問題文
A company wants to protect a column so that the values are useless inside Snowflake but can still be reversed by an authorized system outside it. Which approach matches that requirement?
選択肢
- A row access policy that removes the rows containing sensitive values, where removing the row also removes the value from the view.
- External tokenization, which stores a surrogate in the column and calls out to an external service to reverse it for roles that are allowed to see the original.
- A masking policy that returns a fixed placeholder, which cannot be reversed and which satisfies an even stricter requirement than masking.
- Client-side encryption before loading, with the column then holding ciphertext that no role inside Snowflake has the key for.