Courseiva
Social Engineering and Physical SecurityhardMultiple ChoiceObjective-mapped

CEH Social Engineering and Physical Security Practice Question

You are a security consultant hired by a mid-sized company with 500 employees. The company has a central office with a lobby, reception, and two secure areas: the server room (requires keycard and PIN) and the executive floor (requires keycard only). Recently, employees have reported seeing unfamiliar people in restricted areas. Security logs show keycard access for the server room only during business hours, but no anomalies. However, the executive floor logs show multiple entries by a single employee, John from Sales, at odd hours. John claims he was working late. The company has a policy that all employees must wear ID badges visibly. You observe that employees often hold doors open for colleagues, and the receptionist does not verify visitor badges. Which of the following actions should you recommend FIRST to address the most likely attack vector?

⚠ Common exam trap

EC-Council often tests the distinction between authentication (e.g., biometrics) and access control (e.g., mantraps), and the trap here is that candidates confuse improving credential verification with preventing the social engineering technique of tailgating, leading them to choose a more expensive but ineffective solution like biometric readers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement mantraps and enforce a policy of one person per keycard entry

The most likely attack vector is tailgating (piggybacking), where unauthorized individuals gain physical access by following an authorized employee through a secured door without using their own credentials. Option C directly addresses this by implementing mantraps (a small room with two interlocking doors that only allows one person to pass at a time) and enforcing a strict one-person-per-keycard-entry policy, which physically prevents tailgating. This is the first and most effective control because it mitigates the root cause—social engineering exploiting human courtesy—rather than focusing on symptoms like John's after-hours access or adding surveillance that doesn't prevent the act.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Investigate John's activities and consider disciplinary action

    Why it's wrong here

    This approach incorrectly assumes individual culpability without first addressing the underlying systemic vulnerability that enables tailgating. While John might have inadvertently facilitated an unauthorized entry, focusing solely on disciplinary action fails to identify or mitigate the procedural or physical security weaknesses that allowed the incident to occur. A comprehensive security strategy prioritizes fixing the systemic flaw over immediately penalizing a potentially innocent party, ensuring future incidents are prevented regardless of individual actions.

  • Upgrade keycard readers to biometric scanners

    Why it's wrong here

    While biometric scanners enhance authentication by verifying an individual's unique physical characteristics, they do not inherently prevent tailgating. An authorized person, after successfully authenticating with their biometrics, can still hold the door open for an unauthorized individual to follow them into a secure area. Biometrics confirm identity but do not physically restrict the number of people entering through a single access point, leaving the core tailgating vulnerability unaddressed.

  • Implement mantraps and enforce a policy of one person per keycard entry

    Why this is correct

    Mantraps are highly effective physical security controls consisting of two interlocking doors, designed to permit only one person to pass through at a time after successful authentication. This physical barrier directly prevents tailgating by making it impossible for a second individual to enter behind an authorized person. Coupling this technical control with a strictly enforced policy reinforces security protocols, ensuring both physical and administrative measures actively mitigate the tailgating threat.

  • Install additional CCTV cameras in hallways

    Why it's wrong here

    Installing more CCTV cameras primarily serves as a detective control, meaning it records events for later review and forensic analysis rather than actively preventing them. While CCTV can deter some opportunistic attackers and provide valuable evidence post-incident, it does not physically stop or impede tailgating in real-time. Relying solely on CCTV for tailgating prevention is reactive, failing to address the immediate physical security gap that allows unauthorized access.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.