あなたを合格させるCSP-Assessorお手軽に試験合格リアルCSP-Assessor練習問題集で更新されたのは2025年05月31日 [Q70-Q88]

Share

あなたを合格させるCSP-Assessorお手軽に試験合格リアルCSP-Assessor練習問題集で更新されたのは2025年05月31日

2025年最新の実際に出ると確認されたで無料Swift CSP-Assessor試験問題


Swift CSP-Assessor 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Swift 顧客セキュリティ プログラムの理解: このドメインは、Swift の運用に携わるコンプライアンス担当者とリスク マネージャーを対象としています。候補者の CSP 管理フレームワークの理解度と、顧客セキュリティ管理フレームワーク (CSCF) に概説されている適切なアーキテクチャ タイプと関連範囲を決定する能力を評価します。
トピック 2
  • 方法論と評価の成果物の理解: このセクションは、Swift システムを扱う独立監査人向けに設計されています。CSP 評価を実施する際の評価者の役割と義務に関する候補者の理解度をテストします。このセクションでは、評価プロセス中に考慮すべき重要な要素に関する知識を評価します。
トピック 3
  • Swift の理解: 試験のこのセクションでは、Swift ネットワーク管理者のスキルを測定し、Swift ネットワークとそのインフラストラクチャの構造と運用など、国際金融コミュニティにおける Swift の重要な役割をカバーします。

 

質問 # 70
What does the CSCF expect in terms of Database Integrity? (Select the two correct answers that apply)
*Swift Customer Security Controls Policy
*Swift Customer Security Controls Framework v2025
*Independent Assessment Framework
*Independent Assessment Process for Assessors Guidelines
*Independent Assessment Framework - High-Level Test Plan Guidelines
*Outsourcing Agents - Security Requirements Baseline v2025
*CSP Architecture Type - Decision tree
*CSP_controls_matrix_and_high_test_plan_2025
*Assessment template for Mandatory controls
*Assessment template for Advisory controls

  • A. Alerts generated from performed integrity checks are captured and analyzed for appropriate treatment
  • B. Nothing is further expected when the messaging interface or connector integrates/embeds an integrity check functionality at each SWIFT transaction record level
  • C. When a database is used by a messaging interface or connector, the related hosted database and its supporting system is expected to be protected as a SWIFT-related component, the identified exceptions alerted and followed-up

正解:A、C

解説:
CSCF Control "3.1 Database Integrity" focuses on ensuring the integrity of databases used by SWIFT-related components. Let's evaluate each option:
*Option A: Nothing is further expected when the messaging interface or connector integrates/embeds an integrity check functionality at each SWIFT transaction record level This is incorrect as a sole expectation. While embedding integrity checks (e.g., checksums or hashes) in a messaging interface or connector is a valid measure, the CSCF expects additional protections for the database itself, not just reliance on application-level checks. The "Swift Customer Security Controls Framework v2025" requires broader database security.
*Option B: When a database is used by a messaging interface or connector, the related hosted database and its supporting system is expected to be protected as a SWIFT-related component, the identified exceptions alerted and followed-up This is correct. Control 3.1 mandates that databases supporting SWIFT components (e.g., storing transaction data for Alliance Access) be protected as in-scope components. This includes securing the database and its system (e.g., via access controls, encryption) and addressing integrity exceptions through alerts and follow-up, as detailed in the "Assessment template for Mandatory controls."
*Option C: Alerts generated from performed integrity checks are captured and analyzed for appropriate treatment This is correct. The CSCF expects institutions to monitor database integrity (e.g., via logging) and analyze alerts to detect and respond to anomalies, aligning with Control "3.1" and "5.1 Operational Incident Response." The "CSP_controls_matrix_and_high_test_plan_2025" includes this as a compliance criterion.
Summary of Correct Answers:
The CSCF expects the database and its system to be protected with alerts and follow-up (B) and alerts to be captured and analyzed (C).
References to SWIFT Customer Security Programme Documents:
*Swift Customer Security Controls Framework v2025: Control 3.1 defines database integrity requirements.
*Assessment template for Mandatory controls: Includes protection and alert management.
*CSP_controls_matrix_and_high_test_plan_2025: Tests database integrity measures.
========


質問 # 71
Select the correct statement(s).

  • A. The decryption operation uses the encryption private key of the receiver
  • B. To verify the signature the SwiftNetLink uses the signing private key of the receiver
  • C. The public and private keys of a Swift certificate are stored on the Hardware Security Module
  • D. The certificate stored on the Swift Hardware Security Module is used during the decryption operation of a message

正解:A、C


質問 # 72
The Swift user has an sFTP server to push files to an outsourcing agent hosting the Swift users own Communication interface. What is their architecture type?

  • A. A3
  • B. B
  • C. A1
  • D. A4

正解:B


質問 # 73
How can PKI certificate requests be submitted to SWIFT? (Select the correct answer)
*Connectivity
*Generic
*Products Cloud
*Products OnPrem
*Security

  • A. Using an offline method
  • B. Using both online and offline methods
  • C. Using an online method
  • D. None of the above

正解:B

解説:
SWIFT PKI certificates are critical for securing communications and require a formal request process to SWIFT for issuance or renewal. Let's evaluate each option:
*Option A: Using both online and offline methods
This is correct. SWIFT provides multiple channels for submitting PKI certificate requests to accommodate different customer needs and security requirements. The online method involves submitting requests through the SWIFT Alliance Web Platform or SWIFT's customer portal, where users can generate and upload certificate signing requests (CSRs). The offline method involves physical submission, such as sending a signed request via secure mail or courier, often used for initial setups or high-security environments. SWIFT documentation confirms both methods are supported, aligning with CSCF Control "1.3 Cryptographic Failover" for secure certificate management.
*Option B: Using an online method
This is incorrect as a standalone answer. While the online method is available and widely used, it is not the only method. Excluding the offline option does not reflect SWIFT's flexible process.
*Option C: Using an offline method
This is incorrect as a standalone answer. The offline method is an option, but it is not the only method.
SWIFT supports both approaches depending on the customer's infrastructure and security policies.
*Option D: None of the above
This is incorrect. Both online and offline methods are valid, making this option invalid.
Summary of Correct answer:
PKI certificate requests can be submitted to SWIFT using both online and offline methods (A), providing flexibility and security.
References to SWIFT Customer Security Programme Documents:
*SWIFT Customer Security Controls Framework (CSCF) v2024: Control 1.3 supports secure certificate request processes.
*SWIFT PKI Management Guide: Details online and offline submission methods for certificate requests.
*SWIFT Alliance Documentation: Confirms dual submission channels for PKI certificates.


質問 # 74
As a Swift CSP Certified Assessor. Swift contacted me to provide evidence on an assessment I have performed. This is required to support their quality assurance validation process. Is it allowed?

  • A. No, it's confidential
  • B. Yes, one of the obligations of the certification programme is that quality assessment can be performed by Swift

正解:B

解説:
This question addresses the obligations of a Swift CSP Certified Assessor regarding the provision of evidence to Swift for quality assurance purposes.
Step 1: Understand the Role of a Swift CSP Certified Assessor
A Swift CSP Certified Assessor is an independent professional or entity authorized to conduct CSP assessments under theIndependent Assessment Framework. The certification program, managed by Swift, includes specific obligations to ensure the integrity and quality of assessments.
Step 2: Analyze the Request for Evidence
* Swift has contacted the assessor to provide evidence from an assessment to support their quality assurance validation process. This request implies a review of the assessor's work to ensure compliance with CSP standards.
* TheSwift CSP Assessor Certification Program Guidelinesstate that certified assessors are obligated to cooperate with Swift's quality assurance processes. This includes providingevidence (e.g., assessment reports, workpapers) upon request to verify the accuracy and adherence to methodology, as part of Swift's oversight.
* Confidentiality is a concern, but theCSCF v2024andAssessor Certification Programclarify that assessors must share evidence with Swift under a non-disclosure agreement (NDA) or similar confidentiality framework, ensuring data protection while allowing validation.
Step 3: Evaluate Each Option
* A. Yes, one of the obligations of the certification programme is that quality assessment can be performed by SwiftTheSwift CSP Assessor Certification Program Guidelinesexplicitly outline that Swift may conduct quality assessments, and assessors must provide evidence to support this process.
This is a contractual obligation of certification, aligning with Swift's responsibility to maintain CSP integrity.Conclusion: This is correct.
* B. No, it's confidentialWhile confidentiality is critical (protected underControl 2.3: System Access Controland Swift's privacy policies), the certification program requires assessors to share evidence with Swift for quality assurance, subject to confidentiality agreements. Refusing to provide evidence would breach the assessor's obligations.Conclusion: This is incorrect.
Step 4: Conclusion and Verification
The answer isA, as theSwift CSP Assessor Certification Programmandates that certified assessors must support Swift's quality assurance validation by providing evidence, balancing confidentiality with compliance oversight.
References
* Swift Customer Security Controls Framework (CSCF) v2024, Control 2.3: System Access Control.
* Swift CSP Assessor Certification Program Guidelines, Section: Obligations and Quality Assurance.
* Swift Independent Assessment Framework, Section: Assessor Responsibilities.


質問 # 75
May an assessor approve a SWIFT User's KYC-SA attestation? (Select the correct answer)
*Swift Customer Security Controls Policy
*Swift Customer Security Controls Framework v2025
*Independent Assessment Framework
*Independent Assessment Process for Assessors Guidelines
*Independent Assessment Framework - High-Level Test Plan Guidelines
*Outsourcing Agents - Security Requirements Baseline v2025
*CSP Architecture Type - Decision tree
*CSP_controls_matrix_and_high_test_plan_2025
*Assessment template for Mandatory controls
*Assessment template for Advisory controls
*CSCF Assessment Completion Letter
*Swift_CSP_Assessment_Report_Template

  • A. Yes, if the KYC-SA application is set up in 2-eyes mode, it is possible for the assessor to submit and approve an attestation on behalf of the SWIFT user's
  • B. No, it is the responsibility of the SWIFT user's internal audit to submit a CSP attestation
  • C. Yes, with agreement from the CISO of the SWIFT User
  • D. No, the approval always remains the responsibility of the CISO of the SWIFT User (or similar level of responsibility)

正解:D

解説:
The "Independent Assessment Process for Assessors Guidelines" and "Independent Assessment Framework" define the roles of assessors and SWIFT users in the KYC-SA (Know Your Customer - Security Attestation) process. Let's evaluate each option:
*Option A: Yes, if the KYC-SA application is set up in 2-eyes mode, it is possible for the assessor to submit and approve an attestation on behalf of the SWIFT user's This is incorrect. The 2-eyes mode (dual approval) applies to the user's internal process, not the assessor's role. The assessor conducts the assessment and provides a report, but the submission and approval of the attestation on the KYC-SA portal are the user's responsibility, typically by the CISO or an authorized officer.
*Option B: Yes, with agreement from the CISO of the SWIFT User
This is incorrect. CISO agreement does not authorize the assessor to approve the attestation; the CSP reserves this authority for the user.
*Option C: No, the approval always remains the responsibility of the CISO of the SWIFT User (or similar level of responsibility) This is correct. The "Swift_CSP_Assessment_Report_Template" and "CSCF Assessment Completion Letter" indicate that the assessor provides an independent evaluation, but the final approval and submission of the attestation on KYC-SA are the responsibility of the SWIFT user's CISO or an equivalent senior officer, as per the "Independent Assessment Process for Assessors Guidelines."
*Option D: No, it is the responsibility of the SWIFT user's internal audit to submit a CSP attestation This is incorrect. Internal audit cannot submit or approve attestations due to the independence requirement; this role belongs to the CISO or designated user representative.
Summary of Correct answer:
The assessor cannot approve the attestation; this responsibility lies with the CISO or similar user officer (C).
References to SWIFT Customer Security Programme Documents:
*Independent Assessment Process for Assessors Guidelines: Defines assessor and user roles.
*Independent Assessment Framework: Specifies user responsibility for attestation approval.
*Swift_CSP_Assessment_Report_Template: Outlines the assessment process.
========


質問 # 76
The outsourcing agent of the SWIFT user provided them with an independent assessment report covering the CSP components in their scope, and using the latest CSCF version for testing. Is it enough to support the CSP attestation for the outsourced components? (Select the correct answer)
*Swift Customer Security Controls Policy
*Swift Customer Security Controls Framework v2025
*Independent Assessment Framework
*Independent Assessment Process for Assessors Guidelines
*Independent Assessment Framework - High-Level Test Plan Guidelines
*Outsourcing Agents - Security Requirements Baseline v2025
*CSP Architecture Type - Decision tree
*CSP_controls_matrix_and_high_test_plan_2025
*Assessment template for Mandatory controls
*Assessment template for Advisory controls
*CSCF Assessment Completion Letter
*Swift_CSP_Assessment_Report_Template

  • A. Yes, after confirmation and validation of the scope
  • B. Yes, only if the outsourcing agent is a global trusted provider and published the report on their compliance portal
  • C. No, an audit report (and not an assessment) is required from the outsourcing agent as an external provider
  • D. No, except if the cloud provider components are partially covered by the SWIFT Alliance Connect Virtual programme

正解:A

解説:
The "Outsourcing Agents - Security Requirements Baseline v2025" and "Independent Assessment Framework" address reliance on outsourcing agents' assessments. Let's evaluate each option:
*Option A: Yes, after confirmation and validation of the scope
This is correct. The SWIFT user can rely on the outsourcing agent's independent assessment report if it covers the relevant CSP components and uses the latest CSCF version. However, the user's assessor must confirm and validate the scope and findings to ensure alignment with the user's attestation, as per the "Independent Assessment Process for Assessors Guidelines."
*Option B: Yes, only if the outsourcing agent is a global trusted provider and published the report on their compliance portal This is incorrect. The CSP does not require the outsourcing agent to be a "global trusted provider" or publish the report publicly; validation by the user's assessor is sufficient.
*Option C: No, an audit report (and not an assessment) is required from the outsourcing agent as an external provider This is incorrect. An independent assessment report is acceptable, not necessarily an audit report, as long as it meets CSCF standards, per the "Outsourcing Agents - Security Requirements Baseline v2025."
*Option D: No, except if the cloud provider components are partially covered by the SWIFT Alliance Connect Virtual programme This is incorrect. The Alliance Connect Virtual programme's coverage is irrelevant; the key is the report's validity and scope validation.
Summary of Correct answer:
The report is sufficient after confirmation and validation of the scope (A).
References to SWIFT Customer Security Programme Documents:
*Outsourcing Agents - Security Requirements Baseline v2025: Allows reliance on agent assessments.
*Independent Assessment Process for Assessors Guidelines: Requires scope validation.
*Swift_CSP_Assessment_Report_Template: Supports integrated reporting.
========


質問 # 77
A Swift user uses an application integrating a sFTP client to push files to a service bureau sFTP server What architecture type is the Swift user? (Choose all that apply.)

  • A. B
  • B. A3
  • C. A1
  • D. A4

正解:A、B


質問 # 78
Which ones are Alliance Lite2 key components? (Choose all that apply.)

  • A. A HSM box
  • B. A WebSphere MQ Server
  • C. A web interface
  • D. An AutoClient

正解:A、C、D


質問 # 79
Must Swift users submit a copy of their final assessment report to Swift?

  • A. Yes, in cases where a customer performs an Independent assessment rather than an audit then a copy of the assessment report must be provided. However, it is not required for the Swift user to provide any forms when an Internal/External Audit is performed
  • B. Yes, all documents produced from the assessment must be provided proactively to Swift
  • C. Yes, a copy of (only) the assessment report must be provided to Swift, no other documents
  • D. No, it is not required to provide Swift with any documents by default. However, Swift can request a copy of the Assessment completion letter

正解:D


質問 # 80
Which of the following infrastructures has the smallest SWIFT footprint? (Select the correct answer)
*Connectivity
*Generic
*Products Cloud
*Products OnPrem
*Security

  • A. A user with a Messaging Interface behind a Service Bureau
  • B. Lite 2 or Alliance Cloud
  • C. Full stack of products up to the Messaging Interface
  • D. Alliance Remote Gateway

正解:B

解説:
The "SWIFT footprint" refers to the extent of SWIFT-related infrastructure (hardware, software, and connectivity components) that a user must manage within their environment. A smaller footprint means less local infrastructure to maintain, typically achieved through cloud-based or managed services. Let's evaluate each option:
*Option A: Full stack of products up to the Messaging Interface
This refers to an on-premises deployment where the user manages a complete set of SWIFT components, including the messaging interface (e.g., Alliance Access), communication interface (e.g., Alliance Gateway), SwiftNet Link (SNL), HSM, and VPN boxes for connectivity to the SWIFT network. This setup requires significant local infrastructure, including servers, security devices, and network components, resulting in a large SWIFT footprint.
*Option B: Alliance Remote Gateway
Alliance Remote Gateway (ARG) is a service where the Alliance Gateway is hosted remotely by SWIFT or a third party, but the user still maintains a messaging interface (e.g., Alliance Access) locally. While this reduces the footprint slightly by outsourcing the communication interface, the user still manages the messaging interface, HSM, and local connectivity components, resulting in a moderate footprint.
*Option C: Lite 2 or Alliance Cloud
This is the correct answer. Alliance Lite2 and Alliance Cloud are cloud-based solutions designed for smaller institutions or those seeking a minimal local footprint. In Alliance Lite2, the user connects to SWIFT via a lightweight client (Alliance Lite2 AutoClient) or a browser-based interface, with most infrastructure (e.g., messaging interface, communication interface, HSM) hosted by SWIFT in the cloud. Alliance Cloud similarly hosts the full SWIFT stack (including Alliance Access and Alliance Gateway) in a SWIFT-managed cloud environment, requiring only minimal local infrastructure (e.g., a secure connection to the cloud). This results in the smallest SWIFT footprint, as the user manages very little on-premises infrastructure. The CSCF still applies, but many controls are managed by SWIFT (e.g., "1.1 SWIFT Environment Protection").
*Option D: A user with a Messaging Interface behind a Service Bureau
A Service Bureau is a third-party provider that hosts SWIFT infrastructure (e.g., Alliance Gateway, SNL) for multiple users, but the user still maintains a local messaging interface (e.g., Alliance Access) to connect to the Service Bureau. This setup reduces the footprint compared to a full on-premises deployment, as the user does not manage the communication interface or network connectivity components. However, the local messaging interface and associated security components (e.g., HSM) still constitute a larger footprint than a fully cloud- based solution like Alliance Lite2 or Alliance Cloud.
Summary of Correct answer:
Alliance Lite2 or Alliance Cloud (C) has the smallest SWIFT footprint, as most infrastructure is hosted in the cloud by SWIFT, minimizing the user's local management responsibilities.
References to SWIFT Customer Security Programme Documents:
*SWIFT Customer Security Controls Framework (CSCF) v2024: Control 1.1 applies to cloud deployments like Alliance Cloud, reducing the user's local footprint.
*SWIFT Alliance Lite2 Documentation: Describes the minimal infrastructure required for Lite2 users.
*SWIFT Alliance Cloud Documentation: Highlights the fully hosted nature of the solution, minimizing the SWIFT footprint.
========


質問 # 81
Which statements are true of Alliance Messaging Hub (AMH)? (Select the correct answer)
*Connectivity
*Generic
*Products Cloud
*Products OnPrem
*Security

  • A. AMH is a messaging interface able to connect to other financial networks, not only SWIFT
  • B. All of the above
  • C. AMH is highly resilient, and can consist of multiple instances and sites in parallel
  • D. AMH provides advanced integration capabilities

正解:B

解説:
Alliance Messaging Hub (AMH) is a SWIFT product designed as a centralized messaging platform for financial institutions, enabling them to manage multiple messaging flows, including SWIFT and non-SWIFT networks. Let's evaluate each statement:
*Statement A: AMH is highly resilient, and can consist of multiple instances and sites in parallel This is true. AMH is designed for high availability and resilience, supporting deployments across multiple instances and sites to ensure continuity of operations. This capability is critical for large financial institutions handling high volumes of transactions. SWIFT documentation highlights AMH's ability to operate in a distributed architecture, with instances running in parallel across primary and backup sites. This aligns with CSCF Control "1.1 SWIFT Environment Protection," which emphasizes the need for resilient infrastructure to prevent disruptions in the SWIFT environment.
*Statement B: AMH provides advanced integration capabilities
This is true. AMH offers advanced integration features, allowing institutions to connect various back-office systems, payment engines, and other financial applications to a single hub. It supports multiple message standards (e.g., SWIFT MT, ISO 20022) and provides transformation and routing capabilities, making it a versatile integration platform. This is a key selling point of AMH, as noted in SWIFT's product documentation, enabling seamless interoperability across diverse systems.
*Statement C: AMH is a messaging interface able to connect to other financial networks, not only SWIFT This is true. AMH is not limited to SWIFT messaging; it can connect to other financial networks, such as domestic payment systems, real-time gross settlement (RTGS) systems, or proprietary networks. AMH acts as a universal messaging hub, supporting multiple protocols and standards beyond SWIFT's ecosystem (e.g., FIX for securities trading). This capability is well-documented in SWIFT's AMH product overview, positioning it as a flexible solution for institutions with diverse connectivity needs.
*Statement D: All of the above
Since all three statements (A, B, and C) are true, this option is the correct answer. AMH's design for resilience, advanced integration, and multi-network connectivity makes it a comprehensive messaging solution.
Summary of Correct answer:
All statements about AMH are true, making "All of the above" (D) the correct choice.
References to SWIFT Customer Security Programme Documents:
*SWIFT Customer Security Controls Framework (CSCF) v2024: Control 1.1 emphasizes resilience, which AMH supports through its architecture.
*SWIFT Alliance Messaging Hub Documentation: Highlights AMH's multi-site resilience, integration capabilities, and support for non-SWIFT networks.
*SWIFT Product Overview: Describes AMH as a universal messaging hub for SWIFT and other financial networks.
========


質問 # 82
The SWIFT VPN boxes are located between the Messaging and Communication interface.
*Connectivity
*Generic
*Products Cloud
*Products OnPrem
*Security

  • A. TRUE
  • B. FALSE

正解:B

解説:
In the SWIFT architecture, VPN boxes (e.g., Alliance Connect boxes or virtual VPN appliances) are network devices that establish a secure connection to the SWIFT Secure IP Network (SIPN) using Virtual Private Network (VPN) technology. Let's evaluate the statement:
*The "Messaging Interface" refers to components like Alliance Access (SAA), which create, process, and manage SWIFT messages (e.g., MT103). The "Communication Interface" refers to components like Alliance Gateway (SAG), which consolidate message flows and connect to the SWIFT network via SwiftNet Link (SNL).
*The SWIFT VPN boxes are located at the network boundary, connecting the customer's internal SWIFT environment (including both messaging and communication interfaces) to the external SIPN. They are not positioned between the messaging interface and the communication interface; instead, they sit outside the SWIFT secure zone, linking the entire local infrastructure to SWIFTNet.
*In a typical deployment, the architecture flows as follows: Messaging Interface (e.g., Alliance Access) # Communication Interface (e.g., Alliance Gateway with SNL) # VPN Boxes # SWIFTNet. The VPN boxes are part of the external connectivity layer, not an intermediary between internal components. This is supported by CSCF Control "1.1 SWIFT Environment Protection," which defines the secure zone as including messaging and communication interfaces, with VPN boxes providing the external link.
*The statement's implication that VPN boxes separate the messaging and communication interfaces is incorrect, as they are part of the broader connectivity infrastructure.
Summary of Correct answer:
The SWIFT VPN boxes are not located between the Messaging and Communication interface; they connect the entire local SWIFT environment to the SIPN, making the statement false.
References to SWIFT Customer Security Programme Documents:
*SWIFT Customer Security Controls Framework (CSCF) v2024: Control 1.1 defines the secure zone and external connectivity via VPN boxes.
*SWIFT Alliance Gateway Documentation: Describes the placement of VPN boxes outside the communication interface.
*SWIFT Network Architecture Guide: Confirms VPN boxes as the external connection point to SIPN.


質問 # 83
The SWIFT user has installed its own Communication Interface on a dedicated virtual machine offered by a public cloud provider. Under which provider category does the public cloud provider fit, and what is the CSP impact? (Select the correct answer)
*Swift Customer Security Controls Policy
*Swift Customer Security Controls Framework v2025
*Independent Assessment Framework
*Independent Assessment Process for Assessors Guidelines
*Independent Assessment Framework - High-Level Test Plan Guidelines
*Outsourcing Agents - Security Requirements Baseline v2025
*CSP Architecture Type - Decision tree
*CSP_controls_matrix_and_high_test_plan_2025
*Assessment template for Mandatory controls
*Assessment template for Advisory controls

  • A. The public cloud provider is considered a SWIFT connectivity provider, and therefore not in scope of the CSP
  • B. This type of implementation is not allowed by the CSP
  • C. The public cloud provider is considered a L2BA provider, and therefore not in scope of the CSP
  • D. The public cloud provider is considered an outsourcing agent, and therefore in scope of the CSP

正解:D

解説:
The "Outsourcing Agents - Security Requirements Baseline v2025" and "Swift Customer Security Controls Framework v2025" define provider categories and CSP impact. Let's evaluate each option:
*Option A: The public cloud provider is considered a L2BA provider, and therefore not in scope of the CSP This is incorrect. An L2BA (Lite2 Business Application) provider hosts the full SWIFT stack for users, but a public cloud provider offering a virtual machine is not an L2BA provider unless it provides the full service.
The CSP still applies to the provider's infrastructure.
*Option B: The public cloud provider is considered a SWIFT connectivity provider, and therefore not in scope of the CSP This is incorrect. A SWIFT connectivity provider (e.g., Alliance Connect) is a specific role, but a public cloud provider (e.g., AWS) hosting a communication interface is an outsourcing agent, subject to CSP requirements.
*Option C: The public cloud provider is considered an outsourcing agent, and therefore in scope of the CSP This is correct. The "Outsourcing Agents - Security Requirements Baseline v2025" classifies public cloud providers hosting SWIFT components (e.g., a virtual machine with Alliance Gateway) as outsourcing agents.
The CSP impacts the provider by requiring them to secure the underlying infrastructure (e.g., Control 1.1), while the user secures the communication interface.
*Option D: This type of implementation is not allowed by the CSP
This is incorrect. The CSP permits cloud-based deployments, including user-installed components on public cloud VMs, as long as security controls are met.
Summary of Correct answer:
The public cloud provider is an outsourcing agent, in scope of the CSP (C).
References to SWIFT Customer Security Programme Documents:
*Outsourcing Agents - Security Requirements Baseline v2025: Defines cloud providers as outsourcing agents.
*Swift Customer Security Controls Framework v2025: Applies controls to outsourced environments.
*CSP_controls_matrix_and_high_test_plan_2025: Includes cloud provider assessments.
========


質問 # 84
The objective of the Customer Environment Protection control is to separate the user's Swift infrastructure which restricts malicious access from the external world and from the General IT environment of the Swift user.

  • A. TRUE
  • B. FALSE

正解:A

解説:
This question relates to the objective of Control 1.1 - SWIFT Environment Protection in the CSCF:
* Step 1: Control 1.1 Overview
* Control 1.1 aims to "restrict access to the SWIFT infrastructure by segregating it from the general IT environment and external threats," protecting against unauthorized access and malware.


質問 # 85
A Swift user has remediated an exception reported by the assessor. What are their obligations before updating and submitting an attestation reflecting the new compliance level?

  • A. None, if the remediation has been completed, a new attestation can be submitted reflecting the compliance of the control
  • B. The exception must be re-assessed by an independent assessor. The assessor can be different to the one who initially raised the exception
  • C. The exception must be re-assessed by the same independent assessor that raised the exception
  • D. The first line of defense can confirm their level of compliance using a self-assessment approach

正解:B


質問 # 86
Alliance Lite2 only supports the sending and receiving of FIN messages.

  • A. TRUE
  • B. FALSE

正解:B

解説:
This question examines the messaging capabilities of Alliance Lite2 under the Swift Customer Security Programme (CSP).
Step 1: Understand Alliance Lite2
Alliance Lite2 is a lightweight Swift solution designed for smaller financial institutions, providing access to Swift messaging services. Its capabilities are detailed in theSwift Alliance Lite2 User Guideand referenced in theCSCF v2024context.
Step 2: Analyze the Statement
The statement claims that Alliance Lite2 "only supports the sending and receiving of FIN messages." FIN messages are part of the FIN service for payment transactions, but Alliance Lite2's scope extends beyond this.
Step 3: Evaluate Against Swift Guidelines
* TheSwift Alliance Lite2 User Guidespecifies that Alliance Lite2 supports multiple message types, including:
* FIN messages(e.g., MT103 for payments).
* FileAct(for file transfers).
* InterAct(for real-time messaging).
* TheCSCF v2024does not restrict Alliance Lite2 to FIN messages; it applies security controls to all supported services. TheSwift CSP FAQconfirms that Alliance Lite2 users must comply with controls for all active services, not just FIN.
* Thus, the statement that it "only supports" FIN messages is false, as it also supports FileAct and InterAct.
Step 4: Conclusion and Verification
The answer isB, as Alliance Lite2 supports more than just FIN messages, including FileAct and InterAct, per theSwift Alliance Lite2 User GuideandCSCF v2024.
References
* Swift Alliance Lite2 User Guide, Section: Supported Services.
* Swift Customer Security Controls Framework (CSCF) v2024, Control 1.1: Swift Environment Protection.
* Swift CSP FAQ, Section: Alliance Lite2 Scope.


質問 # 87
For each of the following setups, the responsible party is identified to protect the virtualization or cloud underlying platform. Which one of the combinations is not correct?
*Swift Customer Security Controls Policy
*Swift Customer Security Controls Framework v2025
*Independent Assessment Framework
*Independent Assessment Process for Assessors Guidelines
*Independent Assessment Framework - High-Level Test Plan Guidelines
*Outsourcing Agents - Security Requirements Baseline v2025
*CSP Architecture Type - Decision tree
*CSP_controls_matrix_and_high_test_plan_2025
*Assessment template for Mandatory controls
*Assessment template for Advisory controls
*CSCF Assessment Completion Letter
*Swift_CSP_Assessment_Report_Template

  • A. For on-premises container platform: by the SWIFT user
  • B. For on-premises virtualization platform: by the platform provider
  • C. For virtualization platform deployed at a third party on which user's SWIFT-related components are virtually hosted: by the third party
  • D. For Cloud Provider: the cloud provider

正解:B

解説:
The CSCF and "Outsourcing Agents - Security Requirements Baseline v2025" define responsibilities for securing virtualization or cloud platforms hosting SWIFT-related components. Let's evaluate each combination:
*Option A: For on-premises virtualization platform: by the platform provider This is not correct. An on-premises virtualization platform (e.g., VMware or Hyper-V hosting Alliance Gateway) is managed by the SWIFT user, not the platform provider (e.g., VMware). The "platform provider" supplies the software, but the user is responsible for securing the on-premises environment, including hardening, patching, and compliance with CSCF Control "2.3 System Hardening."
*Option B: For virtualization platform deployed at a third party on which user's SWIFT-related components are virtually hosted: by the third party This is correct. If the virtualization platform is hosted by a third party (e.g., a service provider hosting SWIFT components), the third party is responsible for securing the platform, as per the "Outsourcing Agents - Security Requirements Baseline v2025" and CSCF Control "1.1."
*Option C: For on-premises container platform: by the SWIFT user
This is correct. An on-premises container platform (e.g., Docker or Kubernetes hosting SWIFT applications) is the user's responsibility to secure, aligning with CSCF Control "1.1" and the user's ownership of on- premises infrastructure.
*Option D: For Cloud Provider: the cloud provider
This is correct. In a cloud model (e.g., IaaS like Alliance Cloud on AWS), the cloud provider (e.g., AWS) is responsible for securing the underlying platform, as outlined in the "Outsourcing Agents - Security Requirements Baseline v2025." Summary of Correct answer:
The combination that is not correct is A, as the SWIFT user, not the platform provider, is responsible for securing an on-premises virtualization platform.
References to SWIFT Customer Security Programme Documents:
*Swift Customer Security Controls Framework v2025: Control 1.1 defines responsibilities for on-premises platforms.
*Outsourcing Agents - Security Requirements Baseline v2025: Specifies third-party and cloud provider responsibilities.
*Independent Assessment Framework: Confirms user responsibility for on-premises setups.


質問 # 88
......

CSP-Assessorリアル試験問題解答は無料:https://www.passtest.jp/Swift/CSP-Assessor-shiken.html

CSP-Assessor試験問題、リアルCSP-Assessor練習問題集:https://drive.google.com/open?id=17mPrpp4GZ6HhJqiMwaKrjQuTtTHBwBWK