What does multiple badge entries in two minutes indicate?

A company’s gate access logs show multiple entries from an employee’s ID badge within a two-minute period. Which of the following is this an example of?

  1. RFID cloning Source Reference Answer
  2. Side-channel attack
  3. Shoulder surfing
  4. Tailgating

Community Votes

A
80%
D
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to distinguish between physical access control attacks based on log analysis, with the common trap being confusing badge cloning with tailgating.

Multiple rapid entries from the same ID badge within a short timeframe typically indicate RFID cloning, where an attacker duplicates credentials to gain unauthorized access. Community consensus strongly supports this interpretation over tailgating, as logs show repeated credential use rather than single-use piggybacking.

Many candidates choose D (Tailgating) because they associate physical security breaches with unauthorized entry, but tailgating produces only one log entry per badge scan, not multiple rapid entries from the same credential.

Community Discussion (3 comments)

Nahidwin 👍 1 Selected: A
A is the correct answer because tailgaitng is just following the person without them knowing , and in the question the logs show that there are two entries within two minutes so a card was used
PjoterK 👍 3 Selected: A
D. Tailgating: This refers to an unauthorized person physically following an authorized person through a secured entry point without using their own credentials. It would not produce multiple log entries from the same badge
1eccfc0 👍 1 Selected: D
The correct answer is D. Tailgating. Tailgating happens when an unauthorized person follows an authorized person into a secure area by closely following them through a door or gate without proper access. The multiple entries from an employee's ID badge within a short time period (two minutes) suggest that the employee may have entered and allowed someone else to follow them through, which is typical of tailgating. Here’s a quick rundown of the other options: A. RFID cloning: This would involve copying the RFID credentials (ID badge) and using them to gain unauthorized access. However, there’s no indication that the ID badge itself was cloned, only that multiple entries are logged in a short period.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

RFID cloning involves duplicating an employee's access badge credentials, allowing an attacker to use the cloned badge independently. The key evidence is multiple entries from the same badge within two minutes, which indicates the credential was scanned multiple times in rapid succession. This pattern is consistent with a cloned badge being used by different individuals or the same attacker making repeated access attempts. Physical access logs would show distinct timestamps for each scan, confirming credential reuse rather than a single authorized entry.

Why the Other Options Are Wrong

Tailgating (Option D) involves an unauthorized person following an authorized employee through a secured entry without scanning their own badge, which would produce only one log entry per incident. Side-channel attacks (Option B) involve extracting information through indirect means like power consumption or electromagnetic emissions, not physical access logs. Shoulder surfing (Option C) involves observing someone enter credentials or access codes, which wouldn't generate multiple badge scan entries in access logs. The question specifically references log entries showing repeated badge use, eliminating these alternatives.

Community Comment Notes

Comment [1] correctly identifies that tailgating would not produce multiple log entries from the same badge, as the unauthorized person doesn't use credentials. Comment [2] reinforces this by noting that multiple entries within two minutes indicate actual card usage, not following. Comment [3] represents the common misconception, incorrectly assuming tailgating could produce multiple entries, but fails to recognize that tailgating by definition bypasses credential requirements entirely.

Official Reference

Exam Strategy

When analyzing physical security scenarios, focus on what the evidence actually shows rather than what might have happened. Multiple credential scans indicate credential duplication or reuse, while single scans with unauthorized entry suggest tailgating or piggybacking.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide