nerdexam
CompTIA

PT0-003 · Question #261

While performing a red-team exercise, a penetration tester uses a reading device to extract data from an employee's access badge. The tester creates a copy for unauthorized entry. Which of the…

The correct answer is B. Card skimming. Card skimming (B) is correct because it describes the act of using a device to illicitly read and copy data stored on a card - in this case, an RFID or magnetic stripe access badge - to create a duplicate for unauthorized physical access. Smurfing (A) is a network-based DDoS…

Submitted by jordan8· Mar 6, 2026Attacks and Exploits

Question

While performing a red-team exercise, a penetration tester uses a reading device to extract data from an employee's access badge. The tester creates a copy for unauthorized entry. Which of the following best describes this attack?

Options

  • ASmurfing
  • BCard skimming
  • COn-path attack
  • DCredential stuffing

How the community answered

(60 responses)
  • A
    2% (1)
  • B
    93% (56)
  • C
    3% (2)
  • D
    2% (1)

Explanation

Card skimming (B) is correct because it describes the act of using a device to illicitly read and copy data stored on a card - in this case, an RFID or magnetic stripe access badge - to create a duplicate for unauthorized physical access.

Smurfing (A) is a network-based DDoS attack that amplifies traffic using ICMP packets, having nothing to do with physical card duplication. On-path attacks (C) involve intercepting network communications between two parties, which is a digital/network threat, not a physical one. Credential stuffing (D) refers to using large lists of stolen username/password combinations to attempt logins on various online services - again, unrelated to physical badge cloning.

Memory tip: Think of "skimming" like skimming cream off milk - you're lifting just the surface data off a card without the owner knowing. If a question mentions a reading device + card copy + physical access, that's your signal to choose card skimming.

Topics

#Card skimming#Physical access control#Red teaming#Access badge compromise

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice