Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

Customer Security Programme Assessor Certification(CSPAC) Question and Answers

Customer Security Programme Assessor Certification(CSPAC)

Last Update Oct 16, 2025
Total Questions : 116

We are offering FREE CSP-Assessor Swift exam questions. All you do is to just go and sign up. Give your details, prepare CSP-Assessor free exam questions and then go for complete pool of Customer Security Programme Assessor Certification(CSPAC) test questions that will help you more.

CSP-Assessor pdf

CSP-Assessor PDF

$42  $104.99
CSP-Assessor Engine

CSP-Assessor Testing Engine

$50  $124.99
CSP-Assessor PDF + Engine

CSP-Assessor PDF + Testing Engine

$66  $164.99
Questions 1

The Swift user has an sFTP server to push files to an outsourcing agent hosting the Swift users own Communication interface. What is their architecture type?

Options:

A.  

A1

B.  

B

C.  

A3

D.  

A4

Discussion 0
Questions 2

Which of the following infrastructures has the smallest Swift footprint?

Options:

A.  

Full stack of products up to the Messaging Interface

B.  

Alliance Remote Gateway

C.  

Alliance Lite2

D.  

Full stack of products includinq IPLA

Discussion 0
Questions 3

To rely on a previous CSP assessment report conclusions, a limited testing approach was used. What is the expected sample size as per the High-Level Test Plan (HLTP) guidelines for each identified component? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

There is no need for a sample for this limited testing

B.  

1

C.  

3

D.  

5

Discussion 0
Questions 4

What type of keys does the HSM box store? (Select the correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.  

Private keys

B.  

Public keys

C.  

Both private and public keys

Discussion 0
Questions 5

Compliance to 2.9 Transaction Business Controls can be obtained through different ways. Which of the following one does not ensure compliance?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

More than one of the measures proposed in the implementation guidelines are implemented

B.  

A customer-designed implementation that encounters the control objective and addresses the risk driver

C.  

Reliance on a recent business assessment or regulator response confirming effectiveness of the existing control

D.  

Any implementation if approved by the CIO

Discussion 0
Questions 6

What are the conditions required to allow reliance on the compliance conclusion of a control assessed in the previous year? (Select all answers that apply)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

The control compliance conclusion must have already been relied on the past two years

B.  

The previous assessment was performed on the CSCF version of the previous year (at least)

C.  

The control definition has not changed

D.  

The control design and implementation are the same

Discussion 0
Questions 7

A SWIFT user owns a customer connector and a communication interface. What architecture type is the SWIFT user? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

A1

B.  

A2

C.  

A3

D.  

A4

Discussion 0
Questions 8

As a SWIFT CSP Certified Assessor, my external cybersecurity certification (example: CISA) has expired. Am I still allowed to work as a certified assessor?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

No, a valid external cybersecurity certification is mandatory to keep the CSP Certified Assessor certification

B.  

Yes, if the SWIFT CSP Assessor certification is still valid

Discussion 0
Questions 9

A SWIFT user has had part of controls assessed by their internal audit department, and the other remaining controls using an external assessor company. Is this acceptable? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

Yes, a SWIFT user can combine multiple assessment types (internal and external assessment) as long as all controls are covered

B.  

No, because the SWIFT user cannot be sure the same approach and quality will be delivered

C.  

Yes, but only if there is a signed agreement between all involved assessors

D.  

No, SWIFT can reject the attestation in such situations

Discussion 0
Questions 10

An application only uses (i) the SWIFT API for reporting and gpi basic tracker calls through (ii) a tailored account not allowing business transactions management. Is this application in scope of the CSCF? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

Yes, it is in scope and considered a customer connector because it reads business transaction data

B.  

No, it can be descoped because there is no business transaction management being performed

C.  

No, it is not in scope because the API connection method is not in scope of the CSP

D.  

Yes, it is in scope because the API connection method is less secure than SWIFT interfaces

Discussion 0
Questions 11

There are open exceptions leading to multiple CSP controls being non-compliant. How should the SWIFT user proceed? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

The user must remediate all the exceptions within 3 months before submitting the CSP attestation in KYC-SA

B.  

The SWIFT user may remediate the exceptions and then re-submit an attestation reflecting the new compliance status, but only after compliance validation by the same independent assessor

C.  

The SWIFT user may remediate the exceptions and re-submit an updated attestation reflecting the new compliance status but only after compliance validation by an independent assessor

D.  

The attestation cannot be submitted before all exceptions are resolved

Discussion 0
Questions 12

The Internal Audit and an external assessment company are both involved in a SWIFT user’s assessment. Both have shared control assessments to cover the full scope (meaning two separate assessment teams). Who needs to provide a completion letter? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

The Internal audit lead assessor and the external company lead assessor

B.  

The Internal audit lead assessor only

C.  

The External company lead assessor only

D.  

None of them, it is not required when an internal department was involved in the assessment

Discussion 0
Questions 13

Must all CSCF controls be subject to an assessment? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

Yes

B.  

No, only the mandatory controls

C.  

No, only the attested controls (with as a minimum the mandatory ones according to the architecture type)

D.  

No, the controls selection is agreed upfront between the SWIFT User and the assessor

Discussion 0
Questions 14

Is the restriction of Internet access only relevant when having SWIFT-related components in a secure zone?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.  

Yes, because if there is no secure zone, then the internet connectivity does not need to be restricted

B.  

No, because there can be in-scope general operator PCs used to access a SWIFT-related application hosted at a service provider

Discussion 0
Questions 15

A Swift user has remediated an exception reported by the assessor. What are their obligations before updating and submitting an attestation reflecting the new compliance level?

Options:

A.  

The exception must be re-assessed by an independent assessor. The assessor can be different to the one who initially raised the exception

B.  

The exception must be re-assessed by the same independent assessor that raised the exception

C.  

The first line of defense can confirm their level of compliance using a self-assessment approach

D.  

None, if the remediation has been completed, a new attestation can be submitted reflecting the compliance of the control

Discussion 0
Questions 16

Which of the following statements best describe valid implementations when implementing control 2.9 Transaction Business Controls? (Choose all that apply.)

Options:

A.  

Multiple measures must be implemented by the Swift user to validate the flows of transactions are in the bounds of the normal expected business

B.  

A customer designed implementation or a combination of different measures are deemed valid if they sufficiently mitigate the control risks

C.  

Reliance on a recent business assessment or regulator response confirming the effectiveness of the control (as an example CPMI's_ requirement) is especially poignant to this control

D.  

Any solutions is acceptable so long as the CISO approves the implementation

Discussion 0
Questions 17

A Treasury Management System (TMS) application is installed on the same machine as the customer connector, connecting to a Service Bureau. Are these applications/systems in scope of CSCF? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

The TMS application, the customer connector, and the hosting system are in the scope of the CSCF

B.  

Only the customer connector application is in scope of the CSCF. The TMS application is a back-office

C.  

The TMS application is the highest risk and must be secured appropriately. The customer connector should be secured on a best effort basis

D.  

The TMS application, the customer connector, and the hosting system are in scope only if they connect directly to SWIFT, not towards a Service Bureau

Discussion 0
Questions 18

The Swift HSM boxes:

Options:

A.  

Are located at the network partner premises and managed by Swift

B.  

Are located at the Swift user premises and managed by Swift

C.  

Are located at the Swift user premises and managed by the Swift user

D.  

Are located at the network partner premises and managed by Swift the network partner

Discussion 0
Questions 19

A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server What architecture type is the Swift user? (Choose all that apply.)

Options:

A.  

A1

B.  

B

C.  

A3

D.  

A4

Discussion 0
Questions 20

Select the correct statement(s) about the Swift Alliance Gateway. (Choose all that apply.)

Options:

A.  

It acts as the single window to SwiftNet messaging services byconcentratingyour traffic flows

B.  

It allows sharing of PKI profiles between application or individuals, through the use of virtual profiles

C.  

It allows the creation and/or modification of some Swift messages (depending on the types &/or formats)

D.  

The Alliance Gateway can only be accessed by a SWIFTNet user

Discussion 0
Questions 21

The only type of HSM devices offered by Swift are HSM tokens and HSM boxes.

Options:

A.  

TRUE

B.  

FALSE

Discussion 0
Questions 22

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.  

TRUE

B.  

FALSE

Discussion 0
Questions 23

Where is the implementation of multi-factor authentication deemed sufficient to support control 4.2 compliance? (Choose all that apply.)

Options:

A.  

When accessing an outsourcing agent or an L2BA Swift-related application

B.  

When logging-in on an interface, a connector, or the system running such component

C.  

When login on the jump server filtering access to local Swift secure zone

D.  

On the General Operator PC used to access a Swift-related component

Discussion 0
Questions 24

Is it mandated to perform security awareness and other specific trainings every year for individuals with SWIFT-critical roles? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.  

Yes, and a track record must show that both awareness and specific training are performed annually

B.  

No, both awareness and specific trainings are planned when deemed required

C.  

No, awareness training expected to be performed yearly; specific training to maintain the required knowledge only when needed

D.  

No, a track record must show that both awareness and specific training are performed at least bi-yearly (every 2 years)

Discussion 0
Questions 25

Which statement(s) is/are correct about the LSO/RSO accounts on a Swift Alliance Access? (Choose all that apply.)

Options:

A.  

They are local Security Officers

B.  

Their PKI certificates are stored either on a HSM Token or on a HSM-box

C.  

They are the business profiles that can sign the Swift financial transactions

D.  

They are responsible for the configuration and management of the security functions of the server

Discussion 0
Questions 26

What is the purpose of the High-Level Test Plan (HLTP) provided by SWIFT? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

The HLTP provides a way of testing and the typical evidence for each control (based on implementation guidelines) and must be strictly followed

B.  

The HLTP provides a way of testing and the typical evidence for each control (based on implementation guidelines), testing should be ideally based on it

C.  

The HLTP provides the rules to define the sample for testing

D.  

The HLTP provides a detailed way of control testing

Discussion 0
Questions 27

The Alliance Gateway application is considered a messaging interface.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.  

TRUE

B.  

FALSE

Discussion 0
Questions 28

As a Swift CSP Certified Assessor, I left the listed provider and started to work independently. Can I continue to perform CSP assessments?

Options:

A.  

Yes. during the certification validity period

B.  

No, this is not allowed

C.  

Yes. but not as a Swift CSP Certified assessor

D.  

[No, except if Swift formally provides you permission

Discussion 0
Questions 29

Select the correct statement about Alliance Gateway.

Options:

A.  

It is used to exchange messages over the Swift network

B.  

It is used to create messages to send over the Swift network

Discussion 0
Questions 30

The control SWIFT Environment Protection supports several objectives. (Select the one that does not apply)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

Restrict malicious access from external sources

B.  

Forbids any interactive sessions towards the SWIFT infrastructure

C.  

Limit risks of privileged accounts compromise

D.  

Limit risks of lateral movement

Discussion 0
Questions 31

Can an internal audit department submit and approve their Swift user's attestation on the KYC-SA Swift portal?

Options:

A.  

Yes, providing this is agreed by the head of IT operations and the CISO

B.  

No, this is never an option

C.  

Yes, an internal auditor can submit the attestation for approval provided they have the appropriate credentials for switt.com. The CISO remains in charge of the approval of the attestation

D.  

Yes, with approval from the Chief auditor

Discussion 0
Questions 32

Which statements are true of Alliance Messaging Hub (AMH)? (Select the correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.  

AMH is highly resilient, and can consist of multiple instances and sites in parallel

B.  

AMH provides advanced integration capabilities

C.  

AMH is a messaging interface able to connect to other financial networks, not only SWIFT

D.  

All of the above

Discussion 0
Questions 33

Which statements are correct about the Alliance Access LSO and RSO? (Select the two correct answers that apply)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.  

They are Alliance Security Officers

B.  

Their PKI certificates are stored either on an HSM Token or on an HSM-box

C.  

They are the business profiles that can sign the SWIFT financial transactions

D.  

They are responsible for the configuration and management of the security functions in the messaging interface

Discussion 0
Questions 34

For which reasons (as per the "CSP Independent Assessment Process for Assessors Guidelines") is it required to keep minutes of all key meetings related to a CSP assessment process (examples: kick-off, scope definition, exit meeting)? (Select all answers that apply)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.  

To support quality review (audit) processes

B.  

For documentation purpose

C.  

To keep key information that can be used as input for the next step in the assessment process

D.  

To be uploaded in KYC-SA at the end of the assessment (mandated by SWIFT)

Discussion 0