Halloween Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

CSP-Assessor Swift Customer Security Programme Assessor Certification(CSPAC) Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Swift CSP-Assessor Customer Security Programme Assessor Certification(CSPAC) certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 116 questions

Is the control 2. 11 "RMA Business Controls” only about the process of validating the defined counterparty relationships?

A.

Yes

B.

No

For which reasons (as per the "CSP Independent Assessment Process for Assessors Guidelines") is it required to keep minutes of all key meetings related to a CSP assessment process (examples: kick-off, scope definition, exit meeting)? (Select all answers that apply)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

A.

To support quality review (audit) processes

B.

For documentation purpose

C.

To keep key information that can be used as input for the next step in the assessment process

D.

To be uploaded in KYC-SA at the end of the assessment (mandated by SWIFT)

In the illustration, identify the component type of each of the numbered components.

A.

1. Customer Connector

2. Bridging Server (Middleware Server)

3. Customer Connector

4. Bridging Server (Middleware Server)

B.

1. Customer Connector

2. Bridging Server (Middleware Server)

3. Customer Connector

4. Customer Connector

C.

1. Bridging Server (Middleware Server)

2. Bridging Server (Middleware Server)

3. Bridging Server (Middleware Server)

4. Bridging Server (Middleware Server)

D.

1. Customer Connector

2. Customer Connector

3. Customer Connector

4. Customer Connector

Which authentication methods are possible on the Alliance Interfaces? (Choose all that apply.)

A.

Password

B.

LDAP Authentication

C.

Radius One-time password

D.

Password and TOTP

A Swift user relies on a sFTP server to connect through an externally exposed connection with a service provider or a group hub What architecture type is the Swift user? (Choose all that apply.)

A.

A1

B.

A2

C.

A3

D.

A4

What does the CSCF expect in terms of Database Integrity? (Choose all that apply.)

A.

Nothing is needed when the messaging or connector integrates/embeds an integrity check functionality at each Swift transaction record level.

B.

When a database is used by a messaging interface or connector, the related hosted database and its supporting system must be protected as a Swift-related component and exceptions alerted

C.

Alerts generated from performed integrity checks are captured and analysed for appropriate treatment

What type of control effectiveness needs to be validated for an independent assessment?

A.

Effectiveness is never validated only the control design

B.

An independent assessment is a point in time review with possible reviews of older evidence as appropriate

C.

Operational effectiveness needs to be validated

D.

None of the above

Which ones are Alliance Lite2 key components? (Choose all that apply.)

A.

A web interface

B.

An AutoClient

C.

A HSM box

D.

A WebSphere MQ Server

Can an internal audit department submit and approve their Swift user's attestation on the KYC-SA Swift portal?

A.

Yes, providing this is agreed by the head of IT operations and the CISO

B.

No, this is never an option

C.

Yes, an internal auditor can submit the attestation for approval provided they have the appropriate credentials for switt.com. The CISO remains in charge of the approval of the attestation

D.

Yes, with approval from the Chief auditor

Which statement(s) is/are correct about the LSO/RSO accounts on a Swift Alliance Access? (Choose all that apply.)

A.

They are local Security Officers

B.

Their PKI certificates are stored either on a HSM Token or on a HSM-box

C.

They are the business profiles that can sign the Swift financial transactions

D.

They are responsible for the configuration and management of the security functions of the server

A SWIFT user has had part of controls assessed by their internal audit department, and the other remaining controls using an external assessor company. Is this acceptable? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

A.

Yes, a SWIFT user can combine multiple assessment types (internal and external assessment) as long as all controls are covered

B.

No, because the SWIFT user cannot be sure the same approach and quality will be delivered

C.

Yes, but only if there is a signed agreement between all involved assessors

D.

No, SWIFT can reject the attestation in such situations

How are online SwiftNet Security Officers authenticated?

A.

Via their PKI certificate

B.

Via their swift.com account and secure code card

C.

Via their swift.com account

Which of the following infrastructures has the smallest Swift footprint?

A.

Full stack of products up to the Messaging Interface

B.

Alliance Remote Gateway

C.

Alliance Lite2

D.

Full stack of products includinq IPLA

Select the correct statement about Alliance Gateway.

A.

It is used to exchange messages over the Swift network

B.

It is used to create messages to send over the Swift network

The messaging operator in Alliance Lite2… (Select the two correct answers that apply)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

Can create and modify messages

B.

Can assign RBAC roles to RMA operators and messaging operators

C.

Can approve the Customer Security Officer change requests

D.

Can approve messages

The Alliance Access OS administrator can create and send financial messages.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

TRUE

B.

FALSE

The Swift secure zone is composed of a Swift connector, a middleware server and a back office system Is the selection of only one of the above components a representative sample based on the High-Level Test Plan (HLTP) guidelines?

A.

Yes

B.

No

Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?

A.

Yes, because if there is no secure zone then the internet connectivity does not need to be restricted

B.

No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider

Select the correct statement(s) about the Swift Alliance Gateway. (Choose all that apply.)

A.

It acts as the single window to SwiftNet messaging services byconcentratingyour traffic flows

B.

It allows sharing of PKI profiles between application or individuals, through the use of virtual profiles

C.

It allows the creation and/or modification of some Swift messages (depending on the types &/or formats)

D.

The Alliance Gateway can only be accessed by a SWIFTNet user

As a SWIFT CSP Certified Assessor, my external cybersecurity certification (example: CISA) has expired. Am I still allowed to work as a certified assessor?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

A.

No, a valid external cybersecurity certification is mandatory to keep the CSP Certified Assessor certification

B.

Yes, if the SWIFT CSP Assessor certification is still valid

Page: 1 / 2
Total 116 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved