Easter Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Swift CSP-Assessor Customer Security Programme Assessor Certification(CSPAC) Exam Practice Test

Page: 1 / 12
Total 116 questions

Customer Security Programme Assessor Certification(CSPAC) Questions and Answers

Question 1

In the context of CSP, what type of component is the Alliance Access? (Select the correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

A Messaging Interface

B.

A Communication Interface

C.

A SWIFT Connector

D.

A Secure Server

Question 2

How are online SwiftNet Security Officers authenticated?

Question # 2

Options:

A.

Via their PKI certificate

B.

Via their swift.com account and secure code card

C.

Via their swift.com account

Question 3

What are the three main objectives of the Customer Security Controls Framework? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.

1. Secure your environment

2. Know and Limit Access

3. Detect and Respond

B.

1. Restrict Internet Access and Protect Critical Systems from General IT Environment

2. Reduce Attack Surface and Vulnerabilities

3. Physically Secure the Environment

C.

1. Secure and Protect

2. Prevent and Detect

3. Share and Prepare

D.

1. Raise pragmatically the security bar

2. Maintain appropriate cyber-security hygiene

3. React promptly

Question 4

The SWIFT PKI certificates are used for… (Select the correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

Asymmetric signing and encryption end to end

B.

Asymmetric signing and encryption end to SWIFT only

C.

Symmetric encryption only

D.

Asymmetric signing only

Question 5

A SWIFT user is not based in the same country as the assessor. The assessor would like to perform the assessment remotely. Is this permitted? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Remote assessments are not permitted under any circumstances

B.

This is permitted provided the same level of comfort can be guaranteed

C.

It is possible to perform an assessment remotely only with valid reasons. These reasons must be formally validated by SWIFT CSP office

D.

It is not allowed to conduct an assessment remotely under any circumstances. However, force majeure circumstances like the global pandemic are an exception to this

Question 6

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

TRUE

B.

FALSE

Question 7

The cluster of VPN boxes is also called managed-customer premises equipment (M-CPE).

Question # 7

Options:

A.

TRUE

B.

FALSE

Question 8

Can a Swift user choose to implement the security controls (example: logging and monitoring) in systems which are not directly in scope of the CSCE?

Question # 8

Options:

A.

Yes

B.

No

Question 9

A SWIFT user has had part of controls assessed by their internal audit department, and the other remaining controls using an external assessor company. Is this acceptable? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes, a SWIFT user can combine multiple assessment types (internal and external assessment) as long as all controls are covered

B.

No, because the SWIFT user cannot be sure the same approach and quality will be delivered

C.

Yes, but only if there is a signed agreement between all involved assessors

D.

No, SWIFT can reject the attestation in such situations

Question 10

What are the conditions required to permit reliance on the compliance conclusion of a control assessed in the previous year? (Choose all that apply.)

Question # 10

Options:

A.

The control compliance conclusion must have already been relied on the past two years

B.

The previous assessment was performed on the (correct) CSCF version of the previous year

C.

The control definition has not changed

D.

The control-design and implementation are the same

Question 11

A SWIFT user owns a customer connector and a communication interface. What architecture type is the SWIFT user? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

A1

B.

A2

C.

A3

D.

A4

Question 12

How many Swift Security Officers does an organization need at minimum?

Question # 12

Options:

A.

1

B.

2

C.

3

D.

4

Question 13

Which authentication methods are possible on the Alliance Interfaces? (Choose all that apply.)

Question # 13

Options:

A.

Password

B.

LDAP Authentication

C.

Radius One-time password

D.

Password and TOTP

Question 14

A Swift user relies on a sFTP server to connect through an externally exposed connection with a service provider or a group hub What architecture type is the Swift user? (Choose all that apply.)

Question # 14

Options:

A.

A1

B.

A2

C.

A3

D.

A4

Question 15

A Swift user has remediated an exception reported by the assessor. What are their obligations before updating and submitting an attestation reflecting the new compliance level?

Question # 15

Options:

A.

The exception must be re-assessed by an independent assessor. The assessor can be different to the one who initially raised the exception

B.

The exception must be re-assessed by the same independent assessor that raised the exception

C.

The first line of defense can confirm their level of compliance using a self-assessment approach

D.

None, if the remediation has been completed, a new attestation can be submitted reflecting the compliance of the control

Question 16

Which of the following statements best describes the difference between an audit and an assessment as per SWIFT CSP definitions? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

An audit is a comprehensive review of a customer’s controls to ensure they meet regulatory requirements, while an assessment is a very high-level review of controls to identify potential weaknesses

B.

An audit looks at the defined controls design and implementation compliance and follows recognized international audit standards, whereas an assessment is less strict but aims the same common objectives

C.

An audit is a one-time event, while an assessment is an ongoing process of monitoring and improving security controls

D.

An audit and an assessment can be used interchangeably

Question 17

Which of the following infrastructures has the smallest SWIFT footprint? (Select the correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

Full stack of products up to the Messaging Interface

B.

Alliance Remote Gateway

C.

Lite 2 or Alliance Cloud

D.

A user with a Messaging Interface behind a Service Bureau

Question 18

The SWIFT user’s first line of defence has performed a detailed self-assessment demonstrating an adequate compliance level to each of the applicable controls. As an assessor, may I fully rely on this analysis if the SWIFT user can demonstrate that their conclusion was based on a valid testing approach? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes

B.

Yes, but only if the CISO signs the completion letter at the end of the assessment

C.

No, even if it could support the compliance level, additional testing will always be required by the independent assessor to confirm a controls compliance level

D.

No, except if the SWIFT user’s chief auditor approves this approach

Question 19

A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server What architecture type is the Swift user? (Choose all that apply.)

Question # 19

Options:

A.

A1

B.

B

C.

A3

D.

A4

Question 20

The Swift HSM boxes:

Question # 20

Options:

A.

Are located at the network partner premises and managed by Swift

B.

Are located at the Swift user premises and managed by Swift

C.

Are located at the Swift user premises and managed by the Swift user

D.

Are located at the network partner premises and managed by Swift the network partner

Question 21

Can an internal audit department submit and approve their Swift user's attestation on the KYC-SA Swift portal?

Question # 21

Options:

A.

Yes, providing this is agreed by the head of IT operations and the CISO

B.

No, this is never an option

C.

Yes, an internal auditor can submit the attestation for approval provided they have the appropriate credentials for switt.com. The CISO remains in charge of the approval of the attestation

D.

Yes, with approval from the Chief auditor

Question 22

The internet connectivity restriction control prevents having internet access on any CSCE m-scope components.

Question # 22

Options:

A.

TRUE

B.

FALSE

Question 23

When hesitant on the applicability of a CSCF control to a particular component? What steps should you take? (Choose all that apply.)

Question # 23

Options:

A.

Call your Swift contact

B.

Check appendix F of the CSCF

C.

Check carefully the Introduction section of the CSCF

D.

Open a case with Swift support via the case manager on swift com if further information or solution cannot be found in the documentation

Question 24

On which one of the following components must a Password/PIN Policy not be defined and implemented as per the CSCF? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.

Operator PCs, (physical or virtual) systems running SWIFT-related components, network devices protecting the secure zone(s), bridging servers

B.

Jump server(s), SWIFT-related components at application level

C.

Personal tokens or mobile devices used as a possession factor

D.

All equipment within the user environment

Question 25

Select the components a SwiftNet Link (SNL) may communicate with. (Choose all that apply.)

Question # 25

Options:

A.

The Graphical User Interface

B.

The VPN boxes

C.

The HSM device

D.

The messaging interface (such as Alliance Access)

Question 26

The Alliance Web Platform Administrator uses both the GUI and command line to perform configuration and monitoring tasks on AWP SE.

Question # 26

Options:

A.

TRUE

B.

FALSE

Question 27

May an assessor rely on an ISAE 3000 report dating back 2 years to support a CSP independent assessment? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

No, that is too old, the maximum is 18 months

B.

Yes, there is no time limit for an ISAE 3000 report

C.

No, an ISAE 3000 report is no valid substitute as a rule

D.

Yes, provided there is no change to the SWIFT user’s infrastructure

Question 28

The Alliance Access OS administrator can create and send financial messages.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

TRUE

B.

FALSE

Question 29

What type of control effectiveness needs to be validated for an independent assessment?

Question # 29

Options:

A.

Effectiveness is never validated only the control design

B.

An independent assessment is a point in time review with possible reviews of older evidence as appropriate

C.

Operational effectiveness needs to be validated

D.

None of the above

Question 30

For each of the following setups, the responsible party is identified to protect the virtualization or cloud underlying platform. Which one of the combinations is not correct?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

For on-premises virtualization platform: by the platform provider

B.

For virtualization platform deployed at a third party on which user’s SWIFT-related components are virtually hosted: by the third party

C.

For on-premises container platform: by the SWIFT user

D.

For Cloud Provider: the cloud provider

Question 31

Is it necessary to formally explain to the Swift user the testing methodology that will be used for the CSP assessment during the kick-off?

Question # 31

Options:

A.

Yes

B.

No

Question 32

In the illustration, identify which components are in scope of the CSCF? (Choose all that apply.)

Question # 32

Question # 32

Options:

A.

Components A, B, K

B.

Components J, K, I

C.

Components F, G, H

D.

Components C, E, M

Question 33

The SWIFT user has installed its own Communication Interface on a dedicated virtual machine offered by a public cloud provider. Under which provider category does the public cloud provider fit, and what is the CSP impact? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.

The public cloud provider is considered a L2BA provider, and therefore not in scope of the CSP

B.

The public cloud provider is considered a SWIFT connectivity provider, and therefore not in scope of the CSP

C.

The public cloud provider is considered an outsourcing agent, and therefore in scope of the CSP

D.

This type of implementation is not allowed by the CSP

Question 34

In an entity having a small infrastructure and only 2 operators, the HR manager explains in a short interview how the security training is implemented providing one example. Would it be acceptable?

Question # 34

Options:

A.

Yes. it's a risk based testing approach this can be enough in this case

B.

No. more evidence are required

Page: 1 / 12
Total 116 questions