Access Control Measures to Prevent Social Engineering Attacks

Building Maintenance Uniform Attack

Prev Question Next Question

Question

An attacker wearing a building maintenance uniform approached a company's receptionist asking for access to a secure area.

The receptionist asks for identification, a building access badge and checks the company's list approved maintenance personnel prior to granting physical access to the secure are.

The controls used by the receptionist are in place to prevent which of the following types of attacks?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

The controls used by the receptionist in this scenario are in place to prevent an attack called "Tailgating."

Tailgating is a social engineering technique where an attacker attempts to gain physical access to a secure area by following an authorized person or group of people through a security checkpoint without providing the required authentication credentials or identification. In other words, the attacker attempts to "piggyback" onto an authorized person's entry to gain access to a secure area.

In this scenario, the attacker is wearing a building maintenance uniform, which can make them look like they belong in the secure area. However, the receptionist's controls, such as asking for identification, building access badge, and checking the company's list of approved maintenance personnel, can prevent the attacker from tailgating into the secure area.

Shoulder surfing refers to the practice of looking over someone's shoulder to gain unauthorized access to sensitive information. Impersonation involves pretending to be someone else to gain access to a secure area. A hoax is a deceptive or misleading act or statement intended to deceive or trick someone.

In summary, the controls used by the receptionist are in place to prevent the social engineering attack known as tailgating.