policies, and access failures, then ask you to diagnose why a user sees or cannot see data. You must know how USAGE, SELECT, and schema-level grants interact, plus where access history and Time Travel fit into governance.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Account Management and Data Governance

What the exam tests

What to know about Account Management and Data Governance

Be able to trace a privilege chain from role to table and explain what a policy returns to a given role. The most important thing: USAGE on a database does not expose objects; you also need USAGE on the schema and SELECT on the table.

Diagnosing missing SELECT or schema USAGE grants in a role hierarchy

Reading masking policies and row access policies in query results

Using ACCESS_HISTORY and ACCOUNT_USAGE views to audit table access

Applying Time Travel and Fail-safe concepts for data recovery and retention

Watch out for

Common Account Management and Data Governance exam traps

  • ▸Assuming database USAGE alone grants table visibility; schema and table SELECT privileges are also required.
  • ▸Confusing masking policy output with row filtering; masked values appear, rows are not removed.
  • ▸Treating Time Travel as permanent archival storage rather than a bounded retention window.

Practice set

Account Management and Data Governance questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following statements are true regarding the ACCOUNTADMIN role?

Which THREE of the following are valid methods for ensuring data is encrypted during transit between the client and Snowflake?

A company requires all users to authenticate using MFA. Where is this requirement enforced within Snowflake?

Which THREE actions are permitted for the PUBLIC role?

Which of the following correctly describes the relationship between the SYSADMIN and SECURITYADMIN roles?

Which Snowflake feature allows an administrator to track and audit all SQL queries executed against the account over a long period?

A security analyst needs to determine which users have accessed a specific table in the last month. Which approach is most efficient and reliable?

Which Snowflake concept ensures that data remains available and consistent even if an entire availability zone (AZ) goes offline?

If an organization wants to ensure that specific columns in a table can only be queried by users with a 'FINANCE' tag, what is the best approach?

Which TWO of the following are true regarding the behavior of 'Secure Views' in Snowflake?

An organization wants to restrict access to data based on the user's geographic location. Which combination of features should be used?

Which object type in Snowflake is best suited for centralizing the management of security policies and monitoring access across the entire account?

Which TWO of the following statements regarding the 'ACCOUNTADMIN' role are correct?

Which THREE of the following are valid methods for managing user authentication in Snowflake?

What is the consequence of dropping a database that contains objects with masking policies applied?

A Snowflake administrator wants to enforce that only users with the role PAYROLL_ADMIN can view unmasked values in the SALARY column of the HR.EMPLOYEES table, while all other users see a fixed value. The administrator creates a masking policy and applies it to the SALARY column. Which statement accurately describes how the masking policy must be written to meet this requirement?

A security administrator wants to enforce that all new tables created in the database 'SENSITIVE_DB' must have a tag 'DATA_CLASSIFICATION' applied with a value of 'CONFIDENTIAL'. Existing tables should not be affected. Which Snowflake feature should be used to achieve this?

A Snowflake administrator needs to grant the privilege to create and manage users and roles to a new security team member. Which role should be granted to this user to provide the necessary privileges while following the principle of least privilege?

A company wants to implement data governance using Snowflake tags. Which two statements are true regarding tag-based masking policies? (Choose two.)

A security administrator wants to allow a group of users to query only the columns in the CUSTOMERS table that contain non-sensitive data, while preventing them from seeing the SSN and CREDIT_CARD columns. The users still need to be able to run SELECT * queries. Which Snowflake feature should be used?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Account Management and Data Governance sessions

Start a Account Management and Data Governance only practice session

Every question in these sessions is drawn from the Account Management and Data Governance domain — nothing else.

Related practice questions

Related COF-C03 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the COF-C03 exam test about Account Management and Data Governance?
Be able to trace a privilege chain from role to table and explain what a policy returns to a given role. The most important thing: USAGE on a database does not expose objects; you also need USAGE on the schema and SELECT on the table.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Account Management and Data Governance questions in a focused session?
Yes — the session launcher on this page draws every question from the Account Management and Data Governance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other COF-C03 topics?
Use the topic links above to move to related areas, or go back to the COF-C03 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the COF-C03 exam covers. They are not copied from any real exam or dump site.