Social engineering attacks exploit human behavior to bypass security controls. Tailgating (following an authorized person into a restricted area without authentication) and badge non-compliance are common tactics used by attackers to gain unauthorized physical access. Training employees to recognize and prevent social engineering tactics can reduce these risks. Situational awareness (B) relates to general security awareness but is not specific to social engineering attacks. Phishing (C) targets victims via email or online deception, not physical access. Acceptable use policy (D) defines how employees should use IT resources but does not address physical security risks. Reference: CompTIA Security+ SY0-701 Official Study Guide, General Security Concepts domain.