What does multiple badge entries in two minutes indicate?
A company’s gate access logs show multiple entries from an employee’s ID badge within a two-minute period. Which of the following is this an example of?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to distinguish between physical access control attacks based on log analysis, with the common trap being confusing badge cloning with tailgating.
Multiple rapid entries from the same ID badge within a short timeframe typically indicate RFID cloning, where an attacker duplicates credentials to gain unauthorized access. Community consensus strongly supports this interpretation over tailgating, as logs show repeated credential use rather than single-use piggybacking.
Many candidates choose D (Tailgating) because they associate physical security breaches with unauthorized entry, but tailgating produces only one log entry per badge scan, not multiple rapid entries from the same credential.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
RFID cloning involves duplicating an employee's access badge credentials, allowing an attacker to use the cloned badge independently. The key evidence is multiple entries from the same badge within two minutes, which indicates the credential was scanned multiple times in rapid succession. This pattern is consistent with a cloned badge being used by different individuals or the same attacker making repeated access attempts. Physical access logs would show distinct timestamps for each scan, confirming credential reuse rather than a single authorized entry.
Why the Other Options Are Wrong
Tailgating (Option D) involves an unauthorized person following an authorized employee through a secured entry without scanning their own badge, which would produce only one log entry per incident. Side-channel attacks (Option B) involve extracting information through indirect means like power consumption or electromagnetic emissions, not physical access logs. Shoulder surfing (Option C) involves observing someone enter credentials or access codes, which wouldn't generate multiple badge scan entries in access logs. The question specifically references log entries showing repeated badge use, eliminating these alternatives.
Community Comment Notes
Comment [1] correctly identifies that tailgating would not produce multiple log entries from the same badge, as the unauthorized person doesn't use credentials. Comment [2] reinforces this by noting that multiple entries within two minutes indicate actual card usage, not following. Comment [3] represents the common misconception, incorrectly assuming tailgating could produce multiple entries, but fails to recognize that tailgating by definition bypasses credential requirements entirely.
Official Reference
Exam Strategy
When analyzing physical security scenarios, focus on what the evidence actually shows rather than what might have happened. Multiple credential scans indicate credential duplication or reuse, while single scans with unauthorized entry suggest tailgating or piggybacking.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →