Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

What Is Tailgating? Social Engineering for Physical Access

An attacker gains physical access to a restricted area by following an authorized employee through a secured door without swiping a badge. This technique is known as:

Quick Answer

The correct answer is tailgating, also known as piggybacking, because it describes the social engineering technique where an unauthorized person exploits an authorized individual’s access to bypass physical security controls, such as a badge reader or keypad. This attack relies on human courtesy or distraction rather than technical hacking, as the attacker simply follows closely behind an employee through a secured door without presenting their own credentials. On the Certified Ethical Hacker CEH exam, this concept tests your understanding of physical access vectors within the social engineering domain, often appearing in scenario-based questions that distinguish tailgating from other attacks like phishing or dumpster diving. A common trap is confusing tailgating with shoulder surfing, but remember: tailgating is about following through a door, not looking over a shoulder. For a quick memory tip, think of a tailgater at a concert—someone who slips in behind a ticket holder without paying.

⚠ Common exam trap

Many exam-takers confuse 'tailgating' with 'pretexting' because both involve deception, but tailgating is purely physical (following through a door) while pretexting is purely verbal (creating a false story).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Tailgating

Tailgating is a social engineering attack where an unauthorized person physically follows an authorized employee through a secured entry point (e.g., a badge-protected door) without presenting their own credentials. This exploits the human tendency to hold the door for others, bypassing electronic access control systems (e.g., RFID badge readers) that would otherwise deny entry. The CEH exam defines this as a physical breach of perimeter security, distinct from digital or verbal manipulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Tailgating

    Why this is correct

    Tailgating is following an authorized person through a secure entry.

  • Pretexting

    Why it's wrong here

    Pretexting involves fabricating a scenario to obtain information.

  • Quid pro quo

    Why it's wrong here

    Quid pro quo offers a benefit in exchange for information.

  • Baiting

    Why it's wrong here

    Baiting uses enticing objects like USB drives.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An attacker gains physical access to a building by following an authorized employee through a secure door without using a badge. Which social engineering technique is being used?

hard
  • A.Pretexting
  • B.Tailgating
  • C.Baiting
  • D.Quid pro quo

Why B: Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a restricted area without presenting their own credentials. The attacker exploits the authorized person's trust or politeness to bypass access control systems such as badge readers or biometric locks. This technique relies on the human factor rather than technical vulnerabilities.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.