Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Swift Customer Security Programme (CSP) CSP-Assessor Questions and answers with ValidTests

Exam CSP-Assessor All Questions
Exam CSP-Assessor Premium Access

View all detail and faqs for the CSP-Assessor exam

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

The SWIFT VPN boxes are located between the Messaging and Communication interface.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

TRUE

B.

FALSE

Expert Solution
Questions # 12:

What does SWIFT provide? (Select the two correct answers that apply)

Question # 12

Options:

A.

A platform for messaging

B.

Standards for communicating

C.

Hosting for financial institutions

D.

A high-level programming language

Expert Solution
Questions # 13:

The Alliance Access OS administrator can create and send financial messages.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

TRUE

B.

FALSE

Expert Solution
Questions # 14:

Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?

Question # 14

Options:

A.

Yes, because if there is no secure zone then the internet connectivity does not need to be restricted

B.

No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider

Expert Solution
Questions # 15:

Application Hardening basically applies the following principles. (Choose all that apply.)

Question # 15

Options:

A.

Least Privileges

B.

Access on a need to have

C.

Reduced footprint for less potential vulnerabilities

D.

Enhanced Straight Through Processing

Expert Solution
Questions # 16:

The Swift user has an sFTP server to push files to an outsourcing agent hosting the Swift users own Communication interface. What is their architecture type?

Question # 16

Options:

A.

A1

B.

B

C.

A3

D.

A4

Expert Solution
Questions # 17:

The Alliance Gateway application is considered a messaging interface.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

TRUE

B.

FALSE

Expert Solution
Questions # 18:

A SWIFT user has had part of controls assessed by their internal audit department, and the other remaining controls using an external assessor company. Is this acceptable? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes, a SWIFT user can combine multiple assessment types (internal and external assessment) as long as all controls are covered

B.

No, because the SWIFT user cannot be sure the same approach and quality will be delivered

C.

Yes, but only if there is a signed agreement between all involved assessors

D.

No, SWIFT can reject the attestation in such situations

Expert Solution
Questions # 19:

Is the restriction of Internet access only relevant when having SWIFT-related components in a secure zone?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.

Yes, because if there is no secure zone, then the internet connectivity does not need to be restricted

B.

No, because there can be in-scope general operator PCs used to access a SWIFT-related application hosted at a service provider

Expert Solution
Questions # 20:

How are online SwiftNet Security Officers authenticated?

Question # 20

Options:

A.

Via their PKI certificate

B.

Via their swift.com account and secure code card

C.

Via their swift.com account

Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions