nerdexam
CompTIA

PT0-002 · Question #504

A penetration tester is conducting a physical test against an organization. During the first day of the assessment, the tester follows an employee to the coffee shop next door. While the employee is…

The correct answer is C. RFID cloning. The penetration tester is most likely performing RFID cloning by electronically capturing the employee's badge information from a short distance.

Attacks and Exploits

Question

A penetration tester is conducting a physical test against an organization. During the first day of the assessment, the tester follows an employee to the coffee shop next door. While the employee is ordering, the tester stands near the employee and captures the employee's badge electronically. Which of the following exploits is the penetration tester most likely conducting?

Options

  • ATailgating
  • BBluesnarfing
  • CRFID cloning
  • DSession hijacking

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    16% (7)
  • C
    73% (33)
  • D
    7% (3)

Why each option

The penetration tester is most likely performing RFID cloning by electronically capturing the employee's badge information from a short distance.

ATailgating

Tailgating is physically following an authorized person through a secure entry point without using legitimate credentials, which is a physical access method, not an electronic exploit of a badge.

BBluesnarfing

Bluesnarfing is the unauthorized access to information from a Bluetooth-enabled device, which is not what is described when electronically capturing badge information.

CRFID cloningCorrect

RFID cloning involves using a reader to capture the unique identifier and other data from an RFID-enabled badge from a close proximity without physical contact. This data can then be copied to a blank RFID card, allowing the attacker to impersonate the legitimate badge holder and gain unauthorized access to physical locations.

DSession hijacking

Session hijacking is exploiting a valid computer session to gain unauthorized access to information or services, which is a network-based attack, not a physical badge exploit.

Concept tested: Physical security exploits- RFID cloning

Topics

#Physical penetration testing#RFID cloning#Badge capture#Exploitation techniques

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice