🇬🇧 Chartered IT Professional (CITP) · flashcards

Chartered IT Professional (CITP) Information Security, Risk and Resilience Flashcards

54 question-and-answer cards covering Information Security, Risk and Resilience as it is examined in Chartered IT Professional (CITP). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

54Cards in deck
24Free preview
12Syllabus topics
~214Chars per answer
FreePrice

24 sample cards from the Information Security, Risk and Resilience deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Distinguish penetration testing from vulnerability scanning.

    Vulnerability scanning is an automated, broad identification of known weaknesses. Penetration testing is a goal-oriented, often manual exercise that actively exploits vulnerabilities to demonstrate real-world impact and chains of compromise.

  2. What is the difference between black-box, white-box and grey-box security testing?

    Black-box: the tester has no prior knowledge of the system (external attacker view). White-box: the tester has full knowledge (source code, architecture, credentials). Grey-box: the tester has partial knowledge, such as user-level credentials.

  3. What is the difference between Verification and Validation in assurance?

    Verification asks 'are we building the system right?' (conformance to specification/requirements). Validation asks 'are we building the right system?' (does it meet the actual user/business need).

  4. What is a SOC (Security Operations Centre) responsible for?

    Centralised, ongoing monitoring, detection, analysis and response to security events across the organisation — typically using SIEM tooling, threat intelligence, and defined incident response processes, often 24/7.

  5. State the qualitative risk formula commonly used in information security risk assessment.

    $Risk = Likelihood \times Impact$, where likelihood is the probability of a threat exploiting a vulnerability and impact is the magnitude of resulting harm.

  6. Define Annualised Loss Expectancy (ALE) and its component formulas.

    $ALE = SLE \times ARO$, where Single Loss Expectancy $SLE = AssetValue \times EF$ (Exposure Factor) and ARO is the Annualised Rate of Occurrence. ALE is the expected monetary loss per year from a given risk.

  7. If an asset is worth £200,000, an incident causes 25% loss, and it occurs twice per year, what is the ALE?

    $SLE = £200{,}000 \times 0.25 = £50{,}000$; $ALE = £50{,}000 \times 2 = £100{,}000$ per year.

  8. Contrast qualitative and quantitative risk assessment.

    Qualitative assessment uses descriptive ratings (e.g. high/medium/low) and is faster and more subjective. Quantitative assessment assigns numeric/monetary values (e.g. ALE) enabling cost-benefit analysis but requires more reliable data.

  9. What is the difference between inherent risk and residual risk?

    Inherent risk is the level of risk present before any controls are applied. Residual risk is the risk remaining after controls/treatments have been implemented.

  10. Name the four standard risk treatment options.

    Treat/Mitigate (reduce likelihood or impact with controls), Tolerate/Accept (retain the risk), Transfer/Share (e.g. insurance or outsourcing), and Terminate/Avoid (stop the activity causing the risk).

  11. Define 'risk appetite' and distinguish it from 'risk tolerance'.

    Risk appetite is the amount and type of risk an organisation is willing to pursue or retain to meet its objectives (set at board level). Risk tolerance is the acceptable variation around that appetite for specific risks — the threshold within which risk is acceptable.

  12. What is the formula for Return on Security Investment (ROSI)?

    $ROSI = \dfrac{(ALE_{prior} - ALE_{post}) - CostOfControl}{CostOfControl}$, i.e. the monetary risk reduction achieved by a control minus its cost, divided by its cost.

  13. What is a risk register and what does it typically record?

    A central document tracking identified risks, each with a description, owner, likelihood, impact, risk score, chosen treatment/controls, residual risk, and status/review date.

  14. What are the main concerns of third-party and supply chain risk management?

    The risk that suppliers, vendors or partners introduce vulnerabilities — e.g. through their access to data/systems, weaker security posture, compromised software/components, or fourth-party dependencies — requiring due diligence, contractual controls, and ongoing assurance.

  15. What is a 'fourth-party' risk in supply chain terms?

    Risk arising from the subcontractors and suppliers of your direct (third-party) suppliers — entities you have no direct contract with but whose failure or compromise can still affect you.

  16. In business continuity, define RTO and RPO.

    Recovery Time Objective (RTO) is the maximum acceptable time to restore a service after disruption. Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time (how far back the last good backup must be).

  17. What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

    A BCP is the broad strategy to keep critical business functions operating during/after disruption. A DRP is a subset focused specifically on restoring IT systems, data and infrastructure after an incident.

  18. What is the purpose of a Business Impact Analysis (BIA)?

    To identify critical business functions and processes, assess the impact of their disruption over time, and determine recovery priorities and requirements (informing RTOs, RPOs and resource needs).

  19. Compare hot, warm, and cold disaster recovery sites.

    A hot site is fully equipped and continuously running, enabling near-instant failover (most costly). A warm site has hardware/connectivity but needs data/configuration loading (moderate cost/time). A cold site provides only basic facilities/space and must be fully provisioned (cheapest, slowest recovery).

  20. List the standard phases of the incident management/response lifecycle (NIST SP 800-61).

    Preparation; Detection and Analysis; Containment, Eradication and Recovery; and Post-Incident Activity (lessons learned).

  21. What is the difference between an event and an incident in security management?

    An event is any observable occurrence in a system or network. A security incident is an event (or series of events) that actually or potentially compromises confidentiality, integrity or availability and warrants response.

  22. What distinguishes operational resilience from traditional business continuity?

    Operational resilience is the broader ability of an organisation to prevent, adapt to, respond to, recover from and learn from operational disruptions to its important business services — assuming disruption is inevitable and focusing on service continuity and impact tolerances, rather than just recovering specific assets.

  23. In operational resilience, what is an 'impact tolerance'?

    The maximum tolerable level of disruption to an important business service — expressed by metrics such as time, volume of customers affected, or financial loss — beyond which there would be intolerable harm to the firm, its customers or market integrity.

  24. What is the difference between MTBF and MTTR as resilience metrics?

    Mean Time Between Failures (MTBF) measures average operational time between failures (reliability — higher is better). Mean Time To Repair/Recover (MTTR) measures the average time to restore service after a failure (maintainability — lower is better).

What this deck covers

The Information Security, Risk and Resilience deck follows the Chartered IT Professional (CITP) Information Security, Risk and Resilience syllabus — 4 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 13.5 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 214 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Security, Risk and Resilience flashcards FAQ

How many Information Security, Risk and Resilience flashcards are in this Chartered IT Professional (CITP) deck?

54 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Chartered IT Professional (CITP) flashcards free?

Yes. The preview here is free to read with no signup, and the full 54-card deck is free inside the Examius app.

What do the Information Security, Risk and Resilience cards cover?

They follow the Chartered IT Professional (CITP) Information Security, Risk and Resilience syllabus — 4 chapters and 12 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.