Courseiva
mediumMultiple Choice

220-1102 Practice Question: A technician is setting up a new wireless network…

A technician is setting up a new wireless network for a small office. They want to ensure that only company-issued devices can connect, and that data transmitted over the air is encrypted. Which combination of settings should they use?

⚠ Common exam trap

A common misconception is that disabling SSID broadcast or using MAC filtering alone provides strong security, but the trap here is that encryption (WPA3 with AES) is the primary defense, and MAC filtering is only a supplementary control, not a replacement for encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3 with AES encryption and MAC address filtering.

WPA3 with AES encryption provides the strongest wireless security standard, ensuring robust data confidentiality and integrity. MAC address filtering adds an additional layer of access control, allowing only company-issued devices (with pre-approved MAC addresses) to connect, which aligns with the requirement to restrict access to authorized devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2 with TKIP encryption and SSID broadcast disabled.

    Why it's wrong here

    TKIP is deprecated and lacks the stronger encryption of AES-CCMP; disabling SSID broadcast hides the network name but does not restrict which devices connect. It is tempting because WPA2 sounds secure and hidden SSIDs feel exclusive, and would suit legacy hardware needing WPA2-TKIP compatibility.

  • ✓

    WPA3 with AES encryption and MAC address filtering.

    Why this is correct

    WPA3 with AES encrypts over-the-air traffic using the strongest current Wi-Fi cipher, while MAC address filtering restricts association to company-issued device hardware addresses. Together they satisfy both stated constraints: encryption of transmitted data and limiting connectivity to approved devices.

  • ✗

    WEP with 128-bit key and a strong password.

    Why it's wrong here

    WEP's RC4 keystream is trivially cracked regardless of key length, so it cannot encrypt over-the-air data securely, and it offers no device-identity mechanism. It is tempting because WEP was the original 802.11 privacy standard and 128-bit keys sound strong, but it would only suit legacy hardware that cannot support WPA2/WPA3 or 802.1X.

  • ✗

    Open network with a captive portal requiring employee login.

    Why it's wrong here

    An open network with a captive portal provides no over-the-air encryption and authenticates users, not company-issued devices. It is tempting because captive portals gate access via login, and would be correct for guest Wi-Fi where per-user authentication, not device restriction or link encryption, is required.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.