Courseiva
Social Engineering and Physical SecurityhardMultiple ChoiceObjective-mapped

CEH Social Engineering and Physical Security Practice Question

A security auditor is assessing the physical security of a corporate office building that houses a data center. The building has a single main entrance with a reception desk staffed during business hours (8 AM to 6 PM). After hours, employees use a keycard reader to access the building. The data center itself requires a separate keycard and a 6-digit PIN. The auditor notices that during lunch hours (12-1 PM), the reception desk is often unattended, and employees frequently hold the door for others to avoid using their keycard. Additionally, a recent social engineering test revealed that an attacker was able to call the help desk, claim to be a new employee, and request a password reset, which was granted without proper verification. Based on this scenario, which of the following is the MOST effective combination of controls to mitigate both the physical and social engineering weaknesses?

⚠ Common exam trap

The trap here is that candidates focus on the most obvious single weakness (e.g., tailgating or password reset) and choose a control that only fixes that one, missing the requirement for a combination that addresses both physical and social engineering flaws simultaneously.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Install a mantrap at the main entrance and require multi-factor authentication (MFA) for all password reset requests.

It addresses both weaknesses: a mantrap prevents tailgating at the main entrance (physical security), and requiring MFA for password reset requests mitigates the social engineering attack by adding an authentication factor beyond just a phone call. This combination directly counters the observed vulnerabilities—unattended reception and weak identity verification—without over-engineering or leaving gaps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Install a mantrap at the main entrance and require two-factor authentication for the data center door.

    Why it's wrong here

    Installing a mantrap at the main entrance effectively prevents physical tailgating and unauthorized entry into the facility. Requiring two-factor authentication for the data center door further strengthens physical access control to critical infrastructure. However, these measures solely address physical security and do not mitigate the risk of social engineering attacks targeting logical access, such as an attacker manipulating help desk personnel to reset a user's password.

  • Install a mantrap at the main entrance and require multi-factor authentication (MFA) for all password reset requests.

    Why this is correct

    A mantrap at the main entrance is a robust physical security control that effectively prevents tailgating and unauthorized physical access to the premises. Simultaneously, requiring multi-factor authentication (MFA) for all password reset requests significantly strengthens logical security by making it much harder for social engineers to gain unauthorized account access, even if they successfully trick an employee into initiating a reset. This combination addresses both physical and social engineering vulnerabilities comprehensively.

  • Deploy security guards at the entrance 24/7 and implement a policy that all visitors must be escorted.

    Why it's wrong here

    Deploying 24/7 security guards and enforcing a visitor escort policy significantly enhances physical security by deterring unauthorized entry and monitoring individuals within the facility, thereby reducing tailgating risks. Nevertheless, these measures are primarily focused on physical access control. They offer no direct protection against remote social engineering attacks, where an attacker might impersonate a legitimate user over the phone or email to trick IT support into performing a password reset.

  • Implement a callback verification process for all password reset requests and require a manager approval.

    Why it's wrong here

    Implementing a callback verification process combined with manager approval for password reset requests is an excellent control against social engineering, as it introduces an out-of-band verification and an authorization layer. This significantly reduces the likelihood of an attacker successfully gaining logical access through manipulation. However, this solution exclusively addresses logical security vulnerabilities and provides no defense against physical security threats, such as an unauthorized individual physically tailgating into the building during a busy period.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.