nerdexam
CompTIA

PT0-001 · Question #158

A security guard observes an individual entering the building after scanning a badge. The facility has a strict badge-in and badge-out requirement with a turnstile. The security guard then audits…

The correct answer is A. The badge was cloned. Two badge log entries within 30 minutes while only one physical entry was observed indicates the credential was duplicated and used separately from the original badge.

Attacks and exploits

Question

A security guard observes an individual entering the building after scanning a badge. The facility has a strict badge-in and badge-out requirement with a turnstile. The security guard then audits the badge system and finds two log entries for the badge in question within the last 30 minutes. Which of the following has MOST likely occurred?

Options

  • AThe badge was cloned.
  • BThe physical access control server is malfunctioning.
  • CThe system reached the crossover error rate.
  • DThe employee lost the badge.

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    4% (1)
  • C
    7% (2)
  • D
    4% (1)

Why each option

Two badge log entries within 30 minutes while only one physical entry was observed indicates the credential was duplicated and used separately from the original badge.

AThe badge was cloned.Correct

Badge cloning creates an exact duplicate of the RFID or smart card credential that functions identically to the original. Two successful log entries from the same badge ID in a short window, combined with only one observed physical entry, is the classic indicator that a cloned copy was swiped at a different time or access point by an unauthorized person.

BThe physical access control server is malfunctioning.

A server malfunction would more likely produce missing entries, duplicate phantom records, or system errors, not two distinct and plausible swipe events tied to a real observed entry.

CThe system reached the crossover error rate.

The crossover error rate (CER) is a biometric system metric where the false acceptance rate equals the false rejection rate and has no relevance to badge swipe log counts.

DThe employee lost the badge.

A lost badge can only produce log entries when physically swiped, so losing it does not explain two entries while the legitimate employee was also observed entering the building.

Concept tested: Physical access control badge cloning detection

Topics

#badge cloning#physical security#RFID#access control bypass

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice