Courseiva
mediumMultiple Choice

220-1102 Practice Question: A small business owner wants to replace their old…

A small business owner wants to replace their old wireless router because guests have been using the network to access inappropriate content. The owner wants to isolate guest traffic from the main business network and enforce content filtering. Which combination of wireless security and features should the technician recommend?

⚠ Common exam trap

It's easy for candidates to choose WPA3-Personal or WPA2-Enterprise thinking stronger encryption equals better security, but the question specifically requires guest isolation and content filtering, which are features of a guest network and DNS-level filtering, not of the authentication protocol itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-PSK with a guest network enabled and content filtering via OpenDNS.

WPA2-PSK with a guest network creates a separate VLAN or subnet that isolates guest traffic from the main business network, preventing guests from accessing internal resources. Content filtering via OpenDNS provides DNS-level filtering to block inappropriate content without requiring additional hardware, addressing both isolation and content control requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA3-Personal with MAC address filtering.

    Why it's wrong here

    MAC address filtering restricts which known devices associate, and WPA3-Personal secures the link, but neither creates a separate guest network nor filters content. A guest SSID with client isolation and a content-filtering service is what the scenario requires; MAC filtering is for whitelisting specific hardware.

  • ✓

    WPA2-PSK with a guest network enabled and content filtering via OpenDNS.

    Why this is correct

    WPA2-PSK secures the wireless link, while a guest network provides a separate SSID and VLAN, isolating visitor traffic from business resources. OpenDNS enforces content filtering at the DNS layer, satisfying the requirement to block inappropriate content without extra hardware.

  • ✗

    WPA2-Enterprise with a RADIUS server and no guest network.

    Why it's wrong here

    WPA2-Enterprise with RADIUS authenticates individual users via 802.1X, which is the right choice for corporate staff access, but omitting a guest network leaves visitors on the business LAN with no isolation or filtering. The scenario needs a segregated guest SSID with content filtering.

  • ✗

    WEP encryption with a hidden SSID.

    Why it's wrong here

    WEP is cryptographically broken and a hidden SSID is trivially discovered, so neither isolates guest traffic nor filters content. WEP suits only legacy hardware compatibility; the requirement here is a separate guest network with client isolation and content filtering.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.