nerdexam
CompTIA

SY0-501 · Question #72

An attacker wearing a building maintenance uniform approached a company's receptionist asking for access to a secure area. The receptionist asks for identification, a building access badge and…

The correct answer is C. Impersonation. The security measures taken by the receptionist are designed to verify the identity of the person seeking access, directly countering an attacker attempting to gain entry by falsely representing themselves.

Submitted by alyssa_d· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

An attacker wearing a building maintenance uniform approached a company's receptionist asking for access to a secure area. The receptionist asks for identification, a building access badge and checks the company's list approved maintenance personnel prior to granting physical access to the secure are. The controls used by the receptionist are in place to prevent which of the following types of attacks?

Options

  • ATailgating
  • BShoulder surfing
  • CImpersonation
  • DHoax

How the community answered

(62 responses)
  • A
    8% (5)
  • B
    3% (2)
  • C
    77% (48)
  • D
    11% (7)

Why each option

The security measures taken by the receptionist are designed to verify the identity of the person seeking access, directly countering an attacker attempting to gain entry by falsely representing themselves.

ATailgating

Tailgating involves an unauthorized individual following an authorized person through a secure entry point without presenting their own credentials, which is distinct from the attacker directly requesting access and being subjected to verification checks.

BShoulder surfing

Shoulder surfing is a technique where an attacker observes someone's screen or keyboard to steal sensitive information like passwords, which is unrelated to an attacker attempting to gain physical access by deception in this scenario.

CImpersonationCorrect

Impersonation is a social engineering attack where an individual pretends to be someone else to gain unauthorized access or information. The attacker's use of a uniform and request for access, coupled with the receptionist's verification steps (asking for ID, badge, and checking an approved list), directly addresses and aims to prevent such an impersonation attempt.

DHoax

While a hoax involves deception, impersonation is a more specific social engineering term describing an attacker pretending to be another person or role to achieve unauthorized access, which is precisely what the scenario describes.

Concept tested: Social engineering attack prevention (Impersonation)

Source: https://learn.microsoft.com/en-us/training/modules/threat-mitigation-strategies/4-social-engineering-threats

Topics

#social engineering#impersonation#physical security#access control

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice