QuestionQ128

Secure Data Sharing and Consumption

Consider the following scenario in which a masking policy is applied to the CREDICARDNO column of the CREDITCARDINFO table.

The masking policy is defined as follows:

Question Image

Sample data for the creditcardinfo table is as follows:

| NAME | EXPIRYDATE | CREDITCARDNO |

| --- | --- | --- |

| JOHN DOE | 2022-07-23 | 4321 5678 9012 1234 |

If the Snowflake system roles have not received any additional role grants, what will be the result?

Explanation

IS_ROLE_IN_SESSION('PI_ANALYTICS') returns true when the active primary or secondary role in the session inherits the PI_ANALYTICS role. For such sessions, RIGHT(val, 4) exposes the final four characters of the credit-card value; otherwise, the policy returns ***MASKED***. System-role status or table ownership alone does not override this policy condition. Snowflake: IS_ROLE_IN_SESSION

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!