mediumMultiple Choice
220-1102 Practice Question: During a security audit, a technician notices…
During a security audit, a technician notices that an unauthorized person is standing just behind an employee at the secure door, waiting for the employee to badge in so they can enter without badging themselves. What type of social engineering attack is being attempted?
⚠ Common exam trap
CompTIA often tests the distinction between tailgating and pretexting, where candidates mistakenly choose pretexting because they think the attacker is 'pretending' to be authorized, but the key difference is that tailgating requires no verbal deception—just physical proximity and timing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a secured area without using their own credentials. In this scenario, the attacker waits for the employee to badge in and then slips through the door before it closes, bypassing the access control system. This exploits the trust or politeness of the employee and the physical security gap between the door closing and the authentication check.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pretexting
Why it's wrong here
Pretexting builds a fabricated scenario, often by phone or email, to extract information or access. It is tempting because pretexting can gain physical entry, but here the attacker invents no story and simply follows the employee through the door.
- ✗
Baiting
Why it's wrong here
Baiting lures a victim with something desirable, such as an infected USB drive left in a car park. It is tempting because baiting also targets human curiosity, but no lure or found device appears in this scenario, only unauthorised physical entry.
- ✓
Tailgating
Why this is correct
Tailgating occurs when an unauthorised person follows an authenticated employee through a secure door without badging themselves, exploiting the employee's legitimate access. This matches the observed behaviour of someone standing behind an employee waiting to slip in.
- ✗
Phishing
Why it's wrong here
Phishing uses fraudulent email, messages or websites to harvest credentials or deliver malware; no message is involved here. It is tempting because phishing is the most common social engineering technique, and would be correct if the attacker had emailed the employee a fake login page.
Go deeper
Related to this question
Learn chapter
Secure Disposal of Electronic Equipment
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.