What Is Tailgating? Social Engineering for Physical Access
An attacker gains physical access to a restricted area by following an authorized employee through a secured door without swiping a badge. This technique is known as:
Quick Answer
The correct answer is tailgating, also known as piggybacking, because it describes the social engineering technique where an unauthorized person exploits an authorized individual’s access to bypass physical security controls, such as a badge reader or keypad. This attack relies on human courtesy or distraction rather than technical hacking, as the attacker simply follows closely behind an employee through a secured door without presenting their own credentials. On the Certified Ethical Hacker CEH exam, this concept tests your understanding of physical access vectors within the social engineering domain, often appearing in scenario-based questions that distinguish tailgating from other attacks like phishing or dumpster diving. A common trap is confusing tailgating with shoulder surfing, but remember: tailgating is about following through a door, not looking over a shoulder. For a quick memory tip, think of a tailgater at a concert—someone who slips in behind a ticket holder without paying.
⚠ Common exam trap
Many exam-takers confuse 'tailgating' with 'pretexting' because both involve deception, but tailgating is purely physical (following through a door) while pretexting is purely verbal (creating a false story).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
Tailgating is a social engineering attack where an unauthorized person physically follows an authorized employee through a secured entry point (e.g., a badge-protected door) without presenting their own credentials. This exploits the human tendency to hold the door for others, bypassing electronic access control systems (e.g., RFID badge readers) that would otherwise deny entry. The CEH exam defines this as a physical breach of perimeter security, distinct from digital or verbal manipulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tailgating
Why this is correct
Tailgating is following an authorized person through a secure entry.
- ✗
Pretexting
Why it's wrong here
Pretexting involves fabricating a scenario to obtain information.
- ✗
Quid pro quo
Why it's wrong here
Quid pro quo offers a benefit in exchange for information.
- ✗
Baiting
Why it's wrong here
Baiting uses enticing objects like USB drives.
Go deeper
Related to this question
Learn chapter
Social Engineering
Key term
Evil Twin Attack
An evil twin attack is a type of wireless hacking where a fake Wi-Fi access point mimics a legitimate one to trick users into connecting, allowing the attacker to intercept traffic and steal data.
Key term
OSINT Techniques
OSINT techniques are methods used to collect information from publicly available sources for security assessments or investigations.
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An attacker gains physical access to a building by following an authorized employee through a secure door without using a badge. Which social engineering technique is being used?
hard- A.Pretexting
- ✓ B.Tailgating
- C.Baiting
- D.Quid pro quo
Why B: Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area without presenting their own credentials. The attacker exploits the authorized person's trust or politeness to bypass access control systems such as badge readers or biometric locks. This technique relies on the human factor rather than technical vulnerabilities.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.