Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A technician observes an individual closely following an employee through a secured door that requires a badge swipe. The individual does not use a badge and enters behind the employee. Which social engineering technique is being exhibited?

⚠ Common exam trap

Watch out — candidates often confuse tailgating with shoulder surfing because both involve physical proximity, but shoulder surfing specifically targets visual data capture (e.g., passwords), not unauthorized physical entry through a secured door.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tailgating

Tailgating is a physical social engineering attack where an unauthorized person follows an authorized employee through a secured entry point, such as a door requiring a badge swipe, without using their own credentials. The attacker exploits the employee's politeness or lack of vigilance to bypass access control systems, which rely on authentication per individual. This technique directly matches the scenario of an individual closely following an employee through a badge-secured door without swiping a badge.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering attack delivered via electronic communication, typically email or instant messaging, where the attacker masquerades as a trusted entity to lure the victim into clicking malicious links, downloading malware, or voluntarily providing credentials and personal data. It does not involve physical proximity or following someone through a doorway. In this scenario, the attacker's action is physical entry, not digital deception, so phishing is an incorrect classification.

  • ✓

    Tailgating

    Why this is correct

    Tailgating, also known as piggybacking, exploits the authorized person's politeness or convenience as the attacker slips through a secure access control point, such as a badge-controlled door, immediately behind the legitimate employee. Unlike a brute-force attempt, it relies on the authorized individual not challenging the follower or holding the door open. This matches the observed behavior of closely following an individual, making it the correct answer.

  • ✗

    Vishing

    Why it's wrong here

    Vishing (voice phishing) is a form of social engineering conducted over the telephone or VoIP, where the attacker impersonates a legitimate institution (e.g., bank, IT support) to coerce the victim into revealing sensitive information or performing actions like transferring funds. It entirely lacks a physical element; the attacker never needs to be near the victim. Therefore, it cannot explain the physical following behavior described in the scenario.

  • ✗

    Shoulder surfing

    Why it's wrong here

    Shoulder surfing is a passive physical observation technique where the attacker directly watches the victim's screen, keyboard, or documents to capture sensitive data such as passwords, PINs, or account numbers. While it is physical in nature, it does not involve gaining entry or following through a secure access point; the attacker observes, not accompanies. The clue 'closely following an individual' points to unauthorized physical access, not eavesdropping on visual information.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.