[Apr 29, 2025] Pass Customer Security Programme (CSP) CSP-Assessor Exam With 58 Questions [Q19-Q42]

Share

[Apr 29, 2025] Pass Customer Security Programme (CSP) CSP-Assessor Exam With 58 Questions

Ultimate Guide to Prepare Free Swift CSP-Assessor Exam Questions and Answer

NEW QUESTION # 19
Select the correct statement(s).

  • A. The public and private keys of a Swift certificate are stored on the Hardware Security Module
  • B. The certificate stored on the Swift Hardware Security Module is used during the decryption operation of a message
  • C. The decryption operation uses the encryption private key of the receiver
  • D. To verify the signature the SwiftNetLink uses the signing private key of the receiver

Answer: A,C


NEW QUESTION # 20
Which encryption methods are used to secure the communications between the SNL host and HSM boxes?

  • A. NTLS and Telnet
  • B. NTLS and SSH
  • C. MPLS and SSL
  • D. Telnet and SSL

Answer: B


NEW QUESTION # 21
Which of the following statements best describe valid implementations when implementing control 2.9 Transaction Business Controls? (Choose all that apply.)

  • A. Multiple measures must be implemented by the Swift user to validate the flows of transactions are in the bounds of the normal expected business
  • B. Any solutions is acceptable so long as the CISO approves the implementation
  • C. A customer designed implementation or a combination of different measures are deemed valid if they sufficiently mitigate the control risks
  • D. Reliance on a recent business assessment or regulator response confirming the effectiveness of the control (as an example CPMI's_ requirement) is especially poignant to this control

Answer: A,C,D


NEW QUESTION # 22
As a Swift CSP Certified Assessor, I left the listed provider and started to work independently. Can I continue to perform CSP assessments?

  • A. Yes. during the certification validity period
  • B. No, this is not allowed
  • C. Yes. but not as a Swift CSP Certified assessor
  • D. [No, except if Swift formally provides you permission

Answer: C


NEW QUESTION # 23
Alliance Lite2 only supports the sending and receiving of FIN messages.

  • A. TRUE
  • B. FALSE

Answer: B


NEW QUESTION # 24
Select the components a SwiftNet Link (SNL) may communicate with. (Choose all that apply.)

  • A. The Graphical User Interface
  • B. The HSM device
  • C. The messaging interface (such as Alliance Access)
  • D. The VPN boxes

Answer: A,B,C


NEW QUESTION # 25
Which ones are Alliance Lite2 key components? (Choose all that apply.)

  • A. An AutoClient
  • B. A HSM box
  • C. A WebSphere MQ Server
  • D. A web interface

Answer: A,B,D


NEW QUESTION # 26
A Swift user has remediated an exception reported by the assessor. What are their obligations before updating and submitting an attestation reflecting the new compliance level?

  • A. The exception must be re-assessed by an independent assessor. The assessor can be different to the one who initially raised the exception
  • B. The first line of defense can confirm their level of compliance using a self-assessment approach
  • C. The exception must be re-assessed by the same independent assessor that raised the exception
  • D. None, if the remediation has been completed, a new attestation can be submitted reflecting the compliance of the control

Answer: A


NEW QUESTION # 27
The Swift secure zone is composed of a Swift connector, a middleware server and a back office system Is the selection of only one of the above components a representative sample based on the High-Level Test Plan (HLTP) guidelines?

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 28
Penetration testing must be performed at application level against the Swift-related components, such as the interfaces, Swift and customer connectors?

  • A. False, only the components as defined in Swift Testing Policy
  • B. True, those are key components

Answer: B


NEW QUESTION # 29
What is expected regarding Token Management when (physical or software-based) tokens are used? (Choose all that apply.)

  • A. Similar to user accounts, individual assignment and ownership for accurate traceability and revocation in case of potential tampering, loss or in case of user role change
  • B. All tokens must be stored in a safe when not used
  • C. Individuals must not share their tokens. Tokens must remain under the control and supervision of its owner
  • D. Have in place a strict token assignment process. This avoids the need to perform g a regular review of assigned tokens

Answer: A,C


NEW QUESTION # 30
Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?

  • A. Yes, because if there is no secure zone then the internet connectivity does not need to be restricted
  • B. No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider

Answer: B


NEW QUESTION # 31
Is the control 2. 11 "RMA Business Controls" only about the process of validating the defined counterparty relationships?

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 32
How many Swift Security Officers does an organization need at minimum?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C


NEW QUESTION # 33

  • A. Option C
  • B. Option B
  • C. 1. Customer Connector
    2. Customer Connector
    3. Customer Connector
    4. Customer Connector
  • D. Option D
  • E. 1. Customer Connector
    2. Bridging Server (Middleware Server)
    3. Customer Connector
    4. Customer Connector
  • F. 1. Customer Connector
    2. Bridging Server (Middleware Server)
    3. Customer Connector
    4. Bridging Server (Middleware Server)
  • G. Option A
  • H. 1. Bridging Server (Middleware Server)
    2. Bridging Server (Middleware Server)
    3. Bridging Server (Middleware Server)
    4. Bridging Server (Middleware Server)

Answer: F,G


NEW QUESTION # 34
A Swift user can only exchange FIN messages via the Swift network.

  • A. TRUE
  • B. FALSE

Answer: B


NEW QUESTION # 35
Can a Swift user choose to implement the security controls (example: logging and monitoring) in systems which are not directly in scope of the CSCE?

  • A. Yes
  • B. No

Answer: A


NEW QUESTION # 36
The Physical Security protection control is also aimed at protecting the "on call" and "working from home" employees' equipment used to access the Swift-related components.

  • A. FALSE
  • B. TRUE

Answer: B


NEW QUESTION # 37
Is it necessary to formally explain to the Swift user the testing methodology that will be used for the CSP assessment during the kick-off?

  • A. Yes
  • B. No

Answer: A


NEW QUESTION # 38
The Swift user would like to perform their CSP assessment in May for the CSCF version that will only be active as from July the same year. Is it allowed?

  • A. No, an assessment can only be done on the active version of the CSCF
  • B. Yes, the assessment on a particular version can start before the actual activation date

Answer: A


NEW QUESTION # 39
Which authentication methods are possible on the Alliance Interfaces? (Choose all that apply.)

  • A. Radius One-time password
  • B. Password
  • C. Password and TOTP
  • D. LDAP Authentication

Answer: A,B,C,D


NEW QUESTION # 40
The Swift user has an sFTP server to push files to an outsourcing agent hosting the Swift users own Communication interface. What is their architecture type?

  • A. A3
  • B. A4
  • C. A1
  • D. B

Answer: D


NEW QUESTION # 41
Which user roles are available in Alliance Cloud by default. (Choose all that apply.)

  • A. Role and Operator management
  • B. Message Management
  • C. Message Security Administrator
  • D. Administrator

Answer: D


NEW QUESTION # 42
......

Pass CSP-Assessor Tests Engine pdf - All Free Dumps: https://torrentpdf.actual4exams.com/CSP-Assessor-real-braindumps.html