220-1102 Security Practice Question
A technician is walking through the office and sees a person without a visible ID badge following closely behind an employee who just swiped their badge to enter a secured area. The person does not have a badge and is not recognized by the employee. Which type of social engineering attack is likely occurring?
⚠ Common exam trap
Many exam-takers confuse tailgating with phishing or vishing because all three are social engineering attacks, but the question's physical context (badge swipe, secured area) clearly distinguishes tailgating as the only option involving unauthorized physical access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
The scenario describes an attacker physically following an authorized employee through a secured door without using their own credentials. This is the classic definition of tailgating (also known as piggybacking), a physical social engineering attack that bypasses access control systems such as badge readers or PIN pads. The key detail is that the unauthorized person closely follows the employee who swiped their badge, exploiting the door's open time window to gain entry without authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a form of social engineering conducted through electronic communication, typically via deceptive emails, text messages, or fraudulent websites, to trick victims into revealing passwords, credit card numbers, or other sensitive data. The described scenario involves an individual physically entering a secure office space without a badge, which is an access control breach, not an electronic lure or credential-harvesting attempt. Since no digital message or fraudulent website is used, phishing does not apply.
- ✓
Tailgating
Why this is correct
Tailgating, also known as piggybacking, occurs when an unauthorized person gains access to a restricted area by closely following an authorized individual through a secured entry point, often before the door closes or by blending in with a group. The lack of a visible badge and the person being unrecognized are classic indicators that they did not independently authenticate, bypassing physical security controls like badge readers, keypads, or mantraps. This is a direct, physical social engineering technique, making Tailgating the correct classification.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack executed over phone calls or VoIP systems, where the attacker impersonates a trusted entity to manipulate the victim into providing confidential information such as account credentials, PINs, or payment details. In the given scenario, the incident is entirely physical—an unrecognized person without a badge walking into an office—with no remote voice communication or telephone interaction involved. Therefore, vishing does not describe the attack.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is a technique where an attacker visually obtains sensitive information, such as passwords, PINs, or other confidential data, by looking over a victim's shoulder as they enter it on a device or keypad. The scenario described focuses on unauthorized physical entry into a secure area by bypassing access controls, not on observing a legitimate user's keystrokes or screen. Since no information is being observed or captured, this option is incorrect.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Tailgating
Tailgating is a physical security breach where an unauthorized person follows an authorized person into a restricted area without proper authentication.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.