What Is Tailgating? Social Engineering for Physical Access
An attacker gains physical access to a restricted area by following an authorized employee through a secured door without swiping a badge. This technique is known as:
Quick Answer
The correct answer is tailgating, also known as piggybacking, because it describes the social engineering technique where an unauthorized person exploits an authorized individual’s access to bypass physical security controls, such as a badge reader or keypad. This attack relies on human courtesy or distraction rather than technical hacking, as the attacker simply follows closely behind an employee through a secured door without presenting their own credentials. On the Certified Ethical Hacker CEH exam, this concept tests your understanding of physical access vectors within the social engineering domain, often appearing in scenario-based questions that distinguish tailgating from other attacks like phishing or dumpster diving. A common trap is confusing tailgating with shoulder surfing, but remember: tailgating is about following through a door, not looking over a shoulder. For a quick memory tip, think of a tailgater at a concert—someone who slips in behind a ticket holder without paying.
⚠ Common exam trap
Many exam-takers confuse 'tailgating' with 'pretexting' because both involve deception, but tailgating is purely physical (following through a door) while pretexting is purely verbal (creating a false story).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
Tailgating is a social engineering attack where an unauthorized person physically follows an authorized employee through a secured entry point (e.g., a badge-protected door) without presenting their own credentials. This exploits the human tendency to hold the door for others, bypassing electronic access control systems (e.g., RFID badge readers) that would otherwise deny entry. The CEH exam defines this as a physical breach of perimeter security, distinct from digital or verbal manipulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tailgating
Why this is correct
Tailgating exploits the human element of physical security: the attacker gains entry by closely following an authorised employee through a secured door, bypassing badge authentication entirely. The stem's constraint is unauthorised physical access without credentials, which tailgating satisfies precisely.
- ✗
Pretexting
Why it's wrong here
Pretexting is a fabricated scenario, usually by phone or email, to extract information from a target. It involves no physical door or badge, whereas tailgating exploits an employee's valid entry to slip through a secured entrance unauthorised.
- ✗
Quid pro quo
Why it's wrong here
Quid pro quo offers a service or benefit in exchange for information, typically over the phone. It does not describe physically following someone through a door; tailgating is the term for entering behind an authorised person without swiping a badge.
- ✗
Baiting
Why it's wrong here
Baiting leaves physical media such as infected USB drives for a victim to plug in, exploiting curiosity. Tailgating, the actual technique here, relies on an authorised employee holding a secured door open, letting the attacker pass without presenting credentials.
Go deeper
Related to this question
Learn chapter
Social Engineering
Key term
Evil Twin Attack
An evil twin attack is a type of wireless hacking where a fake Wi-Fi access point mimics a legitimate one to trick users into connecting, allowing the attacker to intercept traffic and steal data.
Key term
OSINT Techniques
OSINT techniques are methods used to collect information from publicly available sources for security assessments or investigations.
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An attacker gains physical access to a building by following an authorized employee through a secure door without using a badge. Which social engineering technique is being used?
hard- A.Pretexting
- ✓ B.Tailgating
- C.Baiting
- D.Quid pro quo
Why B: Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area without presenting their own credentials. The attacker exploits the authorized person's trust or politeness to bypass access control systems such as badge readers or biometric locks. This technique relies on the human factor rather than technical vulnerabilities.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.