For Q1, to test security violation, you cannot write to HPSVCR, which sample the signal.
The proper way to test it is write to SecMon_HP Command Register (HPCOMR).
bit 9
SW_FSV
Software Fatal Security Violation
bit 8
SW_SV
Software Security Violation
Please refer to the documentation for how it will affect the SSM_STATE state.
For Q2, what version of LSDK customer is using? They have to follow the LSDK instruction to put the alternate image in the build script (Sample Input File). For LSDK1906, chapter 6.1.1.6 cover that.
If customer still have issues, please provide memory dump for entire SFP and SECMON, scratchRW1 to 4, and the images that they use. We can take a look.