Explain how unauthorized access to computing resources is gained.

IOC-2.C.1 Phishing is a technique that attempts to trick a user into providing personal information. That personal information can then be used to access sensitive online resources, such as bank accounts and emails.

IOC-2.C.2 Keylogging is the use of a program to record every keystroke made by a computer user in order to gain fraudulent access to passwords and other confidential information.

IOC-2.C.3 Data sent over public networks can be intercepted, analyzed, and modified. One way that this can happen is through a rogue access point.

IOC-2.C.4 A rogue access point is a wireless access point that gives unauthorized access to secure networks.

IOC-2.C.5 A malicious link can be disguised on a web page or in an email message.

IOC-2.C.6 Unsolicited emails, attachments, links, and forms in emails can be used to compromise the security of a computing system. These can come from unknown senders or from known senders whose security has been compromised.

IOC-2.C.7 Untrustworthy (often free) downloads from freeware or shareware sites can contain malware.