Medallia Customer Experience Certification Quality Assurance & Compliance 2 — Questions and Answers
Question 1: In Medallia, what is the primary purpose of a 'role-based access control' (RBAC) configuration within a compliance framework?
- To restrict survey distribution to specific user roles
- To ensure employees only access customer data relevant to their job function (Correct answer)
- To automate reporting schedules by department
- To encrypt outbound email invitations
Correct answer: To ensure employees only access customer data relevant to their job function
RBAC in Medallia limits data visibility so each user sees only the customer data their role requires, reducing compliance risk.
Question 2: Which Medallia feature allows administrators to define data retention periods to comply with regulations like GDPR?
- Survey throttling rules
- Data lifecycle management settings (Correct answer)
- Text analytics pipelines
- Feedback topic tagging
Correct answer: Data lifecycle management settings
Data lifecycle management in Medallia lets admins set automatic deletion or anonymization schedules to meet regulatory retention requirements.
Question 3: A QA analyst notices that a closed-loop action was marked 'resolved' without a customer follow-up call. Which Medallia workflow capability should be audited?
- Alert routing rules
- Case closure validation gates (Correct answer)
- NPS benchmark thresholds
- Embed survey triggers
Correct answer: Case closure validation gates
Case closure validation gates enforce required steps—such as a follow-up contact—before a case can be marked resolved in Medallia.
Question 4: Under PCI DSS compliance, which type of data should NEVER be captured in a Medallia open-text feedback field?
- Customer satisfaction scores
- Agent name or employee ID
- Full credit card numbers or CVV codes (Correct answer)
- Net Promoter Score responses
Correct answer: Full credit card numbers or CVV codes
PCI DSS prohibits storage of sensitive cardholder data such as full PANs or CVVs in any system not specifically scoped and secured for that purpose.
Question 5: When conducting a QA audit of Medallia survey response data, what does a high 'straight-lining' rate indicate?
- Respondents selected the same answer across all scale questions, suggesting low engagement or survey fatigue (Correct answer)
- The survey was distributed via SMS rather than email
- All responses were submitted after business hours
- The NPS question was placed at the end of the survey
Correct answer: Respondents selected the same answer across all scale questions, suggesting low engagement or survey fatigue
Straight-lining occurs when respondents select the same scale point for every question, flagging potential data quality issues that QA teams must investigate.
Question 6: Which Medallia audit log feature is most useful for demonstrating compliance during a regulatory review?
- Survey completion rates by channel
- A timestamped record of all system configuration changes and user actions (Correct answer)
- Customer verbatim export history
- Alert escalation SLA reports
Correct answer: A timestamped record of all system configuration changes and user actions
Timestamped audit logs provide regulators with an immutable record of who changed what and when, satisfying documentation requirements.
Question 7: A Medallia administrator is asked to demonstrate CCPA compliance. Which action is most directly required?
- Enabling response anonymization for all surveys
- Providing a mechanism for California consumers to request deletion of their personal data (Correct answer)
- Switching all surveys to an opt-out distribution model
- Disabling third-party integrations with CRM systems
Correct answer: Providing a mechanism for California consumers to request deletion of their personal data
CCPA grants California residents the right to request deletion of their personal data, so organizations must implement a verifiable deletion process within Medallia.
In Medallia, what is the primary purpose of a 'role-based access control' (RBAC) configuration within a compliance framework?