Courseiva
mediumMultiple Choice

220-1102 Practice Question: A technician is configuring a wireless network…

A technician is configuring a wireless network for a new office. The network must support legacy devices that only support WPA-TKIP, but the technician also wants to maximize security for modern devices. Which configuration should the technician use?

⚠ Common exam trap

CompTIA often tests the misconception that a mixed-mode SSID (WPA2 with TKIP fallback) is a safe compromise, when in fact it can force all clients to use weaker encryption or cause performance degradation, making separate SSIDs the correct approach for legacy support without compromising modern security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set up a separate SSID with WPA-TKIP for legacy devices and another SSID with WPA2-AES for modern devices.

It isolates legacy WPA-TKIP devices on a separate SSID, preventing the weaker TKIP encryption from compromising the security of modern devices. Modern devices can then connect to a second SSID using WPA2-AES, which provides strong encryption (CCMP) and is not vulnerable to TKIP-specific attacks like Michael MIC exhaustion. This approach satisfies both requirements without forcing all devices onto a single, less secure configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable WPA3-SAE for all devices.

    Why it's wrong here

    WPA3-SAE is not backward compatible with WPA-TKIP-only legacy clients, so those devices cannot associate at all. It is tempting because SAE delivers the strongest modern security, and it would be the right sole choice on a network containing only WPA3-capable hardware.

  • ✗

    Use WPA2-PSK with TKIP encryption.

    Why it's wrong here

    WPA2-PSK with TKIP forces modern clients onto the deprecated TKIP cipher, capping the network at WPA-level security instead of allowing AES-CCMP. TKIP-only configuration suits environments where every device is legacy and no AES-capable hardware exists.

  • ✗

    Configure the router for WPA2-PSK with AES and enable WPA-TKIP as a fallback.

    Why it's wrong here

    Enabling WPA-TKIP as a fallback alongside WPA2-PSK/AES permits downgrade attacks and forces the group cipher to TKIP, weakening modern clients. Mixed-mode fallback suits transitional deployments where legacy hardware cannot be upgraded, but it sacrifices the AES-only guarantees the scenario demands.

  • ✓

    Set up a separate SSID with WPA-TKIP for legacy devices and another SSID with WPA2-AES for modern devices.

    Why this is correct

    WPA-TKIP and WPA2-AES use incompatible cipher suites, so a single SSID cannot serve both securely. Separate SSIDs let legacy clients associate using TKIP while modern devices negotiate AES-CCMP, satisfying the legacy support requirement without weakening modern encryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.