Courseiva

COF-C03 Account Management and Data Governance Practice Question

Which object type in Snowflake is required to store a compiled masking policy before it can be applied to a table column?

⚠ Common exam trap

Candidates often confuse the masking policy object with the table column itself. They assume applying the policy creates the object, rather than realizing the policy must exist independently beforehand.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A masking policy object.

In Snowflake, masking policies are independent, schema-level objects. Before a policy can be enforced on a column, it must be created using the 'CREATE MASKING POLICY' command. This object encapsulates the logic for transformation and the conditional access rules. Once defined, the policy is then mapped to one or more columns via an 'ALTER TABLE' statement or during table creation, providing a modular approach to data governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A stored procedure.

    Why it's wrong here

    Stored procedures are used for executing procedural SQL code to automate tasks or perform complex transformations. They are not the container object for masking policy logic, which requires specific declarative syntax that Snowflake's policy engine parses to apply masks during query compilation and execution time.

  • ✓

    A masking policy object.

    Why this is correct

    A masking policy is a first-class schema object in Snowflake. It defines the logic that determines whether data is returned as-is or masked based on the user's role. Once created, it remains dormant until explicitly assigned to a column, allowing for reusable security definitions across multiple tables.

  • ✗

    A data masking role.

    Why it's wrong here

    Roles in Snowflake are used for access control (RBAC), defining what actions a user can perform on objects. There is no such object type as a 'data masking role.' While roles are used to evaluate policy conditions, they do not store the logic for how data is masked.

  • ✗

    A secure function.

    Why it's wrong here

    While masking policies use SQL functions internally to transform data, the policy itself is a distinct object type. A secure function is a user-defined function (UDF) that has been marked as secure to prevent information leakage, but it cannot be directly applied to a column to enforce masking.

About these practice questions

One of 280 original COF-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Snowflake exam blueprint

This COF-C03 practice question is part of Courseiva's free Snowflake certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the COF-C03 exam.