220-1102 Security Practice Question
Which of the following scenarios best describes a tailgating attack?
⚠ Common exam trap
It's easy for candidates to confuse tailgating with phishing (Option B) because both are social engineering, but tailgating is a physical attack, not a digital one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker follows an employee through a secured door without using their own access credentials
A tailgating attack is a physical security breach where an unauthorized person follows an authorized individual into a restricted area without using their own access credentials, such as a badge or keycard. This exploits the human tendency to hold doors for others, bypassing electronic access control systems like RFID readers or PIN pads. The correct answer is A because it directly describes this social engineering tactic that targets physical perimeter defenses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An attacker follows an employee through a secured door without using their own access credentials
Why this is correct
This is the classic definition of tailgating, a physical security attack in which an unauthorized person slips through a controlled access point by closely following an authorized employee through a badge-secured door, turnstile, or man-trap. The attacker avoids presenting their own credentials, instead exploiting the employee's courtesy or inattention to gain entry to a restricted area. Unlike piggybacking, which often involves the employee's consent, tailgating generally occurs without the victim's knowledge or permission, bypassing electronic access controls through social engineering rather than technical exploitation.
- ✗
An attacker sends a fraudulent email asking for sensitive information
Why it's wrong here
This describes a phishing attack, which is a digital social engineering technique where the attacker sends fraudulent emails, text messages, or other communications that appear to be from a trusted source to trick the recipient into revealing sensitive information like passwords, credit card numbers, or personal data. The attack occurs entirely in the communication layer and does not require physical presence or access to a secured facility. It relies on psychological manipulation to elicit a response, whereas tailgating relies on physical proximity and following an authorized person through a controlled entrance.
- ✗
An attacker installs a hardware device to log keystrokes
Why it's wrong here
This describes a keylogger attack, a form of surveillance where the attacker installs a small hardware device—such as a USB plug-in or a device connected between the keyboard and the computer—to capture and record every keystroke a user types. This is a hardware-level compromise that targets data theft, such as capturing login credentials or confidential messages, and requires the attacker to have physical access to the computer itself, but not to a secured doorway. It is fundamentally different from tailgating, which is about unauthorized entry to a physical space rather than tampering with computing equipment.
- ✗
An attacker captures network traffic to intercept data
Why it's wrong here
This describes a packet sniffing attack, a network-based technique where the attacker captures and analyzes data packets as they travel across a wired or wireless network to intercept unencrypted information such as usernames, passwords, or email content. This attack occurs at the data-link or network layer of the OSI model and typically uses software tools like Wireshark or hardware probes, and it does not involve physical entry through a secure door. Tailgating, in contrast, is a physical access attack that exploits personnel behavior to breach a perimeter, not a technical interception of data.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.