nerdexam
CompTIA

PT0-002 · Question #197

A penetration tester was hired to perform a physical security assessment of an organization's office. After monitoring the environment for a few hours, the penetration tester notices that some…

The correct answer is D. Badge cloning. Observing employees leaving their belongings unattended during lunch provides an opportunity for a penetration tester to access and clone an unattended access badge, which would grant seemingly legitimate access to the building without raising immediate alerts.

Attacks and Exploits

Question

A penetration tester was hired to perform a physical security assessment of an organization's office. After monitoring the environment for a few hours, the penetration tester notices that some employees go to lunch in a restaurant nearby and leave their belongings unattended on the table while getting food. Which of the following techniques would MOST likely be used to get legitimate access into the organization's building without raising too many alerts?

Options

  • ATailgating
  • BDumpster diving
  • CShoulder surfing
  • DBadge cloning

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    17% (9)
  • C
    8% (4)
  • D
    71% (37)

Why each option

Observing employees leaving their belongings unattended during lunch provides an opportunity for a penetration tester to access and clone an unattended access badge, which would grant seemingly legitimate access to the building without raising immediate alerts.

ATailgating

Tailgating involves following an authorized person through an access point, but the scenario of unattended belongings doesn't directly facilitate this technique.

BDumpster diving

Dumpster diving is a technique for information gathering from discarded materials, not for directly gaining physical access into a building with a 'legitimate' appearance.

CShoulder surfing

Shoulder surfing is observing sensitive information like PINs or passwords, which may lead to system access but not directly to gaining 'legitimate access' through a physical entry point.

DBadge cloningCorrect

If employees leave their access badges unattended with their belongings, a penetration tester can opportunistically access these badges to clone them. A cloned badge would then allow the tester to gain seemingly legitimate access to the building without raising immediate suspicion.

Concept tested: Physical penetration testing, social engineering

Topics

#Physical security assessment#Social engineering#Badge cloning#Access control bypass

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice