Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

An employee allows a delivery person to enter a secure office building by holding the door open. The delivery person does not have an access badge. Which social engineering attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tailgating

Tailgating (or piggybacking) occurs when an unauthorized person follows an authorized person into a restricted area without proper authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing delivers fraudulent messages that trick a recipient into revealing credentials or clicking malicious links; it operates through email or messaging, not physical entry. It is tempting because both are social engineering, but tailgating exploits in-person courtesy at a controlled doorway, with no deceptive correspondence involved.

  • ✓

    Tailgating

    Why this is correct

    Tailgating occurs when an unauthorised person follows an authorised individual through a secured entry point without presenting credentials. The delivery person gained access solely because the employee held the door, satisfying the stem's scenario of bypassing badge control.

  • ✗

    Baiting

    Why it's wrong here

    Baiting leaves a tempting physical or digital item, such as an infected USB drive, for a victim to pick up and use. It is tempting because baiting also exploits curiosity in person, but here no lure was offered; the attacker simply walked through a door held open by a polite employee.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting invents a fabricated scenario or persona to extract information or access from a target, usually by phone or email. It is tempting because the delivery uniform is a guise, but no fabricated story was presented; the intruder gained entry purely by following an authorised person through the door.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An attacker gains physical access to a building by following an employee through a secured door without using a badge. This is an example of which social engineering technique?

hard
  • A.Phishing
  • B.Baiting
  • C.Pretexting
  • ✓ D.Tailgating

Why D: Tailgating (also called piggybacking) is the social engineering technique where an attacker follows an authorized employee through a secured door without using their own credentials. It exploits politeness or inattention rather than technical vulnerabilities, and it is a physical social engineering attack.

Variation 2. An employee is tailgated into a secure office building by someone without a badge. Which type of security threat does this represent?

medium
  • A.Phishing
  • ✓ B.Tailgating
  • C.Baiting
  • D.Pretexting

Why B: Tailgating is the correct answer because it specifically describes an unauthorized person following an authorized employee through a secure door without presenting credentials. This is a physical security threat, not a social engineering attack conducted remotely. The scenario matches the definition exactly.

Variation 3. An attacker gains physical access to a secure area by following an authorized employee through a door that requires a badge. This social engineering technique is known as:

medium
  • A.Pretexting
  • B.Phishing
  • ✓ C.Tailgating
  • D.Baiting

Why C: Tailgating (or piggybacking) is when an unauthorized person follows an authorized person into a restricted area without proper authentication.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.