SY0-501 · Question #544
A security auditor is testing perimeter security in a building that is protected by badge readers. Which of the following types of attacks would MOST likely gain access?
The correct answer is C. Tailgating. Tailgating is the most likely physical security attack to gain unauthorized access to a building protected by badge readers, as it directly circumvents the physical access control mechanism.
Question
A security auditor is testing perimeter security in a building that is protected by badge readers. Which of the following types of attacks would MOST likely gain access?
Options
- APhishing
- BMan-in-the-middle
- CTailgating
- DWatering hole
- EShoulder surfing
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C69% (18)
- D15% (4)
- E4% (1)
Why each option
Tailgating is the most likely physical security attack to gain unauthorized access to a building protected by badge readers, as it directly circumvents the physical access control mechanism.
Phishing is a social engineering attack conducted digitally to steal credentials or information, not a method for physical entry past a badge reader.
Man-in-the-middle is a network attack that intercepts and modifies communication between two parties, irrelevant to gaining physical access through a badge reader.
Tailgating is a physical security breach where an unauthorized person follows an authorized individual through a secured entry point, such as one protected by badge readers, immediately after they have successfully authenticated. This attack exploits human courtesy or inattention, allowing the attacker to bypass the badge reader system entirely without needing their own credentials.
Watering hole is a web-based attack to infect users with malware by compromising frequently visited websites, unrelated to gaining physical building access.
Shoulder surfing involves observing confidential information (like a PIN or password) by looking over someone's shoulder, which doesn't directly facilitate bypassing a badge reader to gain physical access.
Concept tested: Physical security bypass via social engineering
Topics
Community Discussion
No community discussion yet for this question.