Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Customer Security Programme Assessor Certification(CSPAC)

Last Update 4 hours ago Total Questions : 116

The Customer Security Programme Assessor Certification(CSPAC) content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include CSP-Assessor practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CSP-Assessor exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CSP-Assessor sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Customer Security Programme Assessor Certification(CSPAC) practice test comfortably within the allotted time.

Question # 21

Which statement(s) is/are correct about the LSO/RSO accounts on a Swift Alliance Access? (Choose all that apply.)

A.

They are local Security Officers

B.

Their PKI certificates are stored either on a HSM Token or on a HSM-box

C.

They are the business profiles that can sign the Swift financial transactions

D.

They are responsible for the configuration and management of the security functions of the server

Question # 22

Penetration testing must be performed at application level against the Swift-related components, such as the interfaces, Swift and customer connectors?

A.

True, those are key components

B.

False, only the components as defined in Swift Testing Policy

Question # 23

Alliance Lite2 only supports the sending and receiving of FIN messages.

A.

TRUE

B.

FALSE

Question # 24

Select the correct statement about Alliance Gateway.

A.

It is used to exchange messages over the Swift network

B.

It is used to create messages to send over the Swift network

Question # 25

The Swift user would like to perform their CSP assessment in May for the CSCF version that will only be active as from July the same year. Is it allowed?

A.

No, an assessment can only be done on the active version of the CSCF

B.

Yes, the assessment on a particular version can start before the actual activation date

Question # 26

How are online SwiftNet Security Officers authenticated? (Select the correct answer)

• Connectivity

• Generic

• Products Cloud

• Products OnPrem

• Security

A.

Via their PKI certificate

B.

Via their swift.com account and secure code card

C.

Via their swift.com account

Question # 27

A SWIFT user has had part of controls assessed by their internal audit department, and the other remaining controls using an external assessor company. Is this acceptable? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

A.

Yes, a SWIFT user can combine multiple assessment types (internal and external assessment) as long as all controls are covered

B.

No, because the SWIFT user cannot be sure the same approach and quality will be delivered

C.

Yes, but only if there is a signed agreement between all involved assessors

D.

No, SWIFT can reject the attestation in such situations

Question # 28

In the illustration, identify which components are in scope of the CSCF? (Choose all that apply.)

A.

Components A, B, K

B.

Components J, K, I

C.

Components F, G, H

D.

Components C, E, M

Question # 29

Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?

A.

Yes, because if there is no secure zone then the internet connectivity does not need to be restricted

B.

No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider

Question # 30

Select the correct statement(s) about the Swift Alliance Gateway. (Choose all that apply.)

A.

It acts as the single window to SwiftNet messaging services by concentrating your traffic flows

B.

It allows sharing of PKI profiles between application or individuals, through the use of virtual profiles

C.

It allows the creation and/or modification of some Swift messages (depending on the types & /or formats)

D.

The Alliance Gateway can only be accessed by a SWIFTNet user

Go to page: