Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user notices an unknown person following closely behind them through a secured door that requires a badge. The person does not badge in but gains entry. Which type of social engineering attack is this?

⚠ Common exam trap

Many exam-takers confuse tailgating with shoulder surfing because both involve physical proximity, but shoulder surfing specifically targets visual observation of credentials or data, not unauthorized physical entry through a secured door.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tailgating

Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual through a secured entry point, such as a badge-controlled door, without using their own credentials. The core mechanism relies on the authorized user's courtesy or inattention, bypassing the access control system entirely. This is distinct from other attacks because it exploits human behavior and physical security protocols rather than digital deception.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering tactic that relies on deceptive emails, text messages, or fraudulent websites to trick victims into revealing credentials, downloading malware, or transferring money. It is a remote or digitally mediated attack that does not involve physically following a person through a secured entrance. Since the scenario describes an unknown person close behind in a physical space, phishing is unrelated to this type of unauthorized access.

  • ✓

    Tailgating

    Why this is correct

    Tailgating is a physical security attack in which an unauthorized individual gains entry to a restricted area by closely following an authorized person through an access-controlled door, turnstile, or gate. The attacker takes advantage of the authorized person's access credentials without having to present their own, often in a crowded or high-traffic environment. This precisely matches the user's observation of an unknown person following closely behind them, so it is the correct classification.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is a form of social engineering in which an attacker invents a believable fictional scenario (such as posing as an IT technician or a bank representative) to persuade a victim to disclose sensitive information or grant system access. It typically involves verbal interaction and the cultivation of trust rather than silent physical proximity. Following someone through a doorway without explanation is not an act of pretexting because no fabricated story is being presented to gain that physical entry.

  • ✗

    Shoulder surfing

    Why it's wrong here

    Shoulder surfing involves an attacker visually observing a victim's display, keyboard, or written notes to steal passwords, PINs, or other confidential data, often by standing or leaning nearby. The key element is surreptitious observation of information, not the act of bypassing a physical access control system. In the scenario, the person is following closely behind another, not necessarily looking at a screen or keypad, so this does not describe shoulder surfing.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.