CRM Security and Compliance Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CRM Security and Compliance flashcards as text
Which CRM security feature automatically logs a user out after a defined period of inactivity?
Answer: Session Timeout
Session Timeout automatically ends an idle user session after a set period, reducing the risk of unauthorized access to an unattended workstation.
A CRM administrator wants to ensure that users in the sales team cannot see each other's private accounts. Which sharing model setting achieves this?
Answer: Private (with role hierarchy)
Setting the sharing model to Private means users can only see records they own, while role hierarchy allows managers above them to see their records.
What is a 'sandbox environment' used for in CRM security and compliance testing?
Answer: A production copy used for testing changes without affecting live customer data
A sandbox is an isolated replica of the production CRM environment used to safely test configurations, integrations, or compliance workflows before deploying them live.
Which SOC report type provides the most relevant security assurance for a CRM vendor serving multiple customers with different needs?
Answer: SOC 2 Type II
SOC 2 Type II evaluates a CRM vendor's controls related to security, availability, and confidentiality over a period of time, making it the most relevant for SaaS CRM vendors.
When a customer submits a 'right to erasure' (right to be forgotten) request under GDPR, what must the CRM process include?
Answer: Deleting all personal data from active systems, backups, and connected integrations within the required timeframe
GDPR's right to erasure requires organizations to delete all personal data from their systems, including backups and integrated platforms, within 30 days of a valid request.
Which CRM integration protocol is most commonly used to implement Single Sign-On (SSO) with enterprise identity providers like Azure AD?
Answer: SAML 2.0
SAML 2.0 (Security Assertion Markup Language) is the industry-standard protocol used to implement SSO between CRM platforms and enterprise identity providers like Azure AD or Okta.
What is the primary goal of a CRM penetration test?
Answer: To identify security vulnerabilities by simulating attacks before malicious actors exploit them
A penetration test (pen test) proactively simulates real-world attacks on the CRM to discover security weaknesses before they can be exploited by malicious actors.