Show Social media users’ concerns about their privacy have spiked in recent years. Incidents of data breaches have alarmed many users and forced them to rethink their relationships to social media and the security of their personal information. The dramatic story of the consulting agency Cambridge Analytica is a case in point. The firm exploited the private information of over 50 million Facebook users to influence the 2016 American presidential election. This example and others have steadily deteriorated public trust and resulted in many users wondering if they have lost control over their own data. According to a study conducted by the Pew Trust, 80 percent of social media users report being concerned about businesses and advertisers accessing and using their social media posts. These growing privacy concerns have prompted advocacy for tighter regulations. In addition, they have placed companies responsible for safeguarding personal data under greater scrutiny. Given today’s social media privacy issues and concerns, skilled cybersecurity professionals will play a vital role in protecting social media users’ data and personal information. Those interested in gaining the expertise needed to launch a career in cybersecurity would do well to consider earning an advanced degree in cybersecurity management. Learn More About a Master in Cybersecurity ManagementUnderstanding Social Media Privacy IssuesWhat are social media users worried about? Are their concerns justified? Typically, these concerns stem from the ubiquitous presence of social media in people’s lives. Forty-five percent of the world’s population uses social networks. That means a staggering 3.48 billion people connect to some form of social media, according to data collected by Hootesuite. These connections can leave users vulnerable in several ways. When personal information falls into the wrong hands, the consequences can be damaging. According to the Pew Trust, 13 percent of Americans have had their social media accounts taken over by an unauthorized user. Such hacks can result in stolen information and forced shares that redirect followers to malware, among other things. In general, social media platforms, which collect and store huge amounts of personal information with limited governmental oversight, serve as attractive targets for bad actors seeking to use that data to perpetrate fraud and theft. Another rising concern, exacerbated by Cambridge Analytica’s breach of Facebook data, centers on how bad actors access private data from social media platforms and elsewhere and use it to manipulate opinions for the benefit of a few. For example, the Russian operation Internet Research Agency is accused of interfering in the U.S. presidential election of 2016 by using social media to spread disinformation that stirred up conflict and distrust. Threats to Privacy on Social MediaCriminals are adept at tricking social media users into handing over sensitive information, stealing personal data, and gaining access to accounts users consider private. Following are typical social media threats. Data Mining Phishing Attempts Malware Sharing Botnet Attacks Social Media Privacy Issues in 2020The attacks outlined above will continue to pose privacy threats in 2020. In fact, as the 2020 presidential election draws near, these attacks will likely increase. Earlier this year, Politico reported that wide-ranging disinformation campaigns aimed at Democratic candidates had already begun. Attackers employing the same tactics as the trolls from Internet Research Agency are now using social media data to wage a disinformation “war” designed to confuse and polarize Americans. The cyber-propaganda is often disseminated via bot accounts, which use mined data to target preferred audiences. The full impact of social media attacks on the 2020 state, federal, and presidential elections is hard to predict. Become an Expert in CybersecurityThe importance of comprehensively addressing social media privacy issues cannot be underestimated. The challenge calls for skilled experts. Going to the next level in cybersecurity management requires the right training from top professionals knowledgeable in the field. Learn more about how Tulane University’s Online Master of Professional Studies in Cybersecurity Management prepares graduates to tackle today’s serious cybersecurity challenges.
Download our e-brochure today for more information about our Master in Cybersecurity Management By submitting this form, you agree to receive information about the Tulane School of Professional Advancement’s programs via email, phone and/or text. You may opt out at any time. Sources: We thoroughly check each answer to a question to provide you with the most correct answers. Found a mistake? Let us know about it through the REPORT button at the bottom of the page.
powered by Advanced iFrame free. Get the Pro version on CodeCanyon. *SPILLAGE* Be aware of classification markings and all handling caveats. *SPILLAGE* Label all files, removable media, and subject headers with appropriate classification markings. * CLASSIFIED DATA* *CLASSIFIED DATA* Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material. *INSIDER THREAT* *INSIDER THREAT* They may wittingly or unwittingly use their authorized access to perform actions that result in the loss or degradation of resources or capabilities. *INSIDER THREAT* New interest in learning a foregin language. *SOCIAL NETWORKING* If you participate in or condone it at any time. *SOCIAL NETWORKING* After you have returned home following the vacation. *SOCIAL NETWORKING* Understanding and using the available privacy settings. *UNCONTROLLED CLASSIFIED INFORMATION* *UNCONTROLLED CLASSIFIED INFORMATION* Sensitive information may be stored on any password-protected system. Select the information on the data sheet that is personally identifiable information (PII) But not protected health information (PHI) Jane Jones Select the information on the data sheet that is protected health information (PHI) Jane has been Dr…ect patient..ect. *PHYSICAL SECURITY* Ask the individual to see an identification badge. *IDENTITY MANAGEMENT* Identification, encryption, and digital signature *IDENTITY MANAGEMENT* *SENSITIVE COMPARTMENTED INFORMATION* Mark SCI documents appropriately and use an approved SCI fax machine. *SENSITIVE COMPARTMENTED INFORMATION* At all times while in the facility. *REMOVABLE MEDIA IN A SCIF* Identify and disclose it with local Configuration/Change Management Control and Property Management authorities *MALICIOUS CODE* Legitimate software updates *WEBSITE USE* You should only accept cookies from reputable, trusted websites. *SOCIAL ENGINEERING* Use online sites to confirm or expose potential hoaxes *SOCIAL ENGINEERING* Follow instructions given only by verified personnel *SOCIAL ENGINEERING* Investigate the link’s actual destination using the preview feature *TRAVEL* Others may be able to view your screen. *USE OF GFE* Determine if the software or service is authorized *MOBILE DEVICES* A smartphone that transmits credit card payment information when held in proximity to a credit card reader. *MOBILE DEVICES* *HOME COMPUTER SECURITY* Create separate accounts for each user. *Spillage Attempt to change the subject to something non-work related, but neither confirm nor deny the article’s authenticity. *Spillage Label all files, removable media, and subject headers with appropriate classification markings. *Spillage Spillage because classified data was moved to a lower classification level system without authorization. *Spillage Call your security point of contact immediately *Spillage Ask for information about the website, including the URL. *Spillage Refer the reporter to your organization’s public affairs office. *Spillage ~Immediately notify your security POC. *Spillage Be aware of classification markings and all handling caveats. **Classified Data Store classified data appropriately in a GSA-approved vault/container. **Classified Data Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know **Classified Data **Classified Data Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material. **Classified Data Classified material must be appropriately marked. **Classified Data Damage to national security **Insider Threat New interest in learning a foreign language **Insider Threat 1 Indicator(wrong) **Insider Threat **Insider Threat **Insider Threat **Insider Threat Insiders are given a level of trust and have authorized access to Government information systems **Insider Threat Coworker making consistent statements indicative of hostility or anger toward the United States in its policies. **Insider Threat A coworker removes sensitive information without authorization **Insider Threat ~A coworker brings a personal electronic device into a prohibited area. **Social Networking When vacation is over, after you have returned home **Social Networking *Sensitive Information As long as the document is cleared for public release, you may share it outside of DoD. *Sensitive Information *Sensitive Information *Sensitive Information *Sensitive Information For Official Use Only (FOUO) *Sensitive Information If aggregated, the information could become classified. **Physical Security Challenge people without proper badges. **Physical Security **Identity Management On a NIPRNet system while using it for a PKI-required task **Identity Management Something you possess, like a CAC, and something you know, like a PIN or password **Identity management Use a common password for all your system and application logons. **Identity management Maintain possession of it at all times. *Sensitive Compartmented Information A program that segregates various type of classified information into distinct compartments for added protection and dissemination for distribution control. *Sensitive Compartmented Information A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner. *Sensitive Compartmented Information ~All documents should be appropriately marked, regardless of format, sensitivity, or classification.Unclassified documents do not need to be marked as a SCIF.Only paper documents that are in open storage need to be marked. Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong) *Sensitive Compartmented Information Security Classification Guide (SCG) **Removable Media in a SCIF It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number. *Malicious Code Viruses, Trojan horses, or worms **Website Use Since the URL does not start with “https,” do not provide you credit card information. **Social Engineering Do not access links or hyperlinked media such as buttons and graphics in email messages. **Social Engineering Phishing can be an email with a hyperlink as bait. **Social Engineering Follow instructions given only by verified personnel. **Travel Maintain possession of your laptop and other government-furnished equipment (GFE) at all times. **Use of GFE If allowed by organizational policy **Mobile Devices Do not use any personally owned/non-organizational removable media on your organization’s systems. **Mobile Devices Secure personal mobile devices to the same level as Government-issued systems. **Home Computer Security Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals. What is the best response if you find classified government data on the internet? Note any identifying information, such as the website’s URL, and report the situation to your security POC. What information posted publicly on your personal social networking profile represents a security risk? What is the best example of Protected Health Information (PHI)? Your health insurance explanation of benefits (EOB) What does Personally Identifiable Information (PII) include? Social Security Number; date and place of birth; mother’s maiden name What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card? Identification, encryption, and digital signature What describes how Sensitive Compartmented Information is marked? Approved Security Classification Guide (SCG) Which is a risk associated with removable media? Spillage of classified information. What is an indication that malicious code is running on your system? What is a valid response when identity theft occurs? Report the crime to local law enforcement. A type of phishing targeted at high-level personnel such as senior officials. What is a best practice to protect data on your mobile computing device? Lock your device screen when not in use and require a password to reactivate. What is a possible indication of a malicious code attack in progress? A pop-up window that flashes and warns that your computer is infected with a virus. Which of the following may be helpful to prevent inadvertent spillage? Which of the following may be helpful to prevent inadvertent spillage? What should you do after you have ended a call from a reporter asking you to confirm potentially classified info found on the web? Alert your security point of contact. Which of the following is NOT an example of sensitive information? Which of the following is NOT an example of sensitive information? SSN, date and place of birth, mother’s maiden name, biometric records, PHI, passport number Subset of PII, health information that identifies the individual, relates to physical or mental health of an individual, provision of health care to an individual, or payment of healthcare for individual Which of the following is NOT a typical result from running malicious code? What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure? Have your permissions from your organization, follow your organization guideline, use authorized equipment and software, employ cyber security best practice, perform telework in dedicated when home. Which of the following should be reported as a potential security incident (in accordance with your Agency’s insider threat policy)? A coworker brings a personal electronic device into prohibited areas. A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display? A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and occasionally aggressive in trying to access sensitive information. How many potential insider threat indicators does this employee display? What information most likely presents a security risk on your personal social networking profile? Which of the following represents a good physical security practice? Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIC) card. How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card? Store it in a shielded sleeve to avoid chip cloning. Which of the following statements is NOT true about protecting your virtual identity? Use personal information to help create strong passwords. While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do? Since the URL does not start with “https,” do not provide your credit card information. You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take? Contact the IRS using their publicly available, official contact information. Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email? Do not access links or hyperlinked media such as buttons and graphics in email messages. Which of the following is true of Internet hoaxes? They can be part of a distributed denial-of-service (DDoS) attack. Which of the following is NOT true of traveling overseas with a mobile phone? Physical security of mobile phones carried overseas is not a major issue. A coworker has asked if you want to download a programmer’s game to play at work. What should be your response? A coworker wants to send you a sensitive document to review while you are at lunch and you only have your personal tablet. What should you do? Never allow sensitive data on non-Government-issued mobile devices. A man you do not know is trying to look at your Government-issued phone and has asked to use it. What should you do? Decline to lend the man your phone. How can you protect your information when using wireless technology? Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals. What should you do if a reporter asks you about potentially classified information on the web? Neither confirm or deny the information is classified. Which of the following may be helpful to prevent inadvertent spillage? Label all files, removable media, and subject headers with appropriate classification markings. What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure? Which of the following is NOT true concerning a computer labeled SECRET? May be used on an unclassified network. A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display? Which of the following should be reported as a potential security incident? A coworker removes sensitive information without approval. Which of the following should be reported as a potential security incident (in accordance with your Agency’s insider threat policy)? A coworker brings a personal electronic device into prohibited areas. When would be a good time to post your vacation location and dates on your social networking website? When you return from your vacation. In setting up your personal social networking service account, what email address should you use? Your personal email address. Which of the following is NOT a correct way to protect sensitive information? Sensitive information may be stored on any password-protected system. Which of these is true of unclassified data? It’s classification level may rise when aggregated. Is it permitted to share an unclassified draft document with a non-DoD professional discussion group? As long as the document is cleared for public release, you may share it outside of DoD. Within a secure area, you see an individual you do not know. Her badge is not visible to you. What is the best course of action? Ask the individual to identify herself. How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card? Store it in a shielded sleeve to avoid chip cloning. Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approves for access to the NIPRNET. In which situation below are you permitted to use your PKI token? On a NIPRNET system while using it for a PKI-required task After clicking on a link on a website, a box pops up and asks if you want to run an application. Is it okay to run it? No. Only allow mobile code to run from your organization or your organization’s trusted sites. Upon connecting your Government- issued laptop to a public wireless connection, what should you immediately do? Connect to the Government Virtual Private Network (VPN). What do you do if spillage occurs? Immediately notify your security point of contact. What should you do after you have ended a call from a reporter asking you to confirm potentially classified information found on the web? Alert your security point of contact. Which of the following is NOT a requirement for telework? You must possess security clearance eligibility to telework. Who can be permitted access to classified data? Only persons with appropriate clearance, a non-disclosure agreement, and need-to-know can access classified data. A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and is occasionally aggressive in trying to access sensitive information. How many potential insiders threat indicators does this employee display? A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insiders threat indicators does this employee display? A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insiders threat indicators does this employee display? In setting up your personal social networking service account, what email address should you use? Your personal email address What information most likely presents a security risk on your personal social networking profile? Which of the following is NOT an example of sensitive information? Is it permitted to share an unclassified draft document with a non-DoD professional discussion group? As long as the document is cleared for public release, you may release it outside of DoD Which of the following is an example of Protected Health Information (PHI)? I’ve tried all the answers and it still tells me off. Examples are: Patient names, Social Security numbers, Driver’s license numbers, insurance details, and birth dates Which of the following represents a good physical security practice? Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIC) card. Which of the following is NOT a good way to protect your identity? Use a single, complex password for your system and application logons. Which of the following statements is TRUE about the use of DoD Public Key Infrastructure (PKI) tokens? Always use DoD PKI tokens within their designated classification level. Which of the following is NOT a typical means for spreading malicious code? Patching from a trusted source Which of the following is a practice that helps to protect you from identity theft? Ordering a credit report annually Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email? Do not access links or hyperlinked media such as buttons and graphics in email messages. You receive an unexpected email from a friend: “I think you’ll like this: https://tinyurl.com/2fcbvy.” What action should you take? Use TinyURL’s preview feature to investigate where the link leads. You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take? When using your government-issued laptop in public environments, with which of the following should you be concerned? The potential for unauthorized viewing of work-related information displayed on your screen. Under what circumstances is it acceptable to check personal email on Government-furnished equipment (GFE)? If your organization allows it. Which of the following is NOT a best practice to protect data on your mobile computing device? Lock your device screen when not in use and require a password to reactivate. When checking in at the airline counter for a business trip, you are asked if you would like to check your laptop bag. This bag contains your government-issued laptop. What should you do? I’ve tried all the answers and it still tells me off, part 2. Decline So That You Maintain Physical Control of Your Government-Issued Laptop. How can you protect your information when using wireless technology? Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals. Let us know if this was helpful. That’s the only way we can improve. |