The Listing Vault ETHC303 · list-based recall

Every list, gathered in one place.

Built for the 10-mark listing section of your midterm — every numbered set, category, and "types of…" across all six chapters, extracted and organized for fast recall. marks items confirmed on a past exam.

6chapters
lists
total items
01

Privacy Issues in Cloud Computing

7 lists

Cloud Service Models 4

  1. SaaS — Software as a Service (Google Apps, Office 365, Gmail, Dropbox)
  2. IaaS — Infrastructure as a Service (Azure, AWS — CPU, storage, bandwidth)
  3. PaaS — Platform as a Service (dev/test/deploy platform)
  4. EaaS — Equipment as a Service (IoT device connectivity)

6 Facts About the Cloud Industry 6

  1. Amazon & Microsoft earn a growing share of revenue from the cloud
  2. Security concerns are waning — 60% feel adequately safeguarded
  3. Investment in cloud computing is increasing across all industries
  4. Nearly half of US government agencies use the cloud (largest user)
  5. Banks are the most active cloud users (mobile banking, PayPal, Bitcoin)
  6. Most companies use the cloud mainly for storage & backup/recovery

Advantages of Cloud Computing 12

  • Economical — reduced cost, pay incrementally
  • Increased storage capacity
  • Flexibility
  • More mobility — access from anywhere
  • Allows IT to shift focus to business goals
  • Insight — integrated cloud analytics
  • Collaboration made simple
  • Quality control in reporting
  • Disaster recovery
  • Loss prevention
  • Automatic software updates
  • Sustainability

Disadvantages of Cloud Computing 5

  1. Possible downtime
  2. Slow upload/download (internet-dependent)
  3. Security and legal issues
  4. Lack of support in some circumstances
  5. Data lost if company goes bankrupt

Cloud Security Issues 5

  1. Data breaches — targeted attack or human error/vulnerability
  2. Hijacking of accounts — stolen login credentials abused
  3. Abuse of cloud services — malware injection (malicious "valid instance" scripts)
  4. Shared vulnerabilities — security is a shared client/provider responsibility
  5. Data loss — attack, disaster, or provider wipe (e.g. Amazon 2011, Google lightning strike)

Ethical Issues in Cloud Computing 5

  1. Compliance — must meet standards for the application/service
  2. Spiteful activity — disgruntled insiders/competitors doing harm
  3. Policies ignoring customers' interests — utilitarian duty to all users
  4. Intellectual property — easy unauthorized redistribution of digital media
  5. Discrimination — vendors favoring big accounts over small ones

Legal Issues in Cloud Computing 6

  1. User doesn't know where/how data is stored or recorded
  2. Data stored abroad falls under a different country's laws/jurisdiction
  3. Conflicting regulations across countries of processing, storage, and transit
  4. Users can specify storage countries via agreement, but it's hard to verify (proprietary tech)
  5. Responsibility for data (insurance, third-party partner access) must be clear
  6. Unclear rights over files when a customer stops using the service; T&Cs often unread
02

Business Ethics

6 lists

Core Ethical Principles 5

  1. Integrity — honesty, strong moral principles
  2. Fairness — treating stakeholders equally
  3. Respect — valuing others' rights & dignity
  4. Responsibility — accountability for actions
  5. Transparency — open communication

Types of Ethics in Business 4

  1. Personal Ethics — individual moral beliefs
  2. Professional Ethics — profession-specific standards
  3. Organizational Ethics — company values/principles
  4. Global Ethics — international business issues

Common Ethical Dilemmas 5

  1. Offering or accepting bribes
  2. Misleading advertising
  3. Using insider information
  4. Discriminatory hiring or promotion
  5. Environmental pollution

Ethical Decision-Making Model 5

  1. Recognize the ethical issue
  2. Gather relevant facts & stakeholders' views
  3. Consider ethical principles (fairness, harm, honesty)
  4. Evaluate alternatives & decide
  5. Reflect on the outcome

Importance of Business Ethics 4

  1. Builds consumer trust & loyalty
  2. Enhances reputation & brand image
  3. Encourages transparency & accountability
  4. Helps avoid legal issues & scandals

Consequences of Unethical Behavior 4

  1. Loss of reputation & customer trust
  2. Legal penalties & lawsuits
  3. Decline in employee morale
  4. Financial losses & market exit
03

Social Media: Ethical, Legal & Security Issues

8 lists

Applications of Social Media 3

  1. Employee hiring process
  2. Organizations (internal communication)
  3. Digital marketing

Social Media in Hiring 2

  1. Recruit candidates — publicize job openings
  2. Conduct background checks — confirm qualifications

Reasons Candidates Get Rejected 4

  1. Posts about drinking or drug use
  2. Provocative or inappropriate photos
  3. Discriminatory remarks (race, gender, religion)
  4. Confidential information posted

Pros of Social Media in Organizations 6

  1. Facilitates open communication
  2. Employees discuss ideas, share links/news
  3. Widens business contacts
  4. Effective, wide-reach recruitment tool
  5. Improves reputation & client base cheaply
  6. Expands market research & campaigns

Cons of Social Media in Organizations 4

  1. Opens door to fraud, spam & virus attacks
  2. Risk of scams → data/identity theft
  3. Negative employee comments / legal exposure
  4. Lost productivity

Role of Social Media in Digital Marketing 7

  1. See your target close & personal
  2. Respond to problems immediately
  3. Drives more sales
  4. It's free
  5. Increased brand recognition
  6. Improved brand loyalty
  7. Improved customer insights

Benefits of Brand Promotion on Social Media 9

  1. Growing social signals (SEO boost)
  2. Company branding & awareness
  3. Word of mouth advertising
  4. Improved customer insights
  5. Better customer service
  6. Cost efficient
  7. Connectivity with customers
  8. Establishing brand awareness
  9. Sales growth

Drawbacks of Brand Promotion 4

  1. Exposure to competitors
  2. Needs qualified personnel
  3. Can tarnish brand name
  4. Time consuming

Tips for Safer Social Networking 12

  • Use a strong, unique password
  • Share as little personal info as possible
  • Customize privacy settings
  • Don't allow 3rd-party app access
  • Be careful what you post (photos, opinions, complaints)
  • Don't post about your employer without authorization
  • Supervise kids' social media use
  • Be suspicious of friend/follow requests & ads
  • Minimize careless clicking on ads/videos/games
  • Use browser anti-phishing/malicious-site warnings
  • Google yourself & scrutinize results
  • Think before you click
04

Introduction to Ethical Hacking

7 lists

Threat Categories (by level) 3 groups

Host-Level Threats (6)

  • Malware
  • Password attacks
  • Arbitrary code execution
  • Login bypass
  • Privilege escalation
  • Backdoors

Network-Level Threats (6)

  • Scanning
  • Sniffing & eavesdropping
  • Spoofing
  • Session hijacking
  • Man-in-the-middle attack
  • DNS & ARP poisoning

Application-Level Threats (8)

  • Improper input validation
  • Broken authentication & authorization
  • Security misconfiguration
  • SQL injection
  • Broken session management
  • Buffer overflow issues
  • Cryptography failures
  • Improper error/exception handling

Cyber Attack Components 3

  1. Motive — the goal driving the attacker (financial, espionage, disruption)
  2. Method — technique used (phishing, malware, SQL injection)
  3. Vulnerability — the exploitable weakness

Botnet Uses 4

  1. DDoS attacks
  2. Sending spam emails
  3. Data theft
  4. Cryptomining

Common Mobile Threats 6

  1. Phishing attacks
  2. Spyware
  3. Broken cryptography
  4. Data leakage
  5. Unsecured Wi-Fi
  6. Network spoofing

Security Concept Terminologies 8

  • Hack Value — target's attractiveness to a hacker
  • Zero-Day Attack — exploited before a patch exists
  • Vulnerability — a weak point/loophole
  • Payload — malicious part of exploit code
  • Bot — software remotely controlling a target
  • Daisy Chaining — sequential attacks reusing prior info
  • Exploit — breach via vulnerability/zero-day
  • Doxing — publishing an individual's info from public sources

Shrink-Wrap Exploit Targets 3

  1. Unpatched operating systems
  2. Commercial off-the-shelf (COTS) software
  3. Poorly designed / outdated applications

Other Cybersecurity Threat Types 4

  1. Insider Threat — misuse of legitimate access
  2. Botnets — network of compromised "zombie" devices
  3. Viruses & Worms — self-spreading malicious software
  4. Mobile Threats — see list above
05

Social Engineering

7 lists

Why Social Engineering Is Dangerous 5

  1. Identity theft (bank #s, SSNs, user IDs/passwords)
  2. All kinds of data theft
  3. Corruption of data
  4. Unplanned system downtime
  5. Physical security threat

Types of Email Phishing 2

  1. Spear phishing — targeted at a specific individual
  2. Whaling — targets high-value people (execs/government) to access many users' data

Impersonation Attack Vectors 2

  1. Impersonating a delivery person
  2. Impersonating tech support — gains physical PC access

Common Social Engineering Attacks 4

  1. Phishing (email)
  2. Vishing (voice/phone)
  3. SMiShing (SMS)
  4. Impersonation (delivery/tech support)

How to Avoid Social Engineering Frauds 7

  • Secure your computing devices (AV, firewall, updates)
  • Set spam filters to high
  • Beware of any download
  • Delete requests for financial info/passwords
  • Slow down — don't act on urgency
  • Research the facts independently
  • Watch for email/account hijacking — verify before clicking links

Protecting Against Vishing 5

  1. Never answer calls from unknown numbers
  2. Never give personal info over the phone
  3. Use a caller ID app
  4. Don't fully trust caller ID
  5. Treat vishing like smishing scams

Protecting Against Phishing 3

  1. Restrict social media privacy to people you know
  2. Observe emails carefully for authenticity
  3. Watch for typos, unofficial docs, false URLs
06

Privacy Issues in Cyberspace

6 lists + exam mapping

How Cybertechnology Changed Privacy 4

  1. Amount of personal info that can be collected — huge, low storage cost
  2. Speed of transmission — records move in milliseconds
  3. Duration of retention — can be kept indefinitely
  4. Kind of information acquired/exchanged — detailed transactional profiles

Cyber-Privacy Focuses On 4

  1. What data should be collected?
  2. What personal info can be shared, with whom?
  3. How much control do individuals have over gathering/mining/exchange?
  4. How long should data be retained?

Categories of Private Information 4

  1. Private communications
  2. Health privacy / medical information
  3. Personal information (financial, academic)
  4. Information about one's possessions (property-related)

Types of Internet Cookies 2

  1. First-party cookies — offers/tracking for returning users
  2. Third-party cookies — shared with ad agencies/marketers ("tracking cookies")

Solutions to Protect Online Privacy 5

  1. Anti-virus software
  2. Firewalls
  3. Encryption tools
  4. Raise awareness of privacy
  5. P3P — Platform for Privacy Preferences (W3C protocol)

Dataveillance Examples 3

  1. Video cameras monitoring shoppers in retail stores
  2. Intelligent highway vehicle scanning systems
  3. "Invisible supervisor" software monitoring employees

★ Confirmed Past-Exam Mapping — Privacy Data-Collection Techniques & Countermeasures

Major Exam 2 asked you to match each scenario to a technique/tool AND a countermeasure. Memorize both banks whole — questions rotate which items get described.

Data-collection technique bank (13) Countermeasure bank (8)
RFIDFingerprintingDrone First-party CookiesThird-party Cookies Data miningIRIS recognition Video CamerasFlash-Cookies Cross-device trackingBiometrics GPS trackingBehavioral profiling Encryption toolPrivacy Preferences (P3P) Anti-virus softwareRaise Awareness Access Control PoliciesFirewall Multi-Factor Authentication (MFA) User-Consent Management

Known scenario→answer pairs from the exam text: Dataveillance = general monitoring techniques · Hard-to-detect/delete cookies = Flash-Cookies · Verifying identity via intrinsic physical traits = Biometrics · Short-range chip + reader = RFID · Summary of device software/hardware settings = Fingerprinting · Shopping data → healthy habits or insurance decisions = Data mining.