Skip to main content

CSP-ASSESSOR Real Exam Questions

Customer Security Programme Assessor

116 questions available · Page 1 of 12

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

Where is the implementation of multi-factor authentication deemed sufficient to support control 4.2 compliance? (Choose all that apply.)

  1. A

    When accessing an outsourcing agent or an L2BA Swift-related application

  2. B

    When logging-in on an interface, a connector, or the system running such component

  3. C

    When login on the jump server filtering access to local Swift secure zone

  4. D

    On the General Operator PC used to access a Swift-related component

Show answer and explanation

Correct answers: A, B, C, D

Question 2 Single choice

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

Connectivity

Generic

Products Cloud

Products OnPrem

Security

  1. A

    TRUE

  2. B

    FALSE

Show answer and explanation

Correct answer: A

Question 3 Single choice

Select the correct statement about Alliance Gateway.

  1. A

    It is used to exchange messages over the Swift network

  2. B

    It is used to create messages to send over the Swift network

Show answer and explanation

Correct answer: A

Question 4 Single choice

Is it mandated to perform security awareness and other specific trainings every year for individuals with SWIFT-critical roles? (Select the correct answer) Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025

Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework - High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025

CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

  1. A

    Yes, and a track record must show that both awareness and specific training are performed annually

  2. B

    No, both awareness and specific trainings are planned when deemed required

  3. C

    No, awareness training expected to be performed yearly; specific training to maintain the required
    knowledge only when needed

  4. D

    No, a track record must show that both awareness and specific training are performed at least bi-yearly (every 2 years)

Show answer and explanation

Correct answer: A

Question 5 Single choice

An application only uses (i) the SWIFT API for reporting and gpi basic tracker calls through (ii) a tailored account not allowing business transactions management. Is this application in scope of the CSCF? (Select the correct answer)

Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025

Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework - High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025

CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

CSCF Assessment Completion Letter

Swift_CSP_Assessment_Report_Template

  1. A

    Yes, it is in scope and considered a customer connector because it reads business transaction data

  2. B

    No, it can be descoped because there is no business transaction management being performed

  3. C

    No, it is not in scope because the API connection method is not in scope of the CSP

  4. D

    Yes, it is in scope because the API connection method is less secure than SWIFT interfaces

Show answer and explanation

Correct answer: B

Question 6 Multiple choice

What are the conditions required to allow reliance on the compliance conclusion of a control assessed in the previous year? (Select all answers that apply)

Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025

Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework -High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025 CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

CSCF Assessment Completion Letter

Swift_CSP_Assessment_Report_Template

  1. A

    The control compliance conclusion must have already been relied on the past two years

  2. B

    The previous assessment was performed on the CSCF version of the previous year (at least)

  3. C

    The control definition has not changed

  4. D

    The control design and implementation are the same

Show answer and explanation

Correct answers: C, D

Question 7 Multiple choice

A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server
What architecture type is the Swift user?
(Choose all that apply.)

  1. A

    A1

  2. B

    B

  3. C

    A3

  4. D

    A4

Show answer and explanation

Correct answers: B, C

Question 8 Single choice

To verify the applicability of a CSCF control to a specific component, several actions may be considered.
Which one does not apply in this case?

Swift Customer Security Controls Policy

Swift Customer Security Controls Framework v2025

Independent Assessment Framework

Independent Assessment Process for Assessors Guidelines

Independent Assessment Framework - High-Level Test Plan Guidelines

Outsourcing Agents - Security Requirements Baseline v2025

CSP Architecture Type - Decision tree

CSP_controls_matrix_and_high_test_plan_2025

Assessment template for Mandatory controls

Assessment template for Advisory controls

CSCF Assessment Completion Letter

Swift_CSP_Assessment_Report_Template

  1. A

    Check in the CSP Policy document

  2. B

    Check appendix F of the CSCF

  3. C

    Check carefully the Introduction section of the CSCF

  4. D

    Open a case with SWIFT support via the case manager on swift.com if further information or solution cannot be found in the documentation

Show answer and explanation

Correct answer: A

Question 9 Single choice

The only type of HSM devices offered by Swift are HSM tokens and HSM boxes.

  1. A

    TRUE

  2. B

    FALSE

Show answer and explanation

Correct answer: A

Question 10 Multiple choice

Application Hardening basically applies the following principles. (Choose all that apply.)

  1. A

    Least Privileges

  2. B

    Access on a need to have

  3. C

    Reduced footprint for less potential vulnerabilities

  4. D

    Enhanced Straight Through Processing

Show answer and explanation

Correct answers: A, B, C