Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

CSP-Assessor Customer Security Programme Assessor Certification(CSPAC) Questions and Answers

Questions 4

The Alliance Web Platform Administrator uses both the GUI and command line to perform configuration and monitoring tasks on AWP SE.

CSP-Assessor Question 4

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 5

The SWIFT PKI certificates are used for… (Select the correct answer)

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

Options:

A.

Asymmetric signing and encryption end to end

B.

Asymmetric signing and encryption end to SWIFT only

C.

Symmetric encryption only

D.

Asymmetric signing only

Buy Now
Questions 6

Which of the following infrastructures has the smallest SWIFT footprint? (Select the correct answer)

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

Options:

A.

Full stack of products up to the Messaging Interface

B.

Alliance Remote Gateway

C.

Lite 2 or Alliance Cloud

D.

A user with a Messaging Interface behind a Service Bureau

Buy Now
Questions 7

Is the restriction of Internet access only relevant when having SWIFT-related components in a secure zone?

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

Options:

A.

Yes, because if there is no secure zone, then the internet connectivity does not need to be restricted

B.

No, because there can be in-scope general operator PCs used to access a SWIFT-related application hosted at a service provider

Buy Now
Questions 8

The Physical Security control also includes a regular review of physical access lists of the SWIFT-related servers' locations.

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 9

Select the correct statement about SWIFT Alliance Cloud.

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

Options:

A.

Alliance Cloud is a SWIFT cloud-based solution. It provides a universal channel to the financial community and to SWIFT Value Added services and initiatives

B.

Alliance Cloud is a cloud-based solution. It is offered by the 3 official public cloud providers. This allows customers the choice to select their preferred cloud provider

C.

Alliance Cloud is a cloud-based solution. It is offered by any public cloud provider that subscribed to the digital connectivity initiative

D.

Alliance Cloud is a SWIFT cloud-based solution. It consists of an Alliance Access instance deployed at one of the three SWIFT-approved public cloud providers

Buy Now
Questions 10

What must a Swift user implement to comply with a CSCF security control?

CSP-Assessor Question 10

Options:

A.

A solution that maps the implementation guidelines described for a controls in scope components

B.

A solution that meets the control objectives and addresses the risk drivers for the in scope components)

Buy Now
Questions 11

The Swift user would like to perform their CSP assessment in May for the CSCF version that will only be active as from July the same year. Is it allowed?

CSP-Assessor Question 11

Options:

A.

No, an assessment can only be done on the active version of the CSCF

B.

Yes, the assessment on a particular version can start before the actual activation date

Buy Now
Questions 12

The outsourcing agent of the SWIFT user provided them with an independent assessment report covering the CSP components in their scope, and using the latest CSCF version for testing. Is it enough to support the CSP attestation for the outsourced components? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

Options:

A.

Yes, after confirmation and validation of the scope

B.

Yes, only if the outsourcing agent is a global trusted provider and published the report on their compliance portal

C.

No, an audit report (and not an assessment) is required from the outsourcing agent as an external provider

D.

No, except if the cloud provider components are partially covered by the SWIFT Alliance Connect Virtual programme

Buy Now
Questions 13

In the context of CSP, what type of component is the Alliance Access? (Select the correct answer)

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

Options:

A.

A Messaging Interface

B.

A Communication Interface

C.

A SWIFT Connector

D.

A Secure Server

Buy Now
Questions 14

The bridging servers supporting the data exchange between the back-office and the SWIFT infrastructure are in scope of security controls (for some as advisory).

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 15

A detailed CSP assessment report has been provided to the Swift user following the assessment. Is a completion letter also mandated to be supplied?

CSP-Assessor Question 15

Options:

A.

Yes

B.

No

Buy Now
Questions 16

From the outsourcing agent diagram, which components in the diagram are in scope and applicable for the Swift user.

CSP-Assessor Question 16

CSP-Assessor Question 16

Options:

A.

Components A, B, C, D and E

B.

Components A and B

C.

Components C, D and E

D.

None of the above

Buy Now
Questions 17

In an entity having a small infrastructure and only 2 operators, the HR manager explains in a short interview how the security training is implemented providing one example. Would it be acceptable?

CSP-Assessor Question 17

Options:

A.

Yes. it's a risk based testing approach this can be enough in this case

B.

No. more evidence are required

Buy Now
Questions 18

On which one of the following components must a Password/PIN Policy not be defined and implemented as per the CSCF? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

Options:

A.

Operator PCs, (physical or virtual) systems running SWIFT-related components, network devices protecting the secure zone(s), bridging servers

B.

Jump server(s), SWIFT-related components at application level

C.

Personal tokens or mobile devices used as a possession factor

D.

All equipment within the user environment

Buy Now
Questions 19

In the illustration, identify the component type of each of the numbered components.

CSP-Assessor Question 19

CSP-Assessor Question 19

Options:

A.

1. Customer Connector

2. Bridging Server (Middleware Server)

3. Customer Connector

4. Bridging Server (Middleware Server)

B.

1. Customer Connector

2. Bridging Server (Middleware Server)

3. Customer Connector

4. Customer Connector

C.

1. Bridging Server (Middleware Server)

2. Bridging Server (Middleware Server)

3. Bridging Server (Middleware Server)

4. Bridging Server (Middleware Server)

D.

1. Customer Connector

2. Customer Connector

3. Customer Connector

4. Customer Connector

Buy Now
Questions 20

Select the supporting documents to conduct a CSP assessment. (Choose all that apply.)

CSP-Assessor Question 20

Options:

A.

The CSP User Handbook

B.

The mapping to industry standards article

C.

The Controls Matrix and High Level Test P an

D.

The Customer Security Controls Framework

Buy Now
Questions 21

The Physical Security protection control is also aimed at protecting the “on call” and “working from home” employees’ equipment used to access the Swift-related components.

CSP-Assessor Question 21

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 22

Select the correct statement(s) about the Swift Alliance Gateway. (Choose all that apply.)

CSP-Assessor Question 22

Options:

A.

It acts as the single window to SwiftNet messaging services by concentrating your traffic flows

B.

It allows sharing of PKI profiles between application or individuals, through the use of virtual profiles

C.

It allows the creation and/or modification of some Swift messages (depending on the types & /or formats)

D.

The Alliance Gateway can only be accessed by a SWIFTNet user

Buy Now
Questions 23

What are the possible impacts for a SWIFT user to be non-compliant to CSP? (Select the two correct answers that apply)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

Options:

A.

To be reported to their supervisors (if applicable)

B.

To be seen as non-compliant to their counterparts in KYC-SA

C.

To be contacted by SWIFT to provide the CSP assessment report and detailed information about the reason of non-compliance

D.

To be delisted from the BIC directory

Buy Now
Questions 24

Application Hardening basically applies the following principles. (Choose all that apply.)

CSP-Assessor Question 24

Options:

A.

Least Privileges

B.

Access on a need to have

C.

Reduced footprint for less potential vulnerabilities

D.

Enhanced Straight Through Processing

Buy Now
Questions 25

A SWIFT user is not based in the same country as the assessor. The assessor would like to perform the assessment remotely. Is this permitted? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

Options:

A.

Remote assessments are not permitted under any circumstances

B.

This is permitted provided the same level of comfort can be guaranteed

C.

It is possible to perform an assessment remotely only with valid reasons. These reasons must be formally validated by SWIFT CSP office

D.

It is not allowed to conduct an assessment remotely under any circumstances. However, force majeure circumstances like the global pandemic are an exception to this

Buy Now
Questions 26

What type of control effectiveness needs to be validated for an independent assessment?

CSP-Assessor Question 26

Options:

A.

Effectiveness is never validated only the control design

B.

An independent assessment is a point in time review with possible reviews of older evidence as appropriate

C.

Operational effectiveness needs to be validated

D.

None of the above

Buy Now
Questions 27

The Internal Audit and an external assessment company are both involved in a SWIFT user’s assessment. Both have shared control assessments to cover the full scope (meaning two separate assessment teams). Who needs to provide a completion letter? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

Options:

A.

The Internal audit lead assessor and the external company lead assessor

B.

The Internal audit lead assessor only

C.

The External company lead assessor only

D.

None of them, it is not required when an internal department was involved in the assessment

Buy Now
Questions 28

As a SWIFT CSP Certified Assessor, my external cybersecurity certification (example: CISA) has expired. Am I still allowed to work as a certified assessor?

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

Options:

A.

No, a valid external cybersecurity certification is mandatory to keep the CSP Certified Assessor certification

B.

Yes, if the SWIFT CSP Assessor certification is still valid

Buy Now
Questions 29

The SWIFT user has a local communication interface as their main channel to SWIFT. For contingency, the SWIFT user also has a connector as a backup channel. What is the architecture type for this SWIFT user? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift CSP Assessment Report Template

Options:

A.

A1

B.

A2

C.

A3

D.

A4

Buy Now
Questions 30

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 31

Can an internal audit department submit and approve their Swift user's attestation on the KYC-SA Swift portal?

CSP-Assessor Question 31

Options:

A.

Yes, providing this is agreed by the head of IT operations and the CISO

B.

No, this is never an option

C.

Yes, an internal auditor can submit the attestation for approval provided they have the appropriate credentials for switt.com. The CISO remains in charge of the approval of the attestation

D.

Yes, with approval from the Chief auditor

Buy Now
Questions 32

How can PKI certificate requests be submitted to SWIFT? (Select the correct answer)

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

Options:

A.

Using both online and offline methods

B.

Using an online method

C.

Using an offline method

D.

None of the above

Buy Now
Questions 33

The objective of the Customer Environment Protection control is to separate the user's Swift infrastructure which restricts malicious access from the external world and from the General IT environment of the Swift user.

CSP-Assessor Question 33

Options:

A.

TRUE

B.

FALSE

Buy Now
Exam Code: CSP-Assessor
Exam Name: Customer Security Programme Assessor Certification(CSPAC)
Last Update: May 20, 2026
Questions: 116

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11