Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

In the context of CSP, what type of component is the Alliance Access? (Select the correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

A Messaging Interface

B.

A Communication Interface

C.

A SWIFT Connector

D.

A Secure Server

Which encryption methods are used to secure the communications between the SNL host and HSM boxes?

A.

NTLS and SSH

B.

Telnet and SSL

C.

NTLS and Telnet

D.

MPLS and SSL

In the illustration, identify the component type of each of the numbered components.

A.

1. Customer Connector

2. Bridging Server (Middleware Server)

3. Customer Connector

4. Bridging Server (Middleware Server)

B.

1. Customer Connector

2. Bridging Server (Middleware Server)

3. Customer Connector

4. Customer Connector

C.

1. Bridging Server (Middleware Server)

2. Bridging Server (Middleware Server)

3. Bridging Server (Middleware Server)

4. Bridging Server (Middleware Server)

D.

1. Customer Connector

2. Customer Connector

3. Customer Connector

4. Customer Connector

The Internal Audit and an external assessment company are both involved in a SWIFT user’s assessment. Both have shared control assessments to cover the full scope (meaning two separate assessment teams). Who needs to provide a completion letter? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

A.

The Internal audit lead assessor and the external company lead assessor

B.

The Internal audit lead assessor only

C.

The External company lead assessor only

D.

None of them, it is not required when an internal department was involved in the assessment

Penetration testing must be performed at application level against the Swift-related components, such as the interfaces, Swift and customer connectors?

A.

True, those are key components

B.

False, only the components as defined in Swift Testing Policy

The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.

SIL Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

TRUE

B.

FALSE

What is expected regarding Token Management when (physical or software-based) tokens are used? (Choose all that apply.)

A.

Similar to user accounts, individual assignment and ownership for accurate traceability and revocation in case of potential tampering, loss or in case of user role change

B.

Have in place a strict token assignment process. This avoids the need to perform g a regular review of assigned tokens

C.

Individuals must not share their tokens. Tokens must remain under the control and supervision of its owner

D.

All tokens must be stored in a safe when not used

In a fully on-premises infrastructure, which security management profile is not involved? (Select the one correct answer)

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

Alliance Security Officer (LSO/RSO)

B.

HSM Administrator

C.

swift.com Administrator

D.

Customer Security Officer

As a Swift CSP Certified Assessor. Swift contacted me to provide evidence on an assessment I have performed. This is required to support their quality assurance validation process. Is it allowed?

A.

Yes, one of the obligations of the certification programme is that quality assessment can be performed by Swift

B.

No, it's confidential

The SWIFT VPN boxes are located between the Messaging and Communication interface.

•Connectivity

•Generic

•Products Cloud

•Products OnPrem

•Security

A.

TRUE

B.

FALSE