Courseiva
mediumMultiple Choice

220-1102 Practice Question: During a security audit, a technician notices…

During a security audit, a technician notices that an unauthorized person is standing just behind an employee at the secure door, waiting for the employee to badge in so they can enter without badging themselves. What type of social engineering attack is being attempted?

⚠ Common exam trap

CompTIA often tests the distinction between tailgating and pretexting, where candidates mistakenly choose pretexting because they think the attacker is 'pretending' to be authorized, but the key difference is that tailgating requires no verbal deception—just physical proximity and timing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tailgating

Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a secured area without using their own credentials. In this scenario, the attacker waits for the employee to badge in and then slips through the door before it closes, bypassing the access control system. This exploits the trust or politeness of the employee and the physical security gap between the door closing and the authentication check.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting builds a fabricated scenario, often by phone or email, to extract information or access. It is tempting because pretexting can gain physical entry, but here the attacker invents no story and simply follows the employee through the door.

  • ✗

    Baiting

    Why it's wrong here

    Baiting lures a victim with something desirable, such as an infected USB drive left in a car park. It is tempting because baiting also targets human curiosity, but no lure or found device appears in this scenario, only unauthorised physical entry.

  • ✓

    Tailgating

    Why this is correct

    Tailgating occurs when an unauthorised person follows an authenticated employee through a secure door without badging themselves, exploiting the employee's legitimate access. This matches the observed behaviour of someone standing behind an employee waiting to slip in.

  • ✗

    Phishing

    Why it's wrong here

    Phishing uses fraudulent email, messages or websites to harvest credentials or deliver malware; no message is involved here. It is tempting because phishing is the most common social engineering technique, and would be correct if the attacker had emailed the employee a fake login page.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.