Pass the Swift Customer Security Programme (CSP) CSP-Assessor Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which operator session flows are expected to be protected in terms of confidentiality and integrity? (Choose all that apply.)

Question # 21

Options:

A.

System administrator sessions towards a host running a Swift related component


B.

All sessions to and from a jump server used to access a component in a secure zone


C.

All sessions towards a secure zone (on-premises or hosted by a third-party or a Cloud Provider)


D.

All sessions towards a Swift related application run by an Outsourcing Agent, a Service Bureau or an L2BA Provider


Expert Solution
Questions # 22:

What are the conditions required to allow reliance on the compliance conclusion of a control assessed in the previous year? (Select all answers that apply)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

The control compliance conclusion must have already been relied on the past two years


B.

The previous assessment was performed on the CSCF version of the previous year (at least)


C.

The control definition has not changed


D.

The control design and implementation are the same


Expert Solution
Questions # 23:

A Swift user can only exchange FIN messages via the Swift network.

Question # 23

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 24:

Who can connect to SWIFT? (Select all answers that apply)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

Financial institutions, such as banks and securities broker-dealers


B.

Individuals who use online banking for international transfers


C.

Market infrastructures that provide financial institutions with centralized transaction processing


D.

Corporates that work with multiple banking partners


Expert Solution
Questions # 25:

What is the purpose of the High-Level Test Plan (HLTP) provided by SWIFT? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

The HLTP provides a way of testing and the typical evidence for each control (based on implementation guidelines) and must be strictly followed


B.

The HLTP provides a way of testing and the typical evidence for each control (based on implementation guidelines), testing should be ideally based on it


C.

The HLTP provides the rules to define the sample for testing


D.

The HLTP provides a detailed way of control testing


Expert Solution
Questions # 26:

Which of the following infrastructures has the smallest Swift footprint?

Question # 26

Options:

A.

Full stack of products up to the Messaging Interface


B.

Alliance Remote Gateway


C.

Alliance Lite2


D.

Full stack of products includinq IPLA


Expert Solution
Questions # 27:

Which statements are correct about the Alliance Access LSO and RSO? (Select the two correct answers that apply)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

Options:

A.

They are Alliance Security Officers


B.

Their PKI certificates are stored either on an HSM Token or on an HSM-box


C.

They are the business profiles that can sign the SWIFT financial transactions


D.

They are responsible for the configuration and management of the security functions in the messaging interface


Expert Solution
Questions # 28:

A Treasury Management System (TMS) application is installed on the same machine as the customer connector (such as MQ server) connecting towards a Service Bureau Are these applications/systems in scope of CSCF?

Question # 28

Options:

A.

The TMS application, the MQ server and hosting system are in the scope of the CSCF and must be placed in a secure zone


B.

The TMS application, the MQ server and hosting system enters the scope of the CSCF advisory and should be placed in a secure zone


C.

Only the MO server application is in scope of the CSCF> The TMS application is considered as back-office


D.

The TMS application is the highest risk and must be secured appropriately. The MQ server should be secured on a best effort basis


Expert Solution
Questions # 29:

Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?

Question # 29

Options:

A.

Yes, because if there is no secure zone then the internet connectivity does not need to be restricted


B.

No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider


Expert Solution
Questions # 30:

In the case that nothing has changed in the SWIFT user’s infrastructure, is it possible to rely on a previous Independent assessment report without performing another independent assessment? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes, full reliance can be provided without the need of an independent assessment if nothing has changed


B.

No, even if nothing has changed, an independent assessor needs to assess the conditions before being able to rely on the previous year’s assessment


C.

No, even if nothing has changed, an independent assessor needs to perform a full assessment including full testing every year


D.

Yes, full reliance can be provided if the CISO of the SWIFT user signs a letter which confirms that nothing has changed


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions