hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security audit, a technician discovers…
During a security audit, a technician discovers that an unauthorized person accessed a restricted server room by pretending to be a fire inspector. The person had a fake ID and clipboard. Which social engineering technique was used, and what is the best mitigation?
⚠ Common exam trap
CompTIA often tests the distinction between pretexting and tailgating, where candidates confuse impersonation with simply following someone through a door; the trap here is that the fake ID and clipboard clearly indicate a fabricated identity (pretexting), not physical piggybacking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting; enforce visitor check-in and verification procedures.
The attacker used a fabricated identity (fake ID and clipboard) to create a false scenario—pretending to be a fire inspector—which is the hallmark of pretexting. The best mitigation is to enforce visitor check-in and verification procedures, such as requiring government-issued ID validation and escort policies, to prevent unauthorized access based on fabricated roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tailgating; install mantraps at entrances.
Why it's wrong here
Tailgating is a physical security breach where an unauthorized individual gains entry by closely following an authorized person through a secured checkpoint without presenting their own credentials. While installing mantraps at entrances is an effective physical control designed to prevent tailgating by physically separating individuals and ensuring only one person enters per credential scan, it does not address the scenario of an attacker using a fabricated identity to gain access, which is a form of pretexting.
- ✗
Phishing; implement email filtering.
Why it's wrong here
Phishing is a cyberattack where attackers attempt to trick individuals into revealing sensitive information or installing malware, typically through deceptive emails, text messages, or websites. Implementing email filtering is a crucial technical control to detect and block malicious emails, thereby mitigating phishing attempts by preventing them from reaching the user's inbox. However, email filtering is entirely ineffective against physical impersonation or an attacker using a fabricated identity in person, as it operates solely within the digital communication realm.
- ✓
Pretexting; enforce visitor check-in and verification procedures.
Why this is correct
Pretexting is a social engineering tactic where an attacker invents a fabricated scenario or identity to manipulate a target into divulging information or granting access. Enforcing strict visitor check-in and verification procedures directly counters pretexting by requiring visitors to present valid identification and verifying their stated purpose against official records or scheduled appointments. This process, often combined with requiring escorts for all visitors, prevents unauthorized individuals from gaining physical access under false pretenses.
- ✗
Baiting; disable USB ports on workstations.
Why it's wrong here
Baiting is a social engineering attack that involves luring victims with a tempting offer, such as free software, a seemingly lost USB drive, or an enticing download, to compromise their systems or extract data. Disabling USB ports on workstations is a strong technical control to prevent baiting attacks that rely on physical media, as it eliminates a common vector for introducing malware or unauthorized data access. However, this measure does not address an attacker who physically impersonates someone using a fabricated identity to gain access, as that is a different social engineering vector.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.