Skip to main content

Unit 2 · Topic 2.2

2.2 Physical Vulnerabilities and Attacks

If an attacker can reach a device with their hands, they can skip many of the digital defenses protecting it. This topic covers the common physical attacks, what an intruder can do once inside, and how to rate physical risks as high, moderate or low.

Key terms

  • piggybacking
  • tailgating
  • shoulder surfing
  • dumpster diving
  • card cloning
  • keylogger

Common physical attacks

Physical attacks often start with social engineering. The course names five:

  • Piggybacking: the attacker manipulates an authorized person into letting them into a restricted area. Classic tricks: carrying a big box so someone holds the door, claiming to have forgotten a badge, or posing as a maintenance worker who needs to inspect something.
  • Tailgating: the attacker slips in close behind an authorized person who doesn't notice. The key difference from piggybacking is awareness: in piggybacking the employee knowingly lets the attacker in (after being fooled); in tailgating they never realize it happened.
  • Shoulder surfing: watching someone enter or view sensitive information, like a PIN or password, to use later. Sometimes the attacker records it with a hidden camera.
  • Dumpster diving: searching a target's trash for useful information, like printed org charts, account letters or sticky notes with passwords.
  • Card cloning: copying an authorized person's access card so the attacker can open everything that card can open.

Threats, vulnerabilities and what can go wrong

A threat is anything that could cause harm. It can be a human adversary or a natural disaster like a flood, fire or storm that damages computers, destroys data or knocks out services. A vulnerability is a weakness that could let an asset be compromised. Typical compromises are unauthorized access to data or restricted spaces, service disruption, theft or destruction of resources, and unauthorized changes to data.

Once an adversary is physically inside, they have many options:

  • Cut power by damaging fuses or breakers, unplugging or cutting wiring, or attacking substations and transformers. Without power, the devices and their services go down.
  • Steal or copy sensitive papers and files from the area.
  • Plug a keylogger (a device that records keystrokes) or a malware-loaded drive into an open port, to collect data or even take control of the device.
  • Destroy the device outright, wiping out its data and services.

Rating physical risks

Physical access can bypass many technical controls. A strong password doesn't help if someone walks off with the server. Use the asset's value and how exposed it is to rate the risk:

RatingWhen it appliesExample
HighSensitive information or critical systems sit in a space without enough access controlA server with student records in an unlocked closet off a hallway no one monitors
ModerateA noncritical part of the organization is unprotected in a way that could give an attacker a foothold into more important systemsA lobby kiosk connected to the internal network with exposed USB ports
LowThe asset has little value and the weakness is unlikely to be exploitedLaptops with no sensitive data, left on desks inside a badge-only office during lunch

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Piggybacking or tailgating?

    Case 1: A person in a delivery uniform, arms full of boxes, asks an employee to hold the secure door, and she does. Case 2: A person waits near the secure door and walks in right behind an employee who is looking at his phone and never notices. Name each attack and explain the difference.

    Show the solution
    1. Step 1: Case 1: the employee knowingly let the person in because of a believable story (a social engineering pretext). That's piggybacking.
    2. Step 2: Case 2: the employee never knew anyone followed him. That's tailgating.
    3. Step 3: State the difference: whether the authorized person was aware and was manipulated into granting access.

    Answer: Case 1 is piggybacking (the employee was tricked into knowingly letting the person in). Case 2 is tailgating (the person followed without the employee noticing).

  2. Example 2

    Rating three findings

    A physical assessment of Cedar Valley Library finds: (a) the staff room computer that manages patron accounts and addresses is in a room with a broken lock, off a public hallway; (b) the self-checkout kiosk in the lobby connects to the library's internal network and has an open USB port; (c) a box of blank, unused printer paper is stored in an unlocked hallway closet. Rate each risk and justify.

    Show the solution
    1. Step 1: (a) Sensitive data (patron addresses) and an important system in a space that isn't access-controlled, next to public traffic. That's the high-risk pattern.
    2. Step 2: (b) The kiosk itself holds nothing sensitive, but its open USB port and network connection could give an attacker a foothold into internal systems. That's the moderate pattern.
    3. Step 3: (c) Low-value asset, unlikely to be targeted, no path to anything sensitive. That's low.

    Answer: (a) High: sensitive patron data in an uncontrolled space. (b) Moderate: a nonsensitive device that could be a foothold into the internal network. (c) Low: low-value asset, unlikely target.

Common mistakes

  • Using piggybacking and tailgating as synonyms. The course separates them by whether the authorized person knowingly let the attacker in.
  • Forgetting natural disasters. Threats include floods, fires and storms, not only human attackers.
  • Rating a device as low risk just because it holds no sensitive data. If it connects to the internal network and is easy to reach, it can be a foothold, which makes it moderate.

On the exam

  • Expect short scenarios that ask you to name the physical attack. Look for the giveaway detail: a held door, an unaware employee, someone watching a screen, someone in the trash, a copied badge.
  • For risk-rating questions, check two things: how sensitive or critical the asset is, and whether it could lead an attacker to something more valuable.

Connected topics

Videos

  • AP Cybersecurity Topic 2.2. - Physical Vulnerabilities and Attacks - Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Physical Attacks - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • Tailgating and Piggybacking - Social Engineering Tactics Explained

    LabCyberWatch on YouTube (opens in a new tab)

  • Shoulder Surfing - SY0-601 CompTIA Security+ : 1.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • Dumpster Diving - SY0-601 CompTIA Security+ : 1.1

    Professor MesserWatch on YouTube (opens in a new tab)

Check yourself: 2.2 Physical Vulnerabilities and Attacks

4 questions on 2.2 Physical Vulnerabilities and Attacks. Pick an answer to see if you got it, and why.

Event 1: A man carrying three large boxes waits by the badge-controlled door of a research lab. When an employee badges in, the man says, "Could you grab the door? My hands are full." The employee holds it open, and he walks in.

Event 2: Later, a woman walks close behind a group of employees as they badge through the same door. None of the employees notice her, and she enters before the door closes.

Invented scenario

Question 1 of 4

Which statement correctly identifies the two events?

Question 2 of 4

Once inside the lab, the woman from Event 2 plugs a small device between a computer's keyboard and its USB port. What is the device most likely designed to do?

Question 3 of 4

At an airport, a traveler logs in to a work account on a laptop. A person sitting behind the traveler quietly films the screen and keyboard with a phone. What kind of attack is this?

Question 4 of 4

An adversary searches the recycling bins behind a law office at night and finds printed client lists and a sticky note with a Wi-Fi password. What kind of attack is this?

0 of 4 answered