QuestionQ93

Implement Data Protection and Recovery

A Data Engineer must create a tag-based masking policy that determines whether data is masked according to the label-string value assigned to the salary column in the staff table. The Engineer created the tag and masking policy using these commands:

USE SCHEMA governance.tags;  
CREATE TAG hr_col_salary;  
  
USE ROLE masking_admin;  
USE SCHEMA governance.masking_policies;  
CREATE MASKING POLICY salary_mask_tag_policy  
AS (val number) RETURNS number ->  
  
CASE -  
WHEN SYSTEM$GET_TAG_ON_CURRENT_COLUMN('tags.hr_col_salary') = 'visible' or 'payroll_admin' = current_role() THEN val  
  
ELSE -1 -  
END;  
  
ALTER TAG hr_col_salary SET -  
MASKING POLICY salary_mask_tag_policy;  

How should the Engineer apply the tag to ensure that only users with the payroll_admin role can access the data?

Explanation

A tag-based masking policy is automatically enforced when its tag is assigned to a column whose data type matches the policy signature. This policy exposes the original value when the tag value is visible or when the current role is payroll_admin. Assigning hr_col_salary with the value masked makes the visible condition false, leaving payroll_admin as the only role that receives the unmasked salary; other roles receive -1.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!