Practical Security Takeaways and Tips & Wrap - Up
Practical Security Takeaways & Tips
Prompt:
Now that you have completed the Practical Security Unit, identify to your classmates your take away's and name at least one tip you would like to share with someone not in CIS 141.
Response:
I think one of main take-aways from the Practical Security unit was the importance of cybersecurity. It’s important to not only identify types of virus but also take responsibility for one’s cybersecurity. One tip I would give to someone who is not in CIS 141 is to take cybersecurity into their own hands. Some ways to do this are: create strong passwords, use a password manager, use a secure browser, and install anti-malware software like a firewall.
Wrap-Up
Prompt:
This unit introduced students to the following course competencies:
- Explain different cybersecurity risks
- Demonstrate how to implement different cybersecurity tools
- Discuss the necessary steps to secure a computer from attacks
What have you recognized as your "takeaways" from learning more on cybersecurity from your completion of the Security Awareness Unit?
How has learning computer security affected your daily life and technology use? Please explain.
Response:
Different types of cybersecurity risks/threats include: exploitation of vulnerabilities by cybercriminals; viruses like the trojan virus; a worm; malware; spam; malvertising; drive-by downloads; ransomware; identify theft/leaked personal data; social engineering; phishing; and so on.
One type of attack method is through social manipulation. There are a number of different ways this threat occurs. One way is through phishing. Phishing is when an attacker tricks an user into opening an email or another message. Often this message looks completely innocent, like a tempting Job Offer. Another type of social attack is social engineering, which is when an attacker tricks someone into revealing personal info.
Another type of attack method is hidden threats. This includes: malvertising, trojan virus, and drive-by downloads. Malvertising occurs when malware is inserted into an user’s computer through an ad page. Usually, the user will click on the ad, which leads them to the hacker’s webpage. Similarly, a drive-by download is an unauthorized download that occurs when a user visits a certain website; usually the attackers have already exploited a vulnerability in the site to gain access to the user’s computer. Lastly, a Trojan virus is a virus that is disguised as a harmless program. For example, a hacker could hide their virus under the disguise of a game download, like Minesweeper.
There are certain tools and settings that can protect a user from attacks. For example, they can use web-based settings. Modern web browsers have detailed settings menus, where users can decide if they want the browser to block: third-party cookies, cross-site tracking, JavaScript, Ad Pop-ups and unsecured websites.
Users can also use settings that programs meant for their computer (hardware). One simple thing every user can do is keep on top of installing security patches. Often, the computer will even notify you when an update is available and remind you to download it. Another thing users can do is install a firewall, which helps limit the spread of malware. Another program worth installing is anti-virus software. This software scans for viruses, and creates a detailed report for the user.
Some of the necessary steps to prevent attackers is to take control of one’s cyber security now. Start using strong passwords as well as password managers. Update security options when and where you can by updating security settings in your browser and downloading patches for your computer when they become available. Also, install trustworthy software to run programs like data back-up, anti-virus scans, and firewall.
One of my main take-aways from the unit was the importance of being vigilant against attackers. Taking measures to secure my browser and my computer is a lot more important than I realized.
After learning about computer security, I have installed a VPN to filter out untrustworthy sites and strengthened the password I use for my WKU account.