PT0-003 · Question #261
While performing a red-team exercise, a penetration tester uses a reading device to extract data from an employee's access badge. The tester creates a copy for unauthorized entry. Which of the…
The correct answer is B. Card skimming. Card skimming (B) is correct because it describes the act of using a device to illicitly read and copy data stored on a card - in this case, an RFID or magnetic stripe access badge - to create a duplicate for unauthorized physical access. Smurfing (A) is a network-based DDoS…
Question
While performing a red-team exercise, a penetration tester uses a reading device to extract data from an employee's access badge. The tester creates a copy for unauthorized entry. Which of the following best describes this attack?
Options
- ASmurfing
- BCard skimming
- COn-path attack
- DCredential stuffing
How the community answered
(60 responses)- A2% (1)
- B93% (56)
- C3% (2)
- D2% (1)
Explanation
Card skimming (B) is correct because it describes the act of using a device to illicitly read and copy data stored on a card - in this case, an RFID or magnetic stripe access badge - to create a duplicate for unauthorized physical access.
Smurfing (A) is a network-based DDoS attack that amplifies traffic using ICMP packets, having nothing to do with physical card duplication. On-path attacks (C) involve intercepting network communications between two parties, which is a digital/network threat, not a physical one. Credential stuffing (D) refers to using large lists of stolen username/password combinations to attempt logins on various online services - again, unrelated to physical badge cloning.
Memory tip: Think of "skimming" like skimming cream off milk - you're lifting just the surface data off a card without the owner knowing. If a question mentions a reading device + card copy + physical access, that's your signal to choose card skimming.
Topics
Community Discussion
No community discussion yet for this question.