Every list for the short-answer section — nothing else.
The doctor named exactly which chapters can appear as short-answer questions (20 marks) on the final:
Social Media, Business Ethics, Ethical Hacking, Social Engineering, Intellectual Property Laws, and
Cyber Laws in Saudi Arabia. This page only covers those six — Cloud Computing and Privacy in
Cyberspace are MCQ-only on the final, so they're deliberately left out here.
6 chapters
— lists
— total items
Read each list out loud once, then cover it and rebuild it from memory — that's the fastest way to
lock a short-answer list in before an exam.
01
Social Media: Ethical, Legal & Security Issues
8 lists
Applications of Social Media 3
Employee hiring process
Organizations (internal communication)
Digital marketing
Social Media in Hiring 2
Recruit candidates — publicize job openings
Conduct background checks — confirm qualifications
Reasons Candidates Get Rejected 4
Posts about drinking or drug use
Provocative or inappropriate photos
Discriminatory remarks (race, gender, religion)
Confidential information posted
Pros of Social Media in Organizations 6
Facilitates open communication
Employees discuss ideas, share links/news
Widens business contacts
Effective, wide-reach recruitment tool
Improves reputation & client base cheaply
Expands market research & campaigns
Cons of Social Media in Organizations 4
Opens door to fraud, spam & virus attacks
Risk of scams → data/identity theft
Negative employee comments / legal exposure
Lost productivity
Role of Social Media in Digital Marketing 7
See your target close & personal
Respond to problems immediately
Drives more sales
It's free
Increased brand recognition
Improved brand loyalty
Improved customer insights
Benefits of Brand Promotion on Social Media 9
Growing social signals (SEO boost)
Company branding & awareness
Word of mouth advertising
Improved customer insights
Better customer service
Cost efficient
Connectivity with customers
Establishing brand awareness
Sales growth
Drawbacks of Brand Promotion 4
Exposure to competitors
Needs qualified personnel
Can tarnish brand name
Time consuming
Tips for Safer Social Networking 12
Use a strong, unique password
Share as little personal info as possible
Customize privacy settings
Don't allow 3rd-party app access
Be careful what you post (photos, opinions, complaints)
Don't post about your employer without authorization
Supervise kids' social media use
Be suspicious of friend/follow requests & ads
Minimize careless clicking on ads/videos/games
Use browser anti-phishing/malicious-site warnings
Google yourself & scrutinize results
Think before you click
02
Business Ethics
6 lists
Core Ethical Principles 5
Integrity — honesty, strong moral principles
Fairness — treating stakeholders equally
Respect — valuing others' rights & dignity
Responsibility — accountability for actions
Transparency — open communication
Types of Ethics in Business 4
Personal Ethics — individual moral beliefs
Professional Ethics — profession-specific standards
Organizational Ethics — company values/principles
Global Ethics — international business issues
Common Ethical Dilemmas 5
Offering or accepting bribes
Misleading advertising
Using insider information
Discriminatory hiring or promotion
Environmental pollution
Ethical Decision-Making Model 5
Recognize the ethical issue
Gather relevant facts & stakeholders' views
Consider ethical principles (fairness, harm, honesty)
Evaluate alternatives & decide
Reflect on the outcome
Importance of Business Ethics 4
Builds consumer trust & loyalty
Enhances reputation & brand image
Encourages transparency & accountability
Helps avoid legal issues & scandals
Consequences of Unethical Behavior 4
Loss of reputation & customer trust
Legal penalties & lawsuits
Decline in employee morale
Financial losses & market exit
03
Introduction to Ethical Hacking
7 lists
Threat Categories (by level) 3 groups
Host-Level Threats (6)
Malware
Password attacks
Arbitrary code execution
Login bypass
Privilege escalation
Backdoors
Network-Level Threats (6)
Scanning
Sniffing & eavesdropping
Spoofing
Session hijacking
Man-in-the-middle attack
DNS & ARP poisoning
Application-Level Threats (8)
Improper input validation
Broken authentication & authorization
Security misconfiguration
SQL injection
Broken session management
Buffer overflow issues
Cryptography failures
Improper error/exception handling
Cyber Attack Components 3
Motive — the goal driving the attacker (financial, espionage, disruption)
Method — technique used (phishing, malware, SQL injection)
Vulnerability — the exploitable weakness
Botnet Uses 4
DDoS attacks
Sending spam emails
Data theft
Cryptomining
Common Mobile Threats 6
Phishing attacks
Spyware
Broken cryptography
Data leakage
Unsecured Wi-Fi
Network spoofing
Security Concept Terminologies 8
Hack Value — target's attractiveness to a hacker
Zero-Day Attack — exploited before a patch exists
Vulnerability — a weak point/loophole
Payload — malicious part of exploit code
Bot — software remotely controlling a target
Daisy Chaining — sequential attacks reusing prior info
Exploit — breach via vulnerability/zero-day
Doxing — publishing an individual's info from public sources
Shrink-Wrap Exploit Targets 3
Unpatched operating systems
Commercial off-the-shelf (COTS) software
Poorly designed / outdated applications
Other Cybersecurity Threat Types 4
Insider Threat — misuse of legitimate access
Botnets — network of compromised "zombie" devices
Viruses & Worms — self-spreading malicious software
Mobile Threats — see list above
04
Social Engineering
7 lists
Why Social Engineering Is Dangerous 5
Identity theft (bank #s, SSNs, user IDs/passwords)
All kinds of data theft
Corruption of data
Unplanned system downtime
Physical security threat
Types of Email Phishing 2
Spear phishing — targeted at a specific individual
Whaling — targets high-value people (execs/government) to access many users' data
Impersonation Attack Vectors 2
Impersonating a delivery person
Impersonating tech support — gains physical PC access
Common Social Engineering Attacks 4
Phishing (email)
Vishing (voice/phone)
SMiShing (SMS)
Impersonation (delivery/tech support)
How to Avoid Social Engineering Frauds 7
Secure your computing devices (AV, firewall, updates)
Set spam filters to high
Beware of any download
Delete requests for financial info/passwords
Slow down — don't act on urgency
Research the facts independently
Watch for email/account hijacking — verify before clicking links
Protecting Against Vishing 5
Never answer calls from unknown numbers
Never give personal info over the phone
Use a caller ID app
Don't fully trust caller ID
Treat vishing like smishing scams
Protecting Against Phishing 3
Restrict social media privacy to people you know
Observe emails carefully for authenticity
Watch for typos, unofficial docs, false URLs
05
Intellectual Property Laws
9 lists
The 4 Types of Intellectual Property 4
Copyright — protects creative works
Patents — protects inventions
Trademarks — protects brand identity
Trade Secrets — protects confidential info
Mnemonic: "Can People Trade Secrets?"
The 4 Copyright Rights (RDPD) 4
Reproduce — print, copy, duplicate
Derivative — translate, adapt, movie from book
Perform — play, sing, broadcast
Distribute — sell, rent, lend
Copyright Infringement — 3 Conditions (VAD) 3
Valid copyright — owner holds a real copyright
Access — infringer could access the work
Duplication — beyond legal exceptions
The 4 Fair Use Factors (PANE) 4
Purpose — commercial vs educational
Nature — type of original work
Amount — how much was used
Effect — impact on market value
The 4 Patent Tests (UNUM) 4
Useful — must have a purpose
Novel — not previously invented
Unobvious — not obvious to experts in the field
Must be in class — process, machine, manufacture, composition, improvement
Types of Patent Infringement 6
Direct — make/sell/use without permission
Indirect — helping/encouraging someone else to infringe
Induced — providing instructions/components leading to infringement
Contributory — selling a part with no use except infringement
Literal — direct correspondence between product and patent
Willful — intentionally using patented ideas (up to 3× damages)
Trade Secret Checklist (ECUKC) 5
Economic value
Cost/effort to develop
Unique or novel
Kept from the public
Confidential — company takes active steps
ACPA — 3 Conditions for Cybersquatting 3
Bad faith intent to profit from the domain
Trademark was well-known at time of registration
Domain identical (or confusingly similar) to the trademark
Common Student Mistakes About IP Law 7
Copyright does NOT require registration — it's automatic
Plagiarism ≠ Copyright Infringement (one is ethical, one is legal)
There's no "safe" percentage of copying — courts look at substantiality
Content online is NOT automatically free to use
Patent and copyright do NOT protect the same things
Trade secrets have NO time limit (unlike patents)
Sharing pirated content for free is still infringement — "financial gain"
includes receiving it for free
06
Cyber Laws in Saudi Arabia
7 lists + article table
3 Categories of Cybercrime (IPG) 3
Individual — targets a specific person's privacy/reputation/safety
Property — steals/damages/exploits digital or financial assets
Government — targets state infrastructure, security, or national interests
Mnemonic: "I Protect Governments"
6 Crimes Against Individuals 6
Email Spoofing
Spamming
Phishing
Cyber Stalking
Cyber Defamation
Cyber Pornography
6 Crimes Against Property 6
Credit Card Skimming
Intellectual Property Crimes
Software Piracy
Identity Theft
DDoS / Hacking / Viruses
Cybersquatting / Copyright / IPR violations
8 Crimes Against Government 8
Denial of Service (DoS)
Email Bombing
Logic Bombing
Data Diddling
Sale of Illegal Articles
Cyber Terrorism
Pirated Software
Accessing Confidential Info
4 Objectives of the KSA Anti-Cybercrime Law 4
Enhance Information Security
Protect the Rights of Users (legitimate use)
Protect Public Interest, Morals & Values
Protect the National Economy
Mnemonic: IS · RU · PM · NE — "I Secure Rights — Protecting
Morals & National Economy"
Key Attack Types 8
Data Diddling — alter data before/during entry, restore after
Salami Attack — steal tiny amounts repeatedly, unnoticed
Trojans / Keyloggers — record every keystroke
Web Jacking — forcefully take control of a website
Email Bombing — flood a mailbox to crash it
Logic Bombing — malicious code triggered by a condition
Credit Card Skimming — device steals card data during a transaction
DoS / DDoS — flood a server so legitimate users can't access it
★ KSA Anti-Cybercrime Law — Articles & Penalties
Royal Decree No. M/17 (26 March 2007), 16 articles. Penalties escalate with
severity — know which article covers which crimes.
Article
Crimes Covered
Max Prison
Max Fine (SAR)
Art. 3
Spying/interception without auth · unlawful access to threaten/blackmail · hacking
websites · invasion of privacy (camera phones) · defamation via IT tools
1 year
500,000
Art. 4
Fraud/false identity to obtain property · illegally accessing bank/credit data
3 years
2,000,000
Art. 5
Deleting/leaking/altering private data · causing network halt/breakdown ·
obstructing/distorting services
4 years
3,000,000
Art. 6
Content violating public order/morals/religion · pornographic or gambling sites ·
human trafficking facilitation · drug trade online
5 years
3,000,000
Art. 7
Websites for terrorist organizations · accessing data threatening national
security/economy
10 years
5,000,000
Art. 9
Accomplice rule — inciting/assisting/collaborating in any cybercrime
Crime committed → up to full max. Not committed → up to half the max.