Special Summer Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

CSP-Assessor Customer Security Programme Assessor Certification(CSPAC) Questions and Answers

Questions 4

The internet connectivity restriction control prevents having internet access on any CSCE m-scope components.

CSP-Assessor Question 4

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 5

To rely on a previous CSP assessment report conclusions, a limited testing approach was used. What is the expected sample size as per the High-Level Test Plan (HLTP) guidelines for each identified component? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

There is no need for a sample for this limited testing

B.

1

C.

3

D.

5

Buy Now
Questions 6

Is it necessary to formally explain to the Swift user the testing methodology that will be used for the CSP assessment during the kick-off?

CSP-Assessor Question 6

Options:

A.

Yes

B.

No

Buy Now
Questions 7

Which of the following infrastructures has the smallest Swift footprint?

CSP-Assessor Question 7

Options:

A.

Full stack of products up to the Messaging Interface

B.

Alliance Remote Gateway

C.

Alliance Lite2

D.

Full stack of products includinq IPLA

Buy Now
Questions 8

The only type of HSM devices offered by Swift are HSM tokens and HSM boxes.

CSP-Assessor Question 8

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 9

What are the key elements that usually need to be considered by a cloud provider in an IaaS cloud model? (Select the two correct answers that apply)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

The cloud provider must cover all CSCF controls applicable to the related in-scope components for which the cloud provider is responsible (such as the underlying infrastructure in line with appendix G)

B.

The cloud provider must give comfort of control implementation effectiveness on the virtualization layer hosting the SWIFT users' components

C.

The cloud provider must give full assurance on the change management process of the SWIFT-users' components/applications deployed by the user

D.

The cloud provider must give comfort regarding the resiliency put in place to ensure continuity of SWIFT connectivity service

Buy Now
Questions 10

Which operator session flows are expected to be protected in terms of confidentiality and integrity? (Choose all that apply.)

CSP-Assessor Question 10

Options:

A.

System administrator sessions towards a host running a Swift related component

B.

All sessions to and from a jump server used to access a component in a secure zone

C.

All sessions towards a secure zone (on-premises or hosted by a third-party or a Cloud Provider)

D.

All sessions towards a Swift related application run by an Outsourcing Agent, a Service Bureau or an L2BA Provider

Buy Now
Questions 11

An application only uses (i) the SWIFT API for reporting and gpi basic tracker calls through (ii) a tailored account not allowing business transactions management. Is this application in scope of the CSCF? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes, it is in scope and considered a customer connector because it reads business transaction data

B.

No, it can be descoped because there is no business transaction management being performed

C.

No, it is not in scope because the API connection method is not in scope of the CSP

D.

Yes, it is in scope because the API connection method is less secure than SWIFT interfaces

Buy Now
Questions 12

A Treasury Management System (TMS) application is installed on the same machine as the customer connector (such as MQ server) connecting towards a Service Bureau Are these applications/systems in scope of CSCF?

CSP-Assessor Question 12

Options:

A.

The TMS application, the MQ server and hosting system are in the scope of the CSCF and must be placed in a secure zone

B.

The TMS application, the MQ server and hosting system enters the scope of the CSCF advisory and should be placed in a secure zone

C.

Only the MO server application is in scope of the CSCF> The TMS application is considered as back-office

D.

The TMS application is the highest risk and must be secured appropriately. The MQ server should be secured on a best effort basis

Buy Now
Questions 13

Is it mandated to perform security awareness and other specific trainings every year for individuals with SWIFT-critical roles? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.

Yes, and a track record must show that both awareness and specific training are performed annually

B.

No, both awareness and specific trainings are planned when deemed required

C.

No, awareness training expected to be performed yearly; specific training to maintain the required knowledge only when needed

D.

No, a track record must show that both awareness and specific training are performed at least bi-yearly (every 2 years)

Buy Now
Questions 14

Can an assessor re-use an ISAE 3000 report dating back 2 years to support an independent assessment?

CSP-Assessor Question 14

Options:

A.

No, that is too old, the maximum is 18 months

B.

Yes, there is no time limit for an iSAE 3000 report

C.

No, the SAE 3000 report is no validsurrogateas a rule

D.

Yes, provided there is no change to the Swift user's infrastructure

Buy Now
Questions 15

Alliance Lite2 only supports the sending and receiving of FIN messages.

CSP-Assessor Question 15

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 16

A SWIFT user is not based in the same country as the assessor. The assessor would like to perform the assessment remotely. Is this permitted? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Remote assessments are not permitted under any circumstances

B.

This is permitted provided the same level of comfort can be guaranteed

C.

It is possible to perform an assessment remotely only with valid reasons. These reasons must be formally validated by SWIFT CSP office

D.

It is not allowed to conduct an assessment remotely under any circumstances. However, force majeure circumstances like the global pandemic are an exception to this

Buy Now
Questions 17

Which authentication methods are possible on the Alliance Interfaces? (Choose all that apply.)

CSP-Assessor Question 17

Options:

A.

Password

B.

LDAP Authentication

C.

Radius One-time password

D.

Password and TOTP

Buy Now
Questions 18

The SWIFT VPN boxes are located between the Messaging and Communication interface.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 19

Must Swift users submit a copy of their final assessment report to Swift?

CSP-Assessor Question 19

Options:

A.

Yes, all documents produced from the assessment must be provided proactively to Swift

B.

No, it is not required to provide Swift with any documents by default. However, Swift can request a copy of the Assessment completion letter

C.

Yes, a copy of (only) the assessment report must be provided to Swift, no other documents

D.

Yes, in cases where a customer performs an Independent assessment rather than an audit then a copy of the assessment report must be provided. However, it is not required for the Swift user to provide any forms when an Internal/External Audit is performed

Buy Now
Questions 20

Can an internal audit department submit and approve their Swift user's attestation on the KYC-SA Swift portal?

CSP-Assessor Question 20

Options:

A.

Yes, providing this is agreed by the head of IT operations and the CISO

B.

No, this is never an option

C.

Yes, an internal auditor can submit the attestation for approval provided they have the appropriate credentials for switt.com. The CISO remains in charge of the approval of the attestation

D.

Yes, with approval from the Chief auditor

Buy Now
Questions 21

In an entity having a small infrastructure and only 2 operators, the HR manager explains in a short interview how the security training is implemented providing one example. Would it be acceptable?

CSP-Assessor Question 21

Options:

A.

Yes. it's a risk based testing approach this can be enough in this case

B.

No. more evidence are required

Buy Now
Questions 22

As a Swift CSP Certified Assessor. Swift contacted me to provide evidence on an assessment I have performed. This is required to support their quality assurance validation process. Is it allowed?

CSP-Assessor Question 22

Options:

A.

Yes, one of the obligations of the certification programme is that quality assessment can be performed by Swift

B.

No, it's confidential

Buy Now
Questions 23

Which operator session flows are expected to be protected in terms of confidentiality and integrity? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

System administrator sessions towards a host running a SWIFT-related component (on-premises or remote)

B.

All sessions to and from a jump server used to access a component in a secure zone

C.

All sessions towards a SWIFT-related application run by an Outsourcing Agent, a Service Bureau, or an L2BA Provider

D.

All of the other answers are valid

Buy Now
Questions 24

May an assessor rely on an ISAE 3000 report dating back 2 years to support a CSP independent assessment? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

No, that is too old, the maximum is 18 months

B.

Yes, there is no time limit for an ISAE 3000 report

C.

No, an ISAE 3000 report is no valid substitute as a rule

D.

Yes, provided there is no change to the SWIFT user’s infrastructure

Buy Now
Questions 25

Using the outsourcing agent diagram, which components (including the components in SWIFT user premises) must be placed in a secure zone? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

•Next Service Provider(s)

•SWIFT User

•Outsourcing Agent(s)

•Connector*

•SWIFT

•SWIFT network

Options:

A.

Components A, B, and C

B.

All components

C.

Components A, C, D, and E

D.

Components A, C, and D

Buy Now
Questions 26

Which statement(s) is/are correct about the LSO/RSO accounts on a Swift Alliance Access? (Choose all that apply.)

CSP-Assessor Question 26

Options:

A.

They are local Security Officers

B.

Their PKI certificates are stored either on a HSM Token or on a HSM-box

C.

They are the business profiles that can sign the Swift financial transactions

D.

They are responsible for the configuration and management of the security functions of the server

Buy Now
Questions 27

A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server What architecture type is the Swift user? (Choose all that apply.)

CSP-Assessor Question 27

Options:

A.

A1

B.

B

C.

A3

D.

A4

Buy Now
Questions 28

Who can connect to SWIFT? (Select all answers that apply)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

Financial institutions, such as banks and securities broker-dealers

B.

Individuals who use online banking for international transfers

C.

Market infrastructures that provide financial institutions with centralized transaction processing

D.

Corporates that work with multiple banking partners

Buy Now
Questions 29

Must all CSCF controls be subject to an assessment? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes

B.

No, only the mandatory controls

C.

No, only the attested controls (with as a minimum the mandatory ones according to the architecture type)

D.

No, the controls selection is agreed upfront between the SWIFT User and the assessor

Buy Now
Questions 30

Select the correct statement about SWIFT Alliance Cloud.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

Alliance Cloud is a SWIFT cloud-based solution. It provides a universal channel to the financial community and to SWIFT Value Added services and initiatives

B.

Alliance Cloud is a cloud-based solution. It is offered by the 3 official public cloud providers. This allows customers the choice to select their preferred cloud provider

C.

Alliance Cloud is a cloud-based solution. It is offered by any public cloud provider that subscribed to the digital connectivity initiative

D.

Alliance Cloud is a SWIFT cloud-based solution. It consists of an Alliance Access instance deployed at one of the three SWIFT-approved public cloud providers

Buy Now
Questions 31

A Swift user has moved from one Service Bureau to another What are the obligations of the Swift user in the CSP context?

CSP-Assessor Question 31

Options:

A.

To inform the SB certification office at Swift WW

B.

To reflect that in the next attestation cycle

C.

None if there is no impact in the architecture tope

D.

To submit an updated attestation reflecting this change within 3 months

Buy Now
Questions 32

Select the supporting documents to conduct a CSP assessment. (Choose all that apply.)

CSP-Assessor Question 32

Options:

A.

The CSP User Handbook

B.

The mapping to industry standards article

C.

The Controls Matrix and High Level Test P an

D.

The Customer Security Controls Framework

Buy Now
Questions 33

Select the components a SwiftNet Link (SNL) may communicate with. (Choose all that apply.)

CSP-Assessor Question 33

Options:

A.

The Graphical User Interface

B.

The VPN boxes

C.

The HSM device

D.

The messaging interface (such as Alliance Access)

Buy Now
Questions 34

Where is the implementation of multi-factor authentication deemed sufficient to support control 4.2 compliance? (Choose all that apply.)

CSP-Assessor Question 34

Options:

A.

When accessing an outsourcing agent or an L2BA Swift-related application

B.

When logging-in on an interface, a connector, or the system running such component

C.

When login on the jump server filtering access to local Swift secure zone

D.

On the General Operator PC used to access a Swift-related component

Buy Now
Exam Code: CSP-Assessor
Exam Name: Customer Security Programme Assessor Certification(CSPAC)
Last Update: Mar 28, 2025
Questions: 116

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now CSP-Assessor testing engine

PDF (Q&A)

$31.5  $104.99
buy now CSP-Assessor pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 02 Apr 2025