CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

During an authorized physical security assessment, a tester wants to covertly capture the RF signal from an employee's proximity access card while standing nearby, then write that data to a blank card to test the badge reader's access controls. Which tool is best suited for this task?

  1. ALock pick set
  2. BProxmark3
  3. CKismet
  4. DWireshark
Show answer & explanation

Correct answer: B. Proxmark3

Proxmark3 is a specialized RFID research device capable of sniffing, reading, and cloning proximity card credentials, making it the appropriate tool for covertly capturing and duplicating badge data.

Why the other options are wrong

  • A. A lock pick set is for mechanical locks, not electronic badge cloning.
  • C. Kismet is used for Wi-Fi and Bluetooth discovery, not RFID cloning.
  • D. Wireshark captures network packets, not RF proximity card signals.

Proxmark3

A portable RFID research tool capable of reading, sniffing, and cloning low- and high-frequency proximity card credentials.

  • Supports both 125kHz (low-freq) and 13.56MHz (high-freq) cards
  • Used in physical penetration tests to clone employee badges
  • Requires proximity to the target card to capture signal

Memory trick: 'Proxmark Preys on Proximity cards'

More Vulnerability Discovery and Analysis questions