CSCU - Certified Secure Computer User Social Media Security Questions and Answers 1 — Questions and Answers
Question 1: A user receives a direct message on a social media platform from an account that looks like their friend's. The message contains a link with the text, "Is this you in this video?!" and creates a sense of urgency. This is a common example of which type of attack?
- A watering hole attack
- A Denial-of-Service (DoS) attack
- Clickjacking
- Phishing (Correct answer)
Correct answer: Phishing
This is a classic example of a phishing attack. The attacker impersonates a trusted contact to trick the user into clicking a malicious link, likely leading to a fake login page designed to steal their credentials.
Question 2: What is the primary security risk of authorizing third-party applications, such as games or quizzes, to access your social media account?
- They can significantly slow down your computer's performance.
- They can expose your personal data and your friends' data to be harvested or misused. (Correct answer)
- They will automatically post spam messages on your profile.
- They will cause your social media account to be suspended.
Correct answer: They can expose your personal data and your friends' data to be harvested or misused.
Third-party apps often request extensive permissions to access profile information, friend lists, and other personal data. If the app developer has poor security practices or malicious intent, this data can be collected, sold, or exposed in a breach, compromising the privacy of both you and your connections.
Question 3: Which of the following is the MOST effective security measure for preventing unauthorized access to a social media account, even if an attacker has stolen the user's password?
- Using a password that is longer than 20 characters
- Enabling two-factor authentication (2FA) (Correct answer)
- Changing the password every 30 days
- Connecting the account to a verified phone number
Correct answer: Enabling two-factor authentication (2FA)
Two-factor authentication (2FA) adds a critical second layer of security. Even if a password is stolen, an attacker cannot gain access without the second factor, which is typically a code generated by an authenticator app or sent to the user's phone.
Question 4: A user posts their full vacation itinerary, including dates and locations, on their public social media profile before they leave. What is the most significant physical security risk associated with this action?
- Their friends might become jealous of the trip.
- The social media platform could suspend their account for oversharing.
- It publicly announces that their home will be unoccupied, making it a target for burglars. (Correct answer)
- Their airline tickets could be cancelled by a malicious actor.
Correct answer: It publicly announces that their home will be unoccupied, making it a target for burglars.
Oversharing travel plans in real-time or in advance is a major physical security risk. It acts as a public announcement that a person's home is empty and vulnerable, which is information that burglars can exploit to plan a break-in.
Question 5: The process of automatically adding geographical coordinates to media like photos and posts is known as what?
- Geotagging (Correct answer)
- Geocaching
- Geofencing
- Geoblocking
Correct answer: Geotagging
Geotagging is the process of adding geographical identification to media. While it can be useful, it can also create security risks by revealing sensitive locations like your home or daily routines if shared publicly.
Question 6: When reviewing your social media privacy settings, which option is specifically designed to prevent people from finding your profile by searching for your email address or phone number?
- Setting your posts and profile to 'Private'
- Limiting who can tag you in photos
- Disabling friend requests from 'Everyone'
- Controlling who can look you up using provided contact information (Correct answer)
Correct answer: Controlling who can look you up using provided contact information
Most social media platforms have a specific privacy setting to control 'discoverability'. This option allows you to prevent others from finding your account by entering your phone number or email address into the platform's search function.
A user receives a direct message on a social media platform from an account that looks like their friend's.
The message contains a link with the text, "Is this you in this video?!" and creates a sense of urgency.
This is a common example of which type of attack?