Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CSP-Assessor Exam Dumps - Customer Security Programme Assessor Certification(CSPAC)

Go to page:
Question # 25

Who can connect to SWIFT? (Select all answers that apply)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

Financial institutions, such as banks and securities broker-dealers

B.

Individuals who use online banking for international transfers

C.

Market infrastructures that provide financial institutions with centralized transaction processing

D.

Corporates that work with multiple banking partners

Full Access
Question # 26

The Alliance Web Platform Administrator uses both the GUI and command line to perform configuration and monitoring tasks on AWP SE.

A.

TRUE

B.

FALSE

Full Access
Question # 27

Must Swift users submit a copy of their final assessment report to Swift?

A.

Yes, all documents produced from the assessment must be provided proactively to Swift

B.

No, it is not required to provide Swift with any documents by default. However, Swift can request a copy of the Assessment completion letter

C.

Yes, a copy of (only) the assessment report must be provided to Swift, no other documents

D.

Yes, in cases where a customer performs an Independent assessment rather than an audit then a copy of the assessment report must be provided. However, it is not required for the Swift user to provide any forms when an Internal/External Audit is performed

Full Access
Question # 28

A Treasury Management System (TMS) application is installed on the same machine as the customer connector (such as MQ server) connecting towards a Service Bureau Are these applications/systems in scope of CSCF?

A.

The TMS application, the MQ server and hosting system are in the scope of the CSCF and must be placed in a secure zone

B.

The TMS application, the MQ server and hosting system enters the scope of the CSCF advisory and should be placed in a secure zone

C.

Only the MO server application is in scope of the CSCF> The TMS application is considered as back-office

D.

The TMS application is the highest risk and must be secured appropriately. The MQ server should be secured on a best effort basis

Full Access
Question # 29

A detailed CSP assessment report has been provided to the Swift user following the assessment. Is a completion letter also mandated to be supplied?

A.

Yes

B.

No

Full Access
Question # 30

Using the outsourcing agent diagram, which components (including the components in SWIFT user premises) must be placed in a secure zone? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

•Next Service Provider(s)

•SWIFT User

•Outsourcing Agent(s)

•Connector*

•SWIFT

•SWIFT network

A.

Components A, B, and C

B.

All components

C.

Components A, C, D, and E

D.

Components A, C, and D

Full Access
Question # 31

The cluster of VPN boxes is also called managed-customer premises equipment (M-CPE).

A.

TRUE

B.

FALSE

Full Access
Question # 32

The Internal Audit and an external assessment company are both involved in a SWIFT user’s assessment. Both have shared control assessments to cover the full scope (meaning two separate assessment teams). Who needs to provide a completion letter? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

A.

The Internal audit lead assessor and the external company lead assessor

B.

The Internal audit lead assessor only

C.

The External company lead assessor only

D.

None of them, it is not required when an internal department was involved in the assessment

Full Access
Go to page: