📖 What is Shoulder Surfing?

Shoulder Surfing is a social engineering technique where an attacker physically observes a user's screen or keyboard to steal sensitive information. This is commonly used in public areas to capture passwords, PINs, or credit card numbers without the user's knowledge.

🥋 Sensei Says:

"To prevent this, recommend the use of privacy screens on laptops and mobile devices, especially for employees working in public spaces."

📚 Certification: CompTIA A+ Certification Exam Core 2 (220-1102)

🔑 What are the Key Concepts of Shoulder Surfing?

  • Shoulder surfing is a form of social engineering that relies on physical proximity to observe sensitive data entry or screen contents.
  • Common targets include alphanumeric passwords, ATM PINs, and one-time MFA codes entered on mobile devices in public settings.
  • Privacy screens or filters are the primary hardware mitigation, limiting the viewing angle to the user directly in front of the screen.
  • Environmental awareness, such as positioning your back to a wall, is a critical behavioral defense against this physical observation technique.
  • Unlike technical hacking, this attack requires no software or network access, making it effective against highly secure or air-gapped systems.

🎯 How does Shoulder Surfing appear on the 220-1102 Exam?

You may be asked to identify the specific social engineering attack occurring when a person observes a user entering a PIN at a public kiosk.

A scenario might describe a company with many remote employees working in cafes; you will likely need to recommend privacy filters as the best mitigation.

Expect questions where you must distinguish shoulder surfing from tailgating, focusing on whether the goal is stealing information or gaining unauthorized physical entry.

❓ Frequently Asked Questions

How does shoulder surfing differ from tailgating?

Shoulder surfing focuses on stealing sensitive information by observing a user, whereas tailgating is the act of following an authorized person into a restricted physical area.


Are there any software-based defenses against shoulder surfing?

While software cannot block physical sight, using shorter session timeouts and masking password characters with asterisks helps reduce the window of opportunity for attackers.

Related Terms from CompTIA A+ Certification Exam Core 2

📝 Related Study Guides

Study Guide 10 min read

CompTIA A+ Core 2 (220-1102): How to Pass and Study Plan

To pass the CompTIA A+ Core 2 (220-1102) exam, you must score at least 700/900. Focus on the four key domains: Operating Systems (31%), Security (25%), Software Troubleshooting (22%), and Operational Procedures (22%). Success requires mastering OS command lines, security protocols, and a systematic troubleshooting methodology through rigorous practice exams.

Comparison 7 min read

NTFS vs FAT32 vs exFAT: A+ Core 2 File System Guide

NTFS is the Windows standard featuring security permissions and journaling. FAT32 offers maximum compatibility but limits individual files to 4GB. exFAT bridges the gap, removing the 4GB limit while maintaining cross-platform support for flash drives. Choosing the right one depends on the required security, file size, and OS compatibility.

Study Guide 8 min read

CompTIA A+ Core 2 (220-1102): Domains, Tips & Study Plan

To pass the CompTIA A+ Core 2 (220-1102) exam, you must master four domains: Operating Systems (31%), Security (25%), Software Troubleshooting (22%), and Operational Procedures (22%). Success requires a score of 700/900. The best strategy combines hands-on OS practice, understanding security protocols, and solving 1,000+ high-quality practice questions to build exam stamina.

🧠

Test Your Knowledge

Think you understand Shoulder Surfing? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium