Every list, gathered in one place.
Built for the 10-mark listing section of your midterm — every numbered set, category, and "types of…"
across all six chapters, extracted and organized for fast recall. ★ marks
items confirmed on a past exam.
6 chapters
— lists
— total items
Read each list out loud once, then cover it and rebuild it from memory — that's the fastest way to
lock a "list" question in before an exam.
01
Privacy Issues in Cloud Computing
7 lists
Cloud Service Models 4
SaaS — Software as a Service (Google Apps, Office 365, Gmail,
Dropbox)
IaaS — Infrastructure as a Service (Azure, AWS — CPU, storage,
bandwidth)
PaaS — Platform as a Service (dev/test/deploy platform)
EaaS — Equipment as a Service (IoT device connectivity)
6 Facts About the Cloud Industry 6
Amazon & Microsoft earn a growing share of revenue from the cloud
Security concerns are waning — 60% feel adequately safeguarded
Investment in cloud computing is increasing across all industries
Nearly half of US government agencies use the cloud (largest user)
Banks are the most active cloud users (mobile banking, PayPal, Bitcoin)
Most companies use the cloud mainly for storage & backup/recovery
Advantages of Cloud Computing 12
Economical — reduced cost, pay incrementally
Increased storage capacity
Flexibility
More mobility — access from anywhere
Allows IT to shift focus to business goals
Insight — integrated cloud analytics
Collaboration made simple
Quality control in reporting
Disaster recovery
Loss prevention
Automatic software updates
Sustainability
Disadvantages of Cloud Computing 5
Possible downtime
Slow upload/download (internet-dependent)
Security and legal issues
Lack of support in some circumstances
Data lost if company goes bankrupt
Cloud Security Issues 5
Data breaches — targeted attack or human error/vulnerability
Hijacking of accounts — stolen login credentials abused
Abuse of cloud services — malware injection (malicious "valid instance" scripts)
Shared vulnerabilities — security is a shared client/provider responsibility
Data loss — attack, disaster, or provider wipe (e.g. Amazon 2011,
Google lightning strike)
Ethical Issues in Cloud Computing 5
Compliance — must meet standards for the application/service
Spiteful activity — disgruntled insiders/competitors doing harm
Policies ignoring customers' interests — utilitarian duty to all users
Intellectual property — easy unauthorized redistribution of digital media
Discrimination — vendors favoring big accounts over small ones
Legal Issues in Cloud Computing 6
User doesn't know where/how data is stored or recorded
Data stored abroad falls under a different country's laws/jurisdiction
Conflicting regulations across countries of processing, storage, and transit
Users can specify storage countries via agreement, but it's hard to verify (proprietary
tech)
Responsibility for data (insurance, third-party partner access) must be clear
Unclear rights over files when a customer stops using the service; T&Cs often unread
02
Business Ethics
6 lists
Core Ethical Principles 5
Integrity — honesty, strong moral principles
Fairness — treating stakeholders equally
Respect — valuing others' rights & dignity
Responsibility — accountability for actions
Transparency — open communication
Types of Ethics in Business 4
Personal Ethics — individual moral beliefs
Professional Ethics — profession-specific standards
Organizational Ethics — company values/principles
Global Ethics — international business issues
Common Ethical Dilemmas 5
Offering or accepting bribes
Misleading advertising
Using insider information
Discriminatory hiring or promotion
Environmental pollution
Ethical Decision-Making Model 5
Recognize the ethical issue
Gather relevant facts & stakeholders' views
Consider ethical principles (fairness, harm, honesty)
Evaluate alternatives & decide
Reflect on the outcome
Importance of Business Ethics 4
Builds consumer trust & loyalty
Enhances reputation & brand image
Encourages transparency & accountability
Helps avoid legal issues & scandals
Consequences of Unethical Behavior 4
Loss of reputation & customer trust
Legal penalties & lawsuits
Decline in employee morale
Financial losses & market exit
03
Social Media: Ethical, Legal & Security Issues
8 lists
Applications of Social Media 3
Employee hiring process
Organizations (internal communication)
Digital marketing
Social Media in Hiring 2
Recruit candidates — publicize job openings
Conduct background checks — confirm qualifications
Reasons Candidates Get Rejected 4
Posts about drinking or drug use
Provocative or inappropriate photos
Discriminatory remarks (race, gender, religion)
Confidential information posted
Pros of Social Media in Organizations 6
Facilitates open communication
Employees discuss ideas, share links/news
Widens business contacts
Effective, wide-reach recruitment tool
Improves reputation & client base cheaply
Expands market research & campaigns
Cons of Social Media in Organizations 4
Opens door to fraud, spam & virus attacks
Risk of scams → data/identity theft
Negative employee comments / legal exposure
Lost productivity
Role of Social Media in Digital Marketing 7
See your target close & personal
Respond to problems immediately
Drives more sales
It's free
Increased brand recognition
Improved brand loyalty
Improved customer insights
Benefits of Brand Promotion on Social Media 9
Growing social signals (SEO boost)
Company branding & awareness
Word of mouth advertising
Improved customer insights
Better customer service
Cost efficient
Connectivity with customers
Establishing brand awareness
Sales growth
Drawbacks of Brand Promotion 4
Exposure to competitors
Needs qualified personnel
Can tarnish brand name
Time consuming
Tips for Safer Social Networking 12
Use a strong, unique password
Share as little personal info as possible
Customize privacy settings
Don't allow 3rd-party app access
Be careful what you post (photos, opinions, complaints)
Don't post about your employer without authorization
Supervise kids' social media use
Be suspicious of friend/follow requests & ads
Minimize careless clicking on ads/videos/games
Use browser anti-phishing/malicious-site warnings
Google yourself & scrutinize results
Think before you click
04
Introduction to Ethical Hacking
7 lists
Threat Categories (by level) 3 groups
Host-Level Threats (6)
Malware
Password attacks
Arbitrary code execution
Login bypass
Privilege escalation
Backdoors
Network-Level Threats (6)
Scanning
Sniffing & eavesdropping
Spoofing
Session hijacking
Man-in-the-middle attack
DNS & ARP poisoning
Application-Level Threats (8)
Improper input validation
Broken authentication & authorization
Security misconfiguration
SQL injection
Broken session management
Buffer overflow issues
Cryptography failures
Improper error/exception handling
Cyber Attack Components 3
Motive — the goal driving the attacker (financial, espionage, disruption)
Method — technique used (phishing, malware, SQL injection)
Vulnerability — the exploitable weakness
Botnet Uses 4
DDoS attacks
Sending spam emails
Data theft
Cryptomining
Common Mobile Threats 6
Phishing attacks
Spyware
Broken cryptography
Data leakage
Unsecured Wi-Fi
Network spoofing
Security Concept Terminologies 8
Hack Value — target's attractiveness to a hacker
Zero-Day Attack — exploited before a patch exists
Vulnerability — a weak point/loophole
Payload — malicious part of exploit code
Bot — software remotely controlling a target
Daisy Chaining — sequential attacks reusing prior info
Exploit — breach via vulnerability/zero-day
Doxing — publishing an individual's info from public sources
Shrink-Wrap Exploit Targets 3
Unpatched operating systems
Commercial off-the-shelf (COTS) software
Poorly designed / outdated applications
Other Cybersecurity Threat Types 4
Insider Threat — misuse of legitimate access
Botnets — network of compromised "zombie" devices
Viruses & Worms — self-spreading malicious software
Mobile Threats — see list above
05
Social Engineering
7 lists
Why Social Engineering Is Dangerous 5
Identity theft (bank #s, SSNs, user IDs/passwords)
All kinds of data theft
Corruption of data
Unplanned system downtime
Physical security threat
Types of Email Phishing 2
Spear phishing — targeted at a specific individual
Whaling — targets high-value people (execs/government) to access many users' data
Impersonation Attack Vectors 2
Impersonating a delivery person
Impersonating tech support — gains physical PC access
Common Social Engineering Attacks 4
Phishing (email)
Vishing (voice/phone)
SMiShing (SMS)
Impersonation (delivery/tech support)
How to Avoid Social Engineering Frauds 7
Secure your computing devices (AV, firewall, updates)
Set spam filters to high
Beware of any download
Delete requests for financial info/passwords
Slow down — don't act on urgency
Research the facts independently
Watch for email/account hijacking — verify before clicking links
Protecting Against Vishing 5
Never answer calls from unknown numbers
Never give personal info over the phone
Use a caller ID app
Don't fully trust caller ID
Treat vishing like smishing scams
Protecting Against Phishing 3
Restrict social media privacy to people you know
Observe emails carefully for authenticity
Watch for typos, unofficial docs, false URLs
06
Privacy Issues in Cyberspace
6 lists + exam mapping
How Cybertechnology Changed Privacy 4
Amount of personal info that can be collected — huge, low storage cost
Speed of transmission — records move in milliseconds
Duration of retention — can be kept indefinitely
Kind of information acquired/exchanged — detailed transactional profiles
Cyber-Privacy Focuses On 4
What data should be collected?
What personal info can be shared, with whom?
How much control do individuals have over gathering/mining/exchange?
How long should data be retained?
Categories of Private Information 4
Private communications
Health privacy / medical information
Personal information (financial, academic)
Information about one's possessions (property-related)
Types of Internet Cookies 2
First-party cookies — offers/tracking for returning users
Third-party cookies — shared with ad agencies/marketers ("tracking cookies")
Solutions to Protect Online Privacy 5
Anti-virus software
Firewalls
Encryption tools
Raise awareness of privacy
P3P — Platform for Privacy Preferences (W3C protocol)
Dataveillance Examples 3
Video cameras monitoring shoppers in retail stores
Intelligent highway vehicle scanning systems
"Invisible supervisor" software monitoring employees
★ Confirmed Past-Exam Mapping — Privacy Data-Collection Techniques & Countermeasures
Major Exam 2 asked you to match each scenario to a technique/tool AND a
countermeasure. Memorize both banks whole — questions rotate which items get described.
Data-collection technique bank (13)
Countermeasure bank (8)
RFID Fingerprinting Drone
First-party Cookies Third-party
Cookies
Data mining IRIS recognition
Video Cameras Flash-Cookies
Cross-device tracking Biometrics
GPS tracking Behavioral profiling
Encryption tool Privacy Preferences
(P3P)
Anti-virus software Raise Awareness
Access Control Policies Firewall
Multi-Factor Authentication (MFA)
User-Consent Management
Known scenario→answer pairs from the exam text:
Dataveillance = general monitoring techniques · Hard-to-detect/delete cookies =
Flash-Cookies · Verifying identity via intrinsic physical traits = Biometrics ·
Short-range chip + reader = RFID · Summary of device software/hardware settings =
Fingerprinting · Shopping data → healthy habits or insurance decisions = Data mining.