220-1101 Networking Practice Question
A network technician is setting up a wireless access point (AP) for a small business. The company's router provides DHCP for the 192.168.1.0/24 network. The AP needs to broadcast two SSIDs: one for employees and one for guest users. The guest network must be completely isolated from the employee network and internal resources, while both SSIDs must have internet access. The AP is connected to a managed switch. Which configuration will BEST meet these requirements?
⚠ Common exam trap
A common mix-up: candidates think client isolation alone is sufficient for guest network security, but they overlook that client isolation only prevents peer-to-peer wireless communication and does not isolate traffic at the network layer from other VLANs or internal resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure VLANs on the managed switch and set the AP to tag the employee SSID on VLAN 10 and the guest SSID on VLAN 20; configure trunk port on switch to the AP
It uses VLANs to logically separate the employee and guest traffic at Layer 2. By configuring the managed switch port as a trunk with VLAN 10 (employee) and VLAN 20 (guest), and having the AP tag each SSID to its respective VLAN, the guest network is isolated from the employee network and internal resources. The router can then route both VLANs to the internet via separate subinterfaces or a Layer 3 switch, ensuring both SSIDs have internet access while maintaining isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place both SSIDs on the same subnet and enable client isolation on the AP
Why it's wrong here
Client isolation on the AP only blocks direct wireless client-to-client frames within the same BSS; it does nothing to prevent guest clients from sending traffic upstream to the wired LAN. Because both SSIDs are placed on the same subnet, guest frames are bridged onto the employee network and can reach internal hosts, printers, and servers. Additionally, client isolation does not filter traffic to the AP's management interface or prevent a guest from performing ARP spoofing to intercept traffic on the wired segment. Effective guest separation requires a separate broadcast domain (VLAN) plus explicit Layer 3 routing rules.
- ✓
Configure VLANs on the managed switch and set the AP to tag the employee SSID on VLAN 10 and the guest SSID on VLAN 20; configure trunk port on switch to the AP
Why this is correct
Configuring separate VLANs for the employee and guest SSIDs and tagging them on an 802.1Q trunk isolates the two networks at Layer 2, so each SSID has its own broadcast domain and no direct path to the other VLAN's wired hosts. The managed switch keeps the frames separate, and the router or Layer 3 switch must be configured with subinterfaces or SVIs to route each VLAN. To satisfy the requirement of internet access for both networks, inter-VLAN routing should be allowed only from each VLAN to the internet, typically by using ACLs or a firewall to deny guest-to-employee traffic. This is the only option that provides a true security boundary while preserving internet connectivity.
- ✗
Configure a DHCP reservation on the router for the AP and set the guest SSID to use a static IP in a different subnet
Why it's wrong here
Simply using a different subnet on the guest SSID does not isolate traffic; the switch and router must still be configured to prevent routing between subnets. Without VLANs or ACLs, the router will forward traffic between subnets by default.
- ✗
Disable the guest network's ability to access the default gateway by changing the AP's management settings
Why it's wrong here
Preventing guest clients from reaching the default gateway would remove their ability to route traffic outside their local subnet, which means they could not reach the internet — directly violating the requirement that both networks have internet access. Furthermore, typical AP management settings govern administrative access to the AP itself, not the client devices' routing decisions; you cannot use this setting to enforce guest isolation. Even if you implemented a restrictive ACL to block guest-to-gateway traffic, you would simply break internet connectivity and still leave guest traffic on the employee subnet, so this approach fails to achieve any meaningful isolation.
Visual reference
Go deeper
Related to this question
Learn chapter
DNS and DHCP Configuration for A+
Key term
Access Point
An access point is a device that creates a wireless local area network, usually by connecting to a wired network and broadcasting a Wi-Fi signal for computers, phones, and tablets to join.
Key term
Service Set Identifier
A Service Set Identifier (SSID) is the public name of a Wi-Fi network that devices use to identify and connect to it.
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.