Which Type of Penetration Test Involves Using an Access Badge?

During a penetration test, a vendor attempts to enter an unauthorized area using an access badge. Which of the following types of tests does this represent?

  1. Defensive
  2. Passive
  3. Offensive
  4. Physical Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam expects you to classify pen tests by technique and scope; the trap is choosing offensive based on the word 'attempts' instead of recognizing the physical security context.

For the CompTIA SY0-701 exam, this question tests your ability to distinguish penetration test categories. The community agrees that using an access badge to enter an unauthorized area is a physical penetration test.

Choosing 'Offensive' is the most common mistake because the vendor is actively attempting an unauthorized action, but the test is specifically targeting physical security controls—not just software or network exploitation.

Community Discussion (4 comments)

Cyber24 👍 1 Selected: D
using an access badge is a Physical
96bc5c8 👍 1
kjgjhkg
dbrowndiver 👍 2 Selected: D
o The scenario specifically involves testing the ability to physically enter a secure area, which aligns perfectly with the definition of a physical penetration test.
Shaman73 👍 1 Selected: D
D: Physical

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario explicitly involves a vendor using an access badge to enter an unauthorized area, which tests physical security controls. Physical penetration testing evaluates locks, badges, tailgating, and facility access procedures. The term 'physical' directly maps to the action described, and the community comment [1] confirms this alignment with the definition of a physical penetration test.

Why the Other Options Are Wrong

A defensive test focuses on an organization's ability to detect and respond to attacks, not the attacker's method. A passive test involves no active exploitation or attempts to bypass controls. An offensive test simulates attacks on systems, networks, or applications—typically digital, not physical. While the vendor is 'attempting' an action, that does not make the test offensive by default; physical security testing remains a distinct category.

Community Comment Notes

Comment [1] points out that the scenario specifically tests the ability to physically enter a secure area, aligning perfectly with physical penetration testing. Comment [2] simplistically states 'using an access badge is a Physical,' reinforcing the direct association between the badge and physical access controls. Other comments simply vote for D without additional detail, but the consensus is unanimous.

Official Reference

Exam Strategy

Look for keywords that indicate the type of control being tested: badge, door, lock, or physical area point to a physical test. Memorize the four pen test categories—offensive, defensive, passive, and physical—and map each scenario to the target of the test, not just the action taken.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide