โ† All CRM Flashcard Decks

CRM Security and Compliance Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CRM Security and Compliance flashcards as text
  1. What is the primary purpose of an audit trail in a CRM system?

    Answer: To track and record all changes made to records for accountability and compliance

    An audit trail logs who made changes, what was changed, and when, providing an accountability record required by many compliance frameworks.

  2. The California Consumer Privacy Act (CCPA) grants consumers which of the following rights regarding their data held in a CRM?

    Answer: The right to know, delete, and opt-out of the sale of their personal information

    CCPA provides California consumers with rights to know what data is collected, request deletion, and opt-out of the sale of their personal information.

  3. Which authentication method adds a second verification step beyond a password when logging into a CRM?

    Answer: Multi-Factor Authentication (MFA)

    Multi-Factor Authentication (MFA) requires users to verify their identity with a second factor (e.g., SMS code or authenticator app) in addition to their password.

  4. In the context of CRM data compliance, what does 'data residency' refer to?

    Answer: The physical or geographic location where customer data is stored

    Data residency specifies the country or region where customer data must physically reside, often mandated by local privacy laws and regulations.

  5. What CRM security practice involves replacing sensitive data with a non-sensitive placeholder that retains format but has no exploitable value?

    Answer: Tokenization

    Tokenization replaces sensitive data (e.g., credit card numbers) with a random token, so the original data is never stored in the CRM but can be referenced via the token.

  6. Under HIPAA, which type of CRM data requires the highest level of protection?

    Answer: Protected Health Information (PHI)

    HIPAA specifically governs Protected Health Information (PHI), which includes any data that can identify a patient and relates to their health status or care.

  7. What is the role of a Data Processing Agreement (DPA) between a business and its CRM vendor?

    Answer: It defines how the vendor handles personal data on behalf of the business in compliance with privacy laws

    A DPA is a legally binding contract required by GDPR and similar laws that specifies the vendor's data processing obligations and security responsibilities.

CRM Security and Compliance Flashcards โ€” CRM Study Cards with Answers