Courseiva
Question 157 of 495
easyMultiple ChoiceObjective-mapped

Tailgating: Exploiting Human Politeness

A receptionist holds the door for a person carrying a large box, assuming they work in the building. Later, that person is seen plugging a USB drive into a workstation in the finance department. Which social engineering technique was most likely used to gain initial access?

Quick Answer

The correct answer is tailgating, a social engineering technique that exploits human politeness and the natural instinct to hold doors for others, allowing an unauthorized person to gain physical access to a restricted area. In this scenario, the attacker leveraged the receptionist’s assumption that someone carrying a large box must be an employee, bypassing security without any credentials. On the CompTIA A+ Core 2 220-1202 exam, tailgating questions often test your ability to distinguish it from other attacks like phishing or baiting, with a common trap being to confuse it with shoulder surfing—remember that tailgating is about physical entry, not observation. A useful memory tip is to think of “tailgating” like following a car through a gate; the attacker literally rides on the coattails of an authorized person’s courtesy.

⚠ Common exam trap

Candidates often confuse tailgating with pretexting, as both involve deception, but tailgating specifically relies on physical proximity and social norms rather than a fabricated story or identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Tailgating

Tailgating involves an unauthorized person gaining physical access to a secure area by following an authorized individual. In this scenario, the receptionist held the door for the person carrying a large box, assuming they worked in the building, which allowed the attacker to bypass physical security controls without authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing involves digital deception, not physical access through following someone into a building.

  • Pretexting

    Why it's wrong here

    Pretexting involves fabricating a scenario to obtain information, not simply following someone through a door.

  • Tailgating

    Why this is correct

    Tailgating occurs when an unauthorized person follows an authorized person into a restricted area without proper authentication.

  • Baiting

    Why it's wrong here

    Baiting involves offering something enticing (like a free USB drive) to trick victims, not physically following someone.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 220-1202

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a routine security audit, a technician discovers that an unknown person has been using a badge to enter the building after hours. The badge belongs to a former employee who left the company six months ago. Which type of social engineering attack likely enabled this unauthorized access?

medium
  • A.Phishing
  • B.Tailgating
  • C.Dumpster diving
  • D.Shoulder surfing

Why B: Tailgating. This attack involves an unauthorized person physically following an authorized individual into a secured area without using their own valid credentials. In this scenario, the unknown person likely used the former employee's badge as a prop to appear legitimate, reducing suspicion while closely following an authorized person through a door or turnstile. The fact that the badge was not deactivated is a separate security vulnerability, but the act of gaining entry by following someone, often facilitated by such deception, is characteristic of tailgating.

Variation 2. During a security audit, a technician notices that an unauthorized person is standing just behind an employee at the secure door, waiting for the employee to badge in so they can enter without badging themselves. What type of social engineering attack is being attempted?

medium
  • A.Pretexting
  • B.Baiting
  • C.Tailgating
  • D.Phishing

Why C: Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a secured area without using their own credentials. In this scenario, the attacker waits for the employee to badge in and then slips through the door before it closes, bypassing the access control system. This exploits the trust or politeness of the employee and the physical security gap between the door closing and the authentication check.

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.