Quality Assurance & Compliance Flashcards
7 cards from real Medallia Customer Experience Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Quality Assurance & Compliance flashcards as text
In Medallia, what is the primary purpose of a 'role-based access control' (RBAC) configuration within a compliance framework?
Answer: To ensure employees only access customer data relevant to their job function
RBAC in Medallia limits data visibility so each user sees only the customer data their role requires, reducing compliance risk.
Which Medallia feature allows administrators to define data retention periods to comply with regulations like GDPR?
Answer: Data lifecycle management settings
Data lifecycle management in Medallia lets admins set automatic deletion or anonymization schedules to meet regulatory retention requirements.
A QA analyst notices that a closed-loop action was marked 'resolved' without a customer follow-up call. Which Medallia workflow capability should be audited?
Answer: Case closure validation gates
Case closure validation gates enforce required steps—such as a follow-up contact—before a case can be marked resolved in Medallia.
Under PCI DSS compliance, which type of data should NEVER be captured in a Medallia open-text feedback field?
Answer: Full credit card numbers or CVV codes
PCI DSS prohibits storage of sensitive cardholder data such as full PANs or CVVs in any system not specifically scoped and secured for that purpose.
When conducting a QA audit of Medallia survey response data, what does a high 'straight-lining' rate indicate?
Answer: Respondents selected the same answer across all scale questions, suggesting low engagement or survey fatigue
Straight-lining occurs when respondents select the same scale point for every question, flagging potential data quality issues that QA teams must investigate.
Which Medallia audit log feature is most useful for demonstrating compliance during a regulatory review?
Answer: A timestamped record of all system configuration changes and user actions
Timestamped audit logs provide regulators with an immutable record of who changed what and when, satisfying documentation requirements.
A Medallia administrator is asked to demonstrate CCPA compliance. Which action is most directly required?
Answer: Providing a mechanism for California consumers to request deletion of their personal data
CCPA grants California residents the right to request deletion of their personal data, so organizations must implement a verifiable deletion process within Medallia.