mediumMultiple Choice
220-1102 Practice Question: A technician is configuring a wireless network…
A technician is configuring a wireless network for a new office. The network must support legacy devices that only support WPA-TKIP, but the technician also wants to maximize security for modern devices. Which configuration should the technician use?
⚠ Common exam trap
CompTIA often tests the misconception that a mixed-mode SSID (WPA2 with TKIP fallback) is a safe compromise, when in fact it can force all clients to use weaker encryption or cause performance degradation, making separate SSIDs the correct approach for legacy support without compromising modern security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up a separate SSID with WPA-TKIP for legacy devices and another SSID with WPA2-AES for modern devices.
It isolates legacy WPA-TKIP devices on a separate SSID, preventing the weaker TKIP encryption from compromising the security of modern devices. Modern devices can then connect to a second SSID using WPA2-AES, which provides strong encryption (CCMP) and is not vulnerable to TKIP-specific attacks like Michael MIC exhaustion. This approach satisfies both requirements without forcing all devices onto a single, less secure configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable WPA3-SAE for all devices.
Why it's wrong here
WPA3-SAE is not backward compatible with WPA-TKIP-only legacy clients, so those devices cannot associate at all. It is tempting because SAE delivers the strongest modern security, and it would be the right sole choice on a network containing only WPA3-capable hardware.
- ✗
Use WPA2-PSK with TKIP encryption.
Why it's wrong here
WPA2-PSK with TKIP forces modern clients onto the deprecated TKIP cipher, capping the network at WPA-level security instead of allowing AES-CCMP. TKIP-only configuration suits environments where every device is legacy and no AES-capable hardware exists.
- ✗
Configure the router for WPA2-PSK with AES and enable WPA-TKIP as a fallback.
Why it's wrong here
Enabling WPA-TKIP as a fallback alongside WPA2-PSK/AES permits downgrade attacks and forces the group cipher to TKIP, weakening modern clients. Mixed-mode fallback suits transitional deployments where legacy hardware cannot be upgraded, but it sacrifices the AES-only guarantees the scenario demands.
- ✓
Set up a separate SSID with WPA-TKIP for legacy devices and another SSID with WPA2-AES for modern devices.
Why this is correct
WPA-TKIP and WPA2-AES use incompatible cipher suites, so a single SSID cannot serve both securely. Separate SSIDs let legacy clients associate using TKIP while modern devices negotiate AES-CCMP, satisfying the legacy support requirement without weakening modern encryption.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Temporal Key Integrity Protocol
TKIP is a security protocol used in Wi-Fi networks to strengthen encryption by dynamically changing the encryption key for each data packet.
Key term
TKIP
TKIP is a security protocol used in WPA to replace WEP's static key with dynamic per-packet keys, ensuring data integrity.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.