[Apr 29, 2025] Pass Customer Security Programme (CSP) CSP-Assessor Exam With 58 Questions
Ultimate Guide to Prepare Free Swift CSP-Assessor Exam Questions and Answer
NEW QUESTION # 19
Select the correct statement(s).
- A. The public and private keys of a Swift certificate are stored on the Hardware Security Module
- B. The certificate stored on the Swift Hardware Security Module is used during the decryption operation of a message
- C. The decryption operation uses the encryption private key of the receiver
- D. To verify the signature the SwiftNetLink uses the signing private key of the receiver
Answer: A,C
NEW QUESTION # 20
Which encryption methods are used to secure the communications between the SNL host and HSM boxes?
- A. NTLS and Telnet
- B. NTLS and SSH
- C. MPLS and SSL
- D. Telnet and SSL
Answer: B
NEW QUESTION # 21
Which of the following statements best describe valid implementations when implementing control 2.9 Transaction Business Controls? (Choose all that apply.)
- A. Multiple measures must be implemented by the Swift user to validate the flows of transactions are in the bounds of the normal expected business
- B. Any solutions is acceptable so long as the CISO approves the implementation
- C. A customer designed implementation or a combination of different measures are deemed valid if they sufficiently mitigate the control risks
- D. Reliance on a recent business assessment or regulator response confirming the effectiveness of the control (as an example CPMI's_ requirement) is especially poignant to this control
Answer: A,C,D
NEW QUESTION # 22
As a Swift CSP Certified Assessor, I left the listed provider and started to work independently. Can I continue to perform CSP assessments?
- A. Yes. during the certification validity period
- B. No, this is not allowed
- C. Yes. but not as a Swift CSP Certified assessor
- D. [No, except if Swift formally provides you permission
Answer: C
NEW QUESTION # 23
Alliance Lite2 only supports the sending and receiving of FIN messages.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION # 24
Select the components a SwiftNet Link (SNL) may communicate with. (Choose all that apply.)
- A. The Graphical User Interface
- B. The HSM device
- C. The messaging interface (such as Alliance Access)
- D. The VPN boxes
Answer: A,B,C
NEW QUESTION # 25
Which ones are Alliance Lite2 key components? (Choose all that apply.)
- A. An AutoClient
- B. A HSM box
- C. A WebSphere MQ Server
- D. A web interface
Answer: A,B,D
NEW QUESTION # 26
A Swift user has remediated an exception reported by the assessor. What are their obligations before updating and submitting an attestation reflecting the new compliance level?
- A. The exception must be re-assessed by an independent assessor. The assessor can be different to the one who initially raised the exception
- B. The first line of defense can confirm their level of compliance using a self-assessment approach
- C. The exception must be re-assessed by the same independent assessor that raised the exception
- D. None, if the remediation has been completed, a new attestation can be submitted reflecting the compliance of the control
Answer: A
NEW QUESTION # 27
The Swift secure zone is composed of a Swift connector, a middleware server and a back office system Is the selection of only one of the above components a representative sample based on the High-Level Test Plan (HLTP) guidelines?
- A. No
- B. Yes
Answer: A
NEW QUESTION # 28
Penetration testing must be performed at application level against the Swift-related components, such as the interfaces, Swift and customer connectors?
- A. False, only the components as defined in Swift Testing Policy
- B. True, those are key components
Answer: B
NEW QUESTION # 29
What is expected regarding Token Management when (physical or software-based) tokens are used? (Choose all that apply.)
- A. Similar to user accounts, individual assignment and ownership for accurate traceability and revocation in case of potential tampering, loss or in case of user role change
- B. All tokens must be stored in a safe when not used
- C. Individuals must not share their tokens. Tokens must remain under the control and supervision of its owner
- D. Have in place a strict token assignment process. This avoids the need to perform g a regular review of assigned tokens
Answer: A,C
NEW QUESTION # 30
Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?
- A. Yes, because if there is no secure zone then the internet connectivity does not need to be restricted
- B. No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider
Answer: B
NEW QUESTION # 31
Is the control 2. 11 "RMA Business Controls" only about the process of validating the defined counterparty relationships?
- A. No
- B. Yes
Answer: A
NEW QUESTION # 32
How many Swift Security Officers does an organization need at minimum?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 33
- A. Option C
- B. Option B
- C. 1. Customer Connector
2. Customer Connector
3. Customer Connector
4. Customer Connector - D. Option D
- E. 1. Customer Connector
2. Bridging Server (Middleware Server)
3. Customer Connector
4. Customer Connector - F. 1. Customer Connector
2. Bridging Server (Middleware Server)
3. Customer Connector
4. Bridging Server (Middleware Server) - G. Option A
- H. 1. Bridging Server (Middleware Server)
2. Bridging Server (Middleware Server)
3. Bridging Server (Middleware Server)
4. Bridging Server (Middleware Server)
Answer: F,G
NEW QUESTION # 34
A Swift user can only exchange FIN messages via the Swift network.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION # 35
Can a Swift user choose to implement the security controls (example: logging and monitoring) in systems which are not directly in scope of the CSCE?
- A. Yes
- B. No
Answer: A
NEW QUESTION # 36
The Physical Security protection control is also aimed at protecting the "on call" and "working from home" employees' equipment used to access the Swift-related components.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION # 37
Is it necessary to formally explain to the Swift user the testing methodology that will be used for the CSP assessment during the kick-off?
- A. Yes
- B. No
Answer: A
NEW QUESTION # 38
The Swift user would like to perform their CSP assessment in May for the CSCF version that will only be active as from July the same year. Is it allowed?
- A. No, an assessment can only be done on the active version of the CSCF
- B. Yes, the assessment on a particular version can start before the actual activation date
Answer: A
NEW QUESTION # 39
Which authentication methods are possible on the Alliance Interfaces? (Choose all that apply.)
- A. Radius One-time password
- B. Password
- C. Password and TOTP
- D. LDAP Authentication
Answer: A,B,C,D
NEW QUESTION # 40
The Swift user has an sFTP server to push files to an outsourcing agent hosting the Swift users own Communication interface. What is their architecture type?
- A. A3
- B. A4
- C. A1
- D. B
Answer: D
NEW QUESTION # 41
Which user roles are available in Alliance Cloud by default. (Choose all that apply.)
- A. Role and Operator management
- B. Message Management
- C. Message Security Administrator
- D. Administrator
Answer: D
NEW QUESTION # 42
......
Pass CSP-Assessor Tests Engine pdf - All Free Dumps: https://torrentpdf.actual4exams.com/CSP-Assessor-real-braindumps.html