Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Customer Security Programme Assessor Certification(CSPAC)

Last Update 4 hours ago Total Questions : 116

The Customer Security Programme Assessor Certification(CSPAC) content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include CSP-Assessor practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CSP-Assessor exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CSP-Assessor sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Customer Security Programme Assessor Certification(CSPAC) practice test comfortably within the allotted time.

Question # 11

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

SIL Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

A.

TRUE

B.

FALSE

Question # 12

The cluster of VPN boxes is also called managed-customer premises equipment (M-CPE).

A.

TRUE

B.

FALSE

Question # 13

How many Swift Security Officers does an organization need at minimum?

A.

1

B.

2

C.

3

D.

4

Question # 14

There are open exceptions leading to multiple CSP controls being non-compliant. How should the SWIFT user proceed? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

A.

The user must remediate all the exceptions within 3 months before submitting the CSP attestation in KYC-SA

B.

The SWIFT user may remediate the exceptions and then re-submit an attestation reflecting the new compliance status, but only after compliance validation by the same independent assessor

C.

The SWIFT user may remediate the exceptions and re-submit an updated attestation reflecting the new compliance status but only after compliance validation by an independent assessor

D.

The attestation cannot be submitted before all exceptions are resolved

Question # 15

The objective of the Customer Environment Protection control is to separate the user's Swift infrastructure which restricts malicious access from the external world and from the General IT environment of the Swift user.

A.

TRUE

B.

FALSE

Question # 16

The Swift secure zone is composed of a Swift connector, a middleware server and a back office system Is the selection of only one of the above components a representative sample based on the High-Level Test Plan (HLTP) guidelines?

A.

Yes

B.

No

Question # 17

In the case that nothing has changed in the SWIFT user’s infrastructure, is it possible to rely on a previous Independent assessment report without performing another independent assessment? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

A.

Yes, full reliance can be provided without the need of an independent assessment if nothing has changed

B.

No, even if nothing has changed, an independent assessor needs to assess the conditions before being able to rely on the previous year’s assessment

C.

No, even if nothing has changed, an independent assessor needs to perform a full assessment including full testing every year

D.

Yes, full reliance can be provided if the CISO of the SWIFT user signs a letter which confirms that nothing has changed

Question # 18

What are the three main objectives of the Customer Security Controls Framework? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

A.

1. Secure your environment

2. Know and Limit Access

3. Detect and Respond

B.

1. Restrict Internet Access and Protect Critical Systems from General IT Environment

2. Reduce Attack Surface and Vulnerabilities

3. Physically Secure the Environment

C.

1. Secure and Protect

2. Prevent and Detect

3. Share and Prepare

D.

1. Raise pragmatically the security bar

2. Maintain appropriate cyber-security hygiene

3. React promptly

Question # 19

To rely on a previous CSP assessment report conclusions, a limited testing approach was used. What is the expected sample size as per the High-Level Test Plan (HLTP) guidelines for each identified component? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

A.

There is no need for a sample for this limited testing

B.

1

C.

3

D.

5

Question # 20

Is the control 2. 11 "RMA Business Controls” only about the process of validating the defined counterparty relationships?

A.

Yes

B.

No

Go to page: