Courseiva
mediumMultiple Choice

220-1202 Practice Question: A technician is configuring a small office…

A technician is configuring a small office network and wants to ensure that guest users can access the internet but cannot connect to internal company resources like file servers or printers. Which logical security method should be implemented?

⚠ Common exam trap

In CompTIA A+ exams, candidates often confuse access control methods like passwords or SSID hiding with true network segmentation. The key is that logical segmentation via VLANs isolates traffic at Layer 2, whereas authentication and association controls only restrict who can connect, not what they can access once connected.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a guest VLAN that is isolated from the internal network.

A guest VLAN configured with access control lists (ACLs) or private VLAN features isolates guest traffic from the internal corporate VLAN. This ensures guest users can reach the internet via a default gateway or NAT while being unable to route or bridge to internal subnets containing file servers or printers. This is a standard logical segmentation method defined in IEEE 802.1Q.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MAC address filtering on the wireless access point.

    Why it's wrong here

    MAC address filtering permits or denies association based on hardware addresses, so an allowed guest still routes freely to internal file servers and printers; it controls who joins, not what they reach. VLAN segmentation with ACLs enforces the guest-to-internal restriction. MAC filtering suits small allowlists where only specific known devices may associate.

  • ✓

    Implement a guest VLAN that is isolated from the internal network.

    Why this is correct

    A guest VLAN segments traffic at Layer 2, so broadcast domains and inter-VLAN routing keep guest devices away from internal file servers and printers. Access control lists on the router or Layer 3 switch enforce the isolation, satisfying the requirement that guests reach only the internet while internal resources stay unreachable.

  • ✗

    Require a complex password for the guest Wi-Fi network.

    Why it's wrong here

    A complex Wi-Fi password only governs authentication to the guest SSID; once connected, the guest retains full routed access to internal file servers and printers. Logical separation via a guest VLAN and firewall rules is what restricts reachable resources. Strong passphrases suit preventing unauthorised association, not limiting post-connection access.

  • ✗

    Disable the SSID broadcast for the guest network.

    Why it's wrong here

    Hiding the SSID removes the network name from beacon frames only; it is discoverable through probe requests and provides no enforcement boundary between guest and internal subnets. Guest isolation, typically via VLANs and firewall or access control lists, is the logical method that blocks reach to file servers and printers. SSID suppression suits casual deterrence, not segregation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.