[Feb-2025] Download Real CSP-Assessor Exam Dumps for candidates. 100% Free Dump Files
Prepare Important Exam with CSP-Assessor Exam Dumps(2025)
NEW QUESTION # 22
Select the supporting documents to conduct a CSP assessment. (Choose all that apply.)
- A. The CSP User Handbook
- B. The Controls Matrix and High Level Test P an
- C. The Customer Security Controls Framework
- D. The mapping to industry standards article
Answer: C
NEW QUESTION # 23
Which operator session flows are expected to be protected in terms of confidentiality and integrity? (Choose all that apply.)
- A. System administrator sessions towards a host running a Swift related component
- B. All sessions to and from a jump server used to access a component in a secure zone
- C. All sessions towards a secure zone (on-premises or hosted by a third-party or a Cloud Provider)
- D. All sessions towards a Swift related application run by an Outsourcing Agent, a Service Bureau or an L2BA Provider
Answer: A,B,C,D
NEW QUESTION # 24
Is the restriction of Internet access only relevant when having Swift-related components in a secure zone?
- A. No, because there can be in-scope general operator PCs used to access a Swift-related application hosted at a service provider
- B. Yes, because if there is no secure zone then the internet connectivity does not need to be restricted
Answer: A
NEW QUESTION # 25
What is expected regarding Token Management when (physical or software-based) tokens are used? (Choose all that apply.)
- A. All tokens must be stored in a safe when not used
- B. Have in place a strict token assignment process. This avoids the need to perform g a regular review of assigned tokens
- C. Similar to user accounts, individual assignment and ownership for accurate traceability and revocation in case of potential tampering, loss or in case of user role change
- D. Individuals must not share their tokens. Tokens must remain under the control and supervision of its owner
Answer: C,D
NEW QUESTION # 26
A Swift user has moved from one Service Bureau to another What are the obligations of the Swift user in the CSP context?
- A. None if there is no impact in the architecture tope
- B. To submit an updated attestation reflecting this change within 3 months
- C. To reflect that in the next attestation cycle
- D. To inform the SB certification office at Swift WW
Answer: B
NEW QUESTION # 27
Application Hardening basically applies the following principles. (Choose all that apply.)
- A. Enhanced Straight Through Processing
- B. Least Privileges
- C. Access on a need to have
- D. Reduced footprint for less potential vulnerabilities
Answer: B,C,D
NEW QUESTION # 28
Can an assessor re-use an ISAE 3000 report dating back 2 years to support an independent assessment?
- A. No, the SAE 3000 report is no valid surrogate as a rule
- B. No, that is too old, the maximum is 18 months
- C. Yes, provided there is no change to the Swift user's infrastructure
- D. Yes, there is no time limit for an iSAE 3000 report
Answer: B
NEW QUESTION # 29
Which authentication methods are possible on the Alliance Interfaces? (Choose all that apply.)
- A. Radius One-time password
- B. Password
- C. Password and TOTP
- D. LDAP Authentication
Answer: A,B,C,D
NEW QUESTION # 30
The objective of the Customer Environment Protection control is to separate the user's Swift infrastructure which restricts malicious access from the external world and from the General IT environment of the Swift user.
- A. FALSE
- B. TRUE
Answer: B
NEW QUESTION # 31
What are the conditions required to permit reliance on the compliance conclusion of a control assessed in the previous year? (Choose all that apply.)
- A. The control-design and implementation are the same
- B. The previous assessment was performed on the (correct) CSCF version of the previous year
- C. The control compliance conclusion must have already been relied on the past two years
- D. The control definition has not changed
Answer: A,B,D
NEW QUESTION # 32
Select the correct statement about Alliance Gateway.
- A. It is used to exchange messages over the Swift network
- B. It is used to create messages to send over the Swift network
Answer: A
NEW QUESTION # 33
The Swift user has an sFTP server to push files to an outsourcing agent hosting the Swift users own Communication interface. What is their architecture type?
- A. A4
- B. A3
- C. A1
- D. B
Answer: D
NEW QUESTION # 34
A Treasury Management System (TMS) application is installed on the same machine as the customer connector (such as MQ server) connecting towards a Service Bureau Are these applications/systems in scope of CSCF?
- A. Only the MO server application is in scope of the CSCF> The TMS application is considered as back-office
- B. The TMS application, the MQ server and hosting system enters the scope of the CSCF advisory and should be placed in a secure zone
- C. The TMS application is the highest risk and must be secured appropriately. The MQ server should be secured on a best effort basis
- D. The TMS application, the MQ server and hosting system are in the scope of the CSCF and must be placed in a secure zone
Answer: D
NEW QUESTION # 35
A Swift user can only exchange FIN messages via the Swift network.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION # 36
A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server What architecture type is the Swift user? (Choose all that apply.)
- A. A3
- B. A4
- C. A1
- D. B
Answer: A,D
NEW QUESTION # 37
Must all CSCF controls be subject to an assessment?
- A. No, only the attested controls (with as a minimum the mandatory ones]
- B. Yes
- C. No, only the mandatory controls
- D. No, the control selection is defined between the Swift User and their assessor
Answer: C
NEW QUESTION # 38
What does the CSCF expect in terms of Database Integrity? (Choose all that apply.)
- A. Nothing is needed when the messaging or connector integrates/embeds an integrity check functionality at each Swift transaction record level.
- B. When a database is used by a messaging interface or connector, the related hosted database and its supporting system must be protected as a Swift-related component and exceptions alerted
- C. Alerts generated from performed integrity checks are captured and analysed for appropriate treatment
Answer: B,C
NEW QUESTION # 39
Must Swift users submit a copy of their final assessment report to Swift?
- A. No, it is not required to provide Swift with any documents by default. However, Swift can request a copy of the Assessment completion letter
- B. Yes, in cases where a customer performs an Independent assessment rather than an audit then a copy of the assessment report must be provided. However, it is not required for the Swift user to provide any forms when an Internal/External Audit is performed
- C. Yes, a copy of (only) the assessment report must be provided to Swift, no other documents
- D. Yes, all documents produced from the assessment must be provided proactively to Swift
Answer: A
NEW QUESTION # 40
......
CSP-Assessor Questions - Truly Beneficial For Your Swift Exam: https://pdftorrent.actual4test.com/CSP-Assessor_examcollection.html