CRM Security and Compliance Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CRM Security and Compliance flashcards as text
Which access control model in CRM systems grants permissions based on a user's job function within the organization?
Answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns permissions based on organizational roles, ensuring users can only access data relevant to their job function.
Under GDPR, how long can a CRM store personally identifiable information (PII) about EU citizens?
Answer: Only for the duration necessary for the specified purpose
GDPR's data minimization and storage limitation principles require that PII is kept only as long as necessary for the original purpose of collection.
What CRM feature allows administrators to prevent users from exporting or printing sensitive customer records?
Answer: Data Loss Prevention (DLP) policies
Data Loss Prevention (DLP) policies restrict actions such as exporting, printing, or sharing sensitive records outside approved channels.
Which encryption standard is most commonly recommended for protecting data at rest in enterprise CRM databases?
Answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the industry standard for encrypting data at rest due to its strength and widespread regulatory acceptance.
In Salesforce CRM, which feature restricts which IP addresses can access an organization's instance?
Answer: Network Access (Trusted IP Ranges)
Salesforce's Network Access (Trusted IP Ranges) setting allows admins to whitelist specific IP ranges, blocking login attempts from unauthorized networks.
What is a 'consent record' in the context of CRM compliance?
Answer: Documentation proving a contact agreed to receive communications or have their data processed
A consent record documents that a contact explicitly agreed to data processing or marketing communications, which is required by regulations like GDPR and CCPA.
Which of the following best describes 'field-level security' in a CRM system?
Answer: Controlling which users or profiles can view or edit specific fields on a record
Field-level security restricts visibility and editability of individual fields based on the user's profile or role, enabling granular data access control.