220-1102 Security Practice Question
An employee holds the door for a person who claims to have forgotten their badge. The person does not present any identification but is allowed into the secure area. Later, it is discovered that the person was an unauthorized individual. Which type of social engineering attack occurred?
⚠ Common exam trap
Many candidates confuse tailgating with shoulder surfing because both involve physical proximity, but tailgating is about unauthorized physical entry while shoulder surfing is about visual observation of credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area without presenting proper credentials. In this scenario, the employee held the door for someone who claimed to have forgotten their badge, allowing the unauthorized person to bypass access control systems such as card readers or biometric scanners. This exploits human courtesy and the lack of enforcement of security policies like 'no tailgating' or mantrap protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering attack conducted through electronic communication—typically email, SMS, or fraudulent web pages—where the attacker impersonates a trusted source to deceive a user into revealing credentials, clicking a malicious link, or downloading malware. It can be executed from anywhere and usually relies on spoofed domains, urgency, or specially crafted attachments, not on physical proximity or entry into a secured building. In this scenario the employee is physically holding the door for someone at the access point, so the attack mechanism is unauthorized physical entry, not an electronic deception attempt.
- ✓
Tailgating
Why this is correct
Tailgating is a physical access-control attack in which an unauthorized person follows an authorized employee through a door, turnstile, or gate without independently proving their own identity or credentials. The attacker exploits the employee's goodwill, sense of common courtesy, or reluctance to stop them from entering, and because the door is already unlocked by the employee's badge, the attacker gains entry without passing through the security check. This exactly matches the scenario of holding the door for a person who claims to have forgotten or lost their credentials, because the unauthorized person bypasses the controlled entry point.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a telephone-based social engineering technique in which the attacker calls a victim while impersonating a trusted organization such as the IT help desk or a bank, then pressures or tricks the victim into disclosing passwords, PINs, or remote-access codes. It is a purely audio/logical attack that occurs over a voice channel and never requires the caller to set foot in the target's facility. Since the described incident involves someone physically entering through a door that an employee is holding open, a phone-based voice scam cannot be the correct explanation.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is the act of covertly looking over a victim's shoulder to observe private data such as a password, PIN, or credit card number while that data is being entered into a keyboard, phone, or ATM. It is an informational attack that requires line-of-sight to the input device, but it does not involve moving through physical access barriers or gaining entry to a secured space. The employee's action of holding the door for someone describes a breach of physical perimeter security, not the visual theft of credentials.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician observes an individual closely following an employee through a secured door that requires a badge swipe. The individual does not use a badge and enters behind the employee. Which social engineering technique is being exhibited?
easy- A.Phishing
- ✓ B.Tailgating
- C.Vishing
- D.Shoulder surfing
Why B: Tailgating is a physical social engineering attack where an unauthorized person follows an authorized employee through a secured entry point, such as a door requiring a badge swipe, without using their own credentials. The attacker exploits the employee's politeness or lack of vigilance to bypass access control systems, which rely on authentication per individual. This technique directly matches the scenario of an individual closely following an employee through a badge-secured door without swiping a badge.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.