Security & Compliance Flashcards
6 cards from real Call Center Hosting practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security & Compliance flashcards as text
What does SOC 2 compliance indicate about a CCaaS vendor?
Answer: The vendor has been audited for security, availability, processing integrity, confidentiality, and/or privacy controls
SOC 2 is an auditing framework that validates a service provider's controls around security, availability, and data handling.
What is 'multi-factor authentication' (MFA) and why is it important for call center agent logins?
Answer: Requiring two or more verification methods to log in, preventing unauthorized access even if a password is stolen
MFA requires agents to verify identity through a second factor (like a mobile code) in addition to a password, significantly reducing unauthorized access risk.
What is the principle of 'least privilege' in call center system access management?
Answer: Granting users only the minimum access rights needed to perform their job functions
Least privilege limits each user's access to only what's necessary for their role, minimizing the impact of insider threats or compromised accounts.
Under TCPA regulations, what must outbound call centers obtain before calling consumers using an ATDS?
Answer: Prior express written consent from the consumer
The TCPA requires prior express written consent before placing calls using an Automated Telephone Dialing System (ATDS) to cell phones.
What is the purpose of call center 'audit logs'?
Answer: Maintaining a tamper-evident record of system access and user actions for compliance and forensics
Audit logs record who did what and when in the system, providing an evidence trail for compliance audits, investigations, and security reviews.
What is 'network segmentation' in the context of call center security?
Answer: Isolating different parts of the network to contain breaches and limit access between systems
Network segmentation divides the infrastructure into isolated zones so a breach in one segment cannot easily spread to others.