Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Customer Security Programme Assessor Certification(CSPAC)

Last Update 4 hours ago Total Questions : 116

The Customer Security Programme Assessor Certification(CSPAC) content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include CSP-Assessor practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CSP-Assessor exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CSP-Assessor sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Customer Security Programme Assessor Certification(CSPAC) practice test comfortably within the allotted time.

Question # 31

May an assessor rely on an ISAE 3000 report dating back 2 years to support a CSP independent assessment? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

• CSCF Assessment Completion Letter

• Swift_CSP_Assessment_Report_Template

A.

No, that is too old, the maximum is 18 months

B.

Yes, there is no time limit for an ISAE 3000 report

C.

No, an ISAE 3000 report is no valid substitute as a rule

D.

Yes, provided there is no change to the SWIFT user’s infrastructure

Question # 32

Select the correct statement(s).

A.

The public and private keys of a Swift certificate are stored on the Hardware Security Module

B.

The certificate stored on the Swift Hardware Security Module is used during the decryption operation of a message

C.

The decryption operation uses the encryption private key of the receiver

D.

To verify the signature the SwiftNetLink uses the signing private key of the receiver

Question # 33

Is it necessary to formally explain to the Swift user the testing methodology that will be used for the CSP assessment during the kick-off?

A.

Yes

B.

No

Question # 34

Is it mandated to perform security awareness and other specific trainings every year for individuals with SWIFT-critical roles? (Select the correct answer)

• Swift Customer Security Controls Policy

• Swift Customer Security Controls Framework v2025

• Independent Assessment Framework

• Independent Assessment Process for Assessors Guidelines

• Independent Assessment Framework - High-Level Test Plan Guidelines

• Outsourcing Agents - Security Requirements Baseline v2025

• CSP Architecture Type - Decision tree

• CSP_controls_matrix_and_high_test_plan_2025

• Assessment template for Mandatory controls

• Assessment template for Advisory controls

A.

Yes, and a track record must show that both awareness and specific training are performed annually

B.

No, both awareness and specific trainings are planned when deemed required

C.

No, awareness training expected to be performed yearly; specific training to maintain the required knowledge only when needed

D.

No, a track record must show that both awareness and specific training are performed at least bi-yearly (every 2 years)

Go to page: