220-1201 Networking Practice Question
A small business wants to add a guest wireless network that allows visitors to access the internet but prevents them from reaching internal company resources. The existing network uses a single wireless router with a default configuration. Which of the following should a technician implement?
⚠ Common exam trap
The trap here is assuming that encryption or hiding the SSID provides isolation, when in fact only network segmentation (guest VLAN or client isolation) prevents access to internal resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a separate guest SSID and enable client isolation or a guest VLAN on the wireless router.
A separate guest SSID with client isolation or a guest VLAN isolates guest traffic from the internal network, preventing access to company resources while allowing internet access. This is the most effective and standard solution for the scenario. Other options either do not provide isolation or only add superficial security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the default SSID and disable SSID broadcast to hide the guest network.
Why it's wrong here
Disabling SSID broadcast does not prevent access to internal resources; it only hides the network name. Determined users can still discover and connect to hidden networks. This approach also complicates legitimate guest access. It does not provide the required isolation from the corporate network.
- ✗
Set up MAC filtering to allow only known guest devices on the wireless network.
Why it's wrong here
MAC filtering restricts which devices can connect but does not isolate guests from internal resources. A guest device that is allowed via MAC filtering could still reach corporate systems. MAC addresses can also be spoofed. This option fails to provide the necessary network segmentation.
- ✓
Configure a separate guest SSID and enable client isolation or a guest VLAN on the wireless router.
Why this is correct
Creating a separate guest SSID with client isolation or a dedicated guest VLAN prevents guests from accessing internal company resources while still providing internet access. This is the standard method for guest network segmentation on a small business router. It meets both security and connectivity requirements without additional hardware.
- ✗
Enable WPA3-Personal on the guest SSID and place it on the same VLAN as the corporate network.
Why it's wrong here
WPA3-Personal encrypts wireless traffic, but placing the guest SSID on the same VLAN as the corporate network still allows guests to reach internal resources. The goal is isolation, not just encryption. A separate VLAN or guest network feature is required to restrict access to internal systems. This option does not meet the requirement.
Visual reference
Go deeper
Related to this question
Learn chapter
Proxy Server Configuration
Key term
SSID
An SSID is the public name of a Wi-Fi network that devices use to identify and connect to it.
Key term
Router
A router is a networking device that connects different networks together and directs data traffic between them by choosing the best path for data to travel.
About these practice questions
One of 871 original 220-1201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.