The Listing Vault ETHC303 · final exam · short-answer chapters only

Every list for the short-answer section — nothing else.

The doctor named exactly which chapters can appear as short-answer questions (20 marks) on the final: Social Media, Business Ethics, Ethical Hacking, Social Engineering, Intellectual Property Laws, and Cyber Laws in Saudi Arabia. This page only covers those six — Cloud Computing and Privacy in Cyberspace are MCQ-only on the final, so they're deliberately left out here.

6chapters
lists
total items
01

Social Media: Ethical, Legal & Security Issues

8 lists

Applications of Social Media 3

  1. Employee hiring process
  2. Organizations (internal communication)
  3. Digital marketing

Social Media in Hiring 2

  1. Recruit candidates — publicize job openings
  2. Conduct background checks — confirm qualifications

Reasons Candidates Get Rejected 4

  1. Posts about drinking or drug use
  2. Provocative or inappropriate photos
  3. Discriminatory remarks (race, gender, religion)
  4. Confidential information posted

Pros of Social Media in Organizations 6

  1. Facilitates open communication
  2. Employees discuss ideas, share links/news
  3. Widens business contacts
  4. Effective, wide-reach recruitment tool
  5. Improves reputation & client base cheaply
  6. Expands market research & campaigns

Cons of Social Media in Organizations 4

  1. Opens door to fraud, spam & virus attacks
  2. Risk of scams → data/identity theft
  3. Negative employee comments / legal exposure
  4. Lost productivity

Role of Social Media in Digital Marketing 7

  1. See your target close & personal
  2. Respond to problems immediately
  3. Drives more sales
  4. It's free
  5. Increased brand recognition
  6. Improved brand loyalty
  7. Improved customer insights

Benefits of Brand Promotion on Social Media 9

  1. Growing social signals (SEO boost)
  2. Company branding & awareness
  3. Word of mouth advertising
  4. Improved customer insights
  5. Better customer service
  6. Cost efficient
  7. Connectivity with customers
  8. Establishing brand awareness
  9. Sales growth

Drawbacks of Brand Promotion 4

  1. Exposure to competitors
  2. Needs qualified personnel
  3. Can tarnish brand name
  4. Time consuming

Tips for Safer Social Networking 12

  • Use a strong, unique password
  • Share as little personal info as possible
  • Customize privacy settings
  • Don't allow 3rd-party app access
  • Be careful what you post (photos, opinions, complaints)
  • Don't post about your employer without authorization
  • Supervise kids' social media use
  • Be suspicious of friend/follow requests & ads
  • Minimize careless clicking on ads/videos/games
  • Use browser anti-phishing/malicious-site warnings
  • Google yourself & scrutinize results
  • Think before you click
02

Business Ethics

6 lists

Core Ethical Principles 5

  1. Integrity — honesty, strong moral principles
  2. Fairness — treating stakeholders equally
  3. Respect — valuing others' rights & dignity
  4. Responsibility — accountability for actions
  5. Transparency — open communication

Types of Ethics in Business 4

  1. Personal Ethics — individual moral beliefs
  2. Professional Ethics — profession-specific standards
  3. Organizational Ethics — company values/principles
  4. Global Ethics — international business issues

Common Ethical Dilemmas 5

  1. Offering or accepting bribes
  2. Misleading advertising
  3. Using insider information
  4. Discriminatory hiring or promotion
  5. Environmental pollution

Ethical Decision-Making Model 5

  1. Recognize the ethical issue
  2. Gather relevant facts & stakeholders' views
  3. Consider ethical principles (fairness, harm, honesty)
  4. Evaluate alternatives & decide
  5. Reflect on the outcome

Importance of Business Ethics 4

  1. Builds consumer trust & loyalty
  2. Enhances reputation & brand image
  3. Encourages transparency & accountability
  4. Helps avoid legal issues & scandals

Consequences of Unethical Behavior 4

  1. Loss of reputation & customer trust
  2. Legal penalties & lawsuits
  3. Decline in employee morale
  4. Financial losses & market exit
03

Introduction to Ethical Hacking

7 lists

Threat Categories (by level) 3 groups

Host-Level Threats (6)

  • Malware
  • Password attacks
  • Arbitrary code execution
  • Login bypass
  • Privilege escalation
  • Backdoors

Network-Level Threats (6)

  • Scanning
  • Sniffing & eavesdropping
  • Spoofing
  • Session hijacking
  • Man-in-the-middle attack
  • DNS & ARP poisoning

Application-Level Threats (8)

  • Improper input validation
  • Broken authentication & authorization
  • Security misconfiguration
  • SQL injection
  • Broken session management
  • Buffer overflow issues
  • Cryptography failures
  • Improper error/exception handling

Cyber Attack Components 3

  1. Motive — the goal driving the attacker (financial, espionage, disruption)
  2. Method — technique used (phishing, malware, SQL injection)
  3. Vulnerability — the exploitable weakness

Botnet Uses 4

  1. DDoS attacks
  2. Sending spam emails
  3. Data theft
  4. Cryptomining

Common Mobile Threats 6

  1. Phishing attacks
  2. Spyware
  3. Broken cryptography
  4. Data leakage
  5. Unsecured Wi-Fi
  6. Network spoofing

Security Concept Terminologies 8

  • Hack Value — target's attractiveness to a hacker
  • Zero-Day Attack — exploited before a patch exists
  • Vulnerability — a weak point/loophole
  • Payload — malicious part of exploit code
  • Bot — software remotely controlling a target
  • Daisy Chaining — sequential attacks reusing prior info
  • Exploit — breach via vulnerability/zero-day
  • Doxing — publishing an individual's info from public sources

Shrink-Wrap Exploit Targets 3

  1. Unpatched operating systems
  2. Commercial off-the-shelf (COTS) software
  3. Poorly designed / outdated applications

Other Cybersecurity Threat Types 4

  1. Insider Threat — misuse of legitimate access
  2. Botnets — network of compromised "zombie" devices
  3. Viruses & Worms — self-spreading malicious software
  4. Mobile Threats — see list above
04

Social Engineering

7 lists

Why Social Engineering Is Dangerous 5

  1. Identity theft (bank #s, SSNs, user IDs/passwords)
  2. All kinds of data theft
  3. Corruption of data
  4. Unplanned system downtime
  5. Physical security threat

Types of Email Phishing 2

  1. Spear phishing — targeted at a specific individual
  2. Whaling — targets high-value people (execs/government) to access many users' data

Impersonation Attack Vectors 2

  1. Impersonating a delivery person
  2. Impersonating tech support — gains physical PC access

Common Social Engineering Attacks 4

  1. Phishing (email)
  2. Vishing (voice/phone)
  3. SMiShing (SMS)
  4. Impersonation (delivery/tech support)

How to Avoid Social Engineering Frauds 7

  • Secure your computing devices (AV, firewall, updates)
  • Set spam filters to high
  • Beware of any download
  • Delete requests for financial info/passwords
  • Slow down — don't act on urgency
  • Research the facts independently
  • Watch for email/account hijacking — verify before clicking links

Protecting Against Vishing 5

  1. Never answer calls from unknown numbers
  2. Never give personal info over the phone
  3. Use a caller ID app
  4. Don't fully trust caller ID
  5. Treat vishing like smishing scams

Protecting Against Phishing 3

  1. Restrict social media privacy to people you know
  2. Observe emails carefully for authenticity
  3. Watch for typos, unofficial docs, false URLs
05

Intellectual Property Laws

9 lists

The 4 Types of Intellectual Property 4

  1. Copyright — protects creative works
  2. Patents — protects inventions
  3. Trademarks — protects brand identity
  4. Trade Secrets — protects confidential info

Mnemonic: "Can People Trade Secrets?"

The 4 Copyright Rights (RDPD) 4

  1. Reproduce — print, copy, duplicate
  2. Derivative — translate, adapt, movie from book
  3. Perform — play, sing, broadcast
  4. Distribute — sell, rent, lend

Copyright Infringement — 3 Conditions (VAD) 3

  1. Valid copyright — owner holds a real copyright
  2. Access — infringer could access the work
  3. Duplication — beyond legal exceptions

The 4 Fair Use Factors (PANE) 4

  1. Purpose — commercial vs educational
  2. Nature — type of original work
  3. Amount — how much was used
  4. Effect — impact on market value

The 4 Patent Tests (UNUM) 4

  1. Useful — must have a purpose
  2. Novel — not previously invented
  3. Unobvious — not obvious to experts in the field
  4. Must be in class — process, machine, manufacture, composition, improvement

Types of Patent Infringement 6

  • Direct — make/sell/use without permission
  • Indirect — helping/encouraging someone else to infringe
  • Induced — providing instructions/components leading to infringement
  • Contributory — selling a part with no use except infringement
  • Literal — direct correspondence between product and patent
  • Willful — intentionally using patented ideas (up to 3× damages)

Trade Secret Checklist (ECUKC) 5

  1. Economic value
  2. Cost/effort to develop
  3. Unique or novel
  4. Kept from the public
  5. Confidential — company takes active steps

ACPA — 3 Conditions for Cybersquatting 3

  1. Bad faith intent to profit from the domain
  2. Trademark was well-known at time of registration
  3. Domain identical (or confusingly similar) to the trademark

Common Student Mistakes About IP Law 7

  • Copyright does NOT require registration — it's automatic
  • Plagiarism ≠ Copyright Infringement (one is ethical, one is legal)
  • There's no "safe" percentage of copying — courts look at substantiality
  • Content online is NOT automatically free to use
  • Patent and copyright do NOT protect the same things
  • Trade secrets have NO time limit (unlike patents)
  • Sharing pirated content for free is still infringement — "financial gain" includes receiving it for free
06

Cyber Laws in Saudi Arabia

7 lists + article table

3 Categories of Cybercrime (IPG) 3

  1. Individual — targets a specific person's privacy/reputation/safety
  2. Property — steals/damages/exploits digital or financial assets
  3. Government — targets state infrastructure, security, or national interests

Mnemonic: "I Protect Governments"

6 Crimes Against Individuals 6

  1. Email Spoofing
  2. Spamming
  3. Phishing
  4. Cyber Stalking
  5. Cyber Defamation
  6. Cyber Pornography

6 Crimes Against Property 6

  1. Credit Card Skimming
  2. Intellectual Property Crimes
  3. Software Piracy
  4. Identity Theft
  5. DDoS / Hacking / Viruses
  6. Cybersquatting / Copyright / IPR violations

8 Crimes Against Government 8

  • Denial of Service (DoS)
  • Email Bombing
  • Logic Bombing
  • Data Diddling
  • Sale of Illegal Articles
  • Cyber Terrorism
  • Pirated Software
  • Accessing Confidential Info

4 Objectives of the KSA Anti-Cybercrime Law 4

  1. Enhance Information Security
  2. Protect the Rights of Users (legitimate use)
  3. Protect Public Interest, Morals & Values
  4. Protect the National Economy

Mnemonic: IS · RU · PM · NE — "I Secure Rights — Protecting Morals & National Economy"

Key Attack Types 8

  • Data Diddling — alter data before/during entry, restore after
  • Salami Attack — steal tiny amounts repeatedly, unnoticed
  • Trojans / Keyloggers — record every keystroke
  • Web Jacking — forcefully take control of a website
  • Email Bombing — flood a mailbox to crash it
  • Logic Bombing — malicious code triggered by a condition
  • Credit Card Skimming — device steals card data during a transaction
  • DoS / DDoS — flood a server so legitimate users can't access it

★ KSA Anti-Cybercrime Law — Articles & Penalties

Royal Decree No. M/17 (26 March 2007), 16 articles. Penalties escalate with severity — know which article covers which crimes.

Article Crimes Covered Max Prison Max Fine (SAR)
Art. 3 Spying/interception without auth · unlawful access to threaten/blackmail · hacking websites · invasion of privacy (camera phones) · defamation via IT tools 1 year 500,000
Art. 4 Fraud/false identity to obtain property · illegally accessing bank/credit data 3 years 2,000,000
Art. 5 Deleting/leaking/altering private data · causing network halt/breakdown · obstructing/distorting services 4 years 3,000,000
Art. 6 Content violating public order/morals/religion · pornographic or gambling sites · human trafficking facilitation · drug trade online 5 years 3,000,000
Art. 7 Websites for terrorist organizations · accessing data threatening national security/economy 10 years 5,000,000
Art. 9 Accomplice rule — inciting/assisting/collaborating in any cybercrime Crime committed → up to full max. Not committed → up to half the max.