Exam DEA-C02 Topic 1 Question 170 Discussion
Actual exam question for Snowflake's DEA-C02 exam
Question #: 170
Topic #: 1
Question #: 170
Topic #: 1
You need to implement both a row access policy and a dynamic data masking policy on the 'EMPLOYEE table in Snowflake. The requirements are as follows: 1. Employees should only be able to see their own record in the 'EMPLOYEE table. 2. The 'SALARY' column should be masked for all employees except those with the 'HR ADMIN' role. Unmasked values are required for compliance reasons, they need to be available for 'HR ADMIN' role. Given the following table structure: CREATE TABLE EMPLOYEE ( EMPLOYEE ID INT, EMPLOYEE NAME STRING, SALARY NUMBER, EMAIL STRING ) ; Which of the following sets of steps correctly implement the row access policy and dynamic data masking policy?


Suggested Answer: B Vote an answer
Option B implements both policies correctly. The row access policy correctly checks if the 'EMPLOYEE ID matches the 'CURRENT_USER()'. Although the use of is not correct in this situation, it is being used with 'employee_id' so can only see his own record in the 'EMPLOYEE table. The masking policy uses 'CURRENT correctly to check if the role in the session is 'HR_ADMIN'. If it is, the original salary value is returned; otherwise, it masks it to Other masking policy options will return a string representation ("MASKED") or return a hash of the value, which is not a valid 'NUMBER. Option A uses IS ROLE IN SESSION rather than CURRENT_ROLE. 'CURRENT_ROLE only returns the primary role used to initialize the session whereas will return TRUE if the role is the primary role or any of the active secondary roles in the current session.
by Evan at Sep 27, 2026, 10:49 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).