220-1102 Security Practice Question
An employee is walking into the office building holding a coffee and their phone. A person in a uniform, carrying a clipboard, approaches and says they are from the HVAC company and need to check the thermostat on the third floor. The employee holds the door open and lets them in. This is an example of which type of social engineering attack?
⚠ Common exam trap
Test-takers frequently confuse the attacker's impersonation (wearing a uniform and carrying a clipboard) as the primary attack, when the actual social engineering technique is the physical act of following an authorized person through a secured door without authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
The employee physically holds the door open for an unauthorized person, allowing them to enter a secured area without proper authentication. This is the classic definition of tailgating (also known as piggybacking), where an attacker exploits a legitimate user's courtesy or inattention to bypass physical access controls. The scenario does not involve any electronic communication, credential harvesting, or remote deception.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a cybercrime technique that uses deceptive emails, text messages, or cloned websites to trick victims into revealing credentials, clicking malicious links, or downloading malware. It operates entirely in the digital domain and relies on the victim interacting with a fraudulent electronic message. The described activity of physically following a coffee-toting employee through an office entrance has no electronic component, so phishing is categorically the wrong classification.
- ✗
Vishing
Why it's wrong here
Vishing is a form of social engineering conducted over the phone, where an attacker impersonates a legitimate entity to coax the victim into revealing sensitive data or performing actions. The office scenario involves no voice call, audio spoofing, or telephony; the attack vector is entirely physical proximity. While vishing could precede a physical breach by gathering information, the act of following someone through a secured entrance is a distinct physical security failure known as tailgating.
- ✓
Tailgating
Why this is correct
Tailgating is a physical security attack in which an unauthorized person exploits an authorized entrant's momentum, politeness, or distraction to gain entry through a secure doorway without presenting valid credentials. In this scenario, the attacker is deliberately holding a coffee to look innocuous and to justify being close behind the employee, then steps through the door while it is unlocked, defeating the access control system. This is a pure physical access vector, not a digital or communication-based attack.
- ✗
Impersonation
Why it's wrong here
Impersonation (or pretexting) occurs when an attacker adopts a false identity—such as a courier, IT technician, or new hire—to verbally manipulate their way into a facility without directly following someone. Although the person in the scenario may be trying to look like an ordinary employee, the decisive factor is that they are physically shadowing an authorized person through a door, which is the defining characteristic of tailgating rather than identity deception alone.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Tailgating
Tailgating is a physical security breach where an unauthorized person follows an authorized person into a restricted area without proper authentication.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.