Quality Assurance & Compliance Flashcards
7 cards from real Medallia Customer Experience Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Quality Assurance & Compliance flashcards as text
Which Medallia capability allows quality managers to flag specific agent interactions for calibration review based on predefined compliance criteria?
Answer: Rules-based case flagging and scoring workflows
Rules-based flagging in Medallia automatically identifies interactions meeting compliance criteria (e.g., regulatory keywords, low scores) and routes them for calibration review.
A Medallia QA team discovers that 15% of email survey invitations bounced due to invalid addresses. What is the primary data quality implication?
Answer: The CRM contact data feeding Medallia may be stale or inaccurate, requiring a data cleansing process
High bounce rates point to outdated or incorrect contact data in the source CRM, signaling a need for a data hygiene review before the next distribution cycle.
Under SOC 2 Type II compliance, which Medallia platform requirement is most directly relevant to the Security trust service criterion?
Answer: Implementing multi-factor authentication (MFA) for all Medallia administrator accounts
SOC 2 Security criteria require strong access controls including MFA for administrative accounts to prevent unauthorized system access.
In Medallia, what distinguishes a 'system-generated alert' from a 'manual case' in the context of closed-loop QA?
Answer: System-generated alerts are created automatically based on score thresholds or rule triggers, while manual cases are created by a human reviewer after reading a response
System-generated alerts fire automatically when feedback meets predefined rules, whereas manual cases are initiated by a human who identifies an issue requiring follow-up.
A Medallia QA analyst is reviewing a batch of survey responses and notices an unusually high proportion of 10/10 scores submitted within a two-minute window. What should be the first investigative step?
Answer: Investigate whether the responses were submitted by a bot or if an employee coached customers to give top scores
A suspicious cluster of perfect scores in a very short window is a red flag for bot activity or score manipulation, both of which are data integrity and compliance violations.
Which Medallia data governance practice ensures that a deleted customer record is also removed from all associated feedback and reporting tables?
Answer: Cross-system data reconciliation triggered by a deletion event (right-to-erasure workflow)
A right-to-erasure workflow propagates a deletion event across all linked tables—responses, alerts, cases—ensuring complete removal of the individual's data.
What is the compliance risk of allowing Medallia survey results to be exported to unmanaged personal devices (e.g., personal laptops) without DLP controls?
Answer: Customer PII in exported reports could be exposed or mishandled outside of the organization's security perimeter
Exporting reports containing PII to unmanaged devices bypasses organizational data loss prevention controls and creates regulatory exposure under GDPR, CCPA, and similar laws.