Question

Difficulty: MediumSocial Engineering and Threat Types

A security technician at a corporate facility reviews badge access logs and camera footage following an unauthorized entry into a restricted server room. The footage reveals an unknown individual carrying several large, heavy boxes who asked an employee to hold the badge-restricted electronic door open. The employee complied out of courtesy and held the door, allowing the individual to enter the facility without scanning a security credential. Which of the following social engineering techniques occurred in this scenario?

  1. PiggybackingAnswer
  2. B
    Tailgating
  3. C
    Shoulder surfing
  4. D
    Pretexting

Answer

Piggybacking
Piggybacking refers to a physical social engineering attack where an unauthorized individual gains entry into a restricted area with the active assistance or consent of an authorized person, typically by appealing to social norms like holding a door open for someone carrying heavy items.

Step-by-Step Solution

1
Analyze the physical access mechanism described in the scenario.
The perpetrator gained entry into a secure building without presenting valid access credentials.
Security protocols require every individual entering a restricted area to authenticate independently.
2
Evaluate the interaction between the intruder and the authorized employee.
The intruder asked the employee to hold the door, and the employee knowingly held it open out of courtesy.
Distinguishing whether entry was gained with the employee's active cooperation determines the exact social engineering classification.
3
Differentiate between piggybacking and tailgating.
Because the employee held the door open with consent/awareness, the attack is classified as piggybacking.
Piggybacking implies permission or compliance from the authorized person, whereas tailgating involves sneaking in unassisted.

Key Concept

Physical Social Engineering Threat Types
Rate this question