mediumMultiple Choice
220-1102 Practice Question: A technician is setting up a new wireless network…
A technician is setting up a new wireless network for a small office. They want to ensure that only company-issued devices can connect, and that data transmitted over the air is encrypted. Which combination of settings should they use?
⚠ Common exam trap
A common misconception is that disabling SSID broadcast or using MAC filtering alone provides strong security, but the trap here is that encryption (WPA3 with AES) is the primary defense, and MAC filtering is only a supplementary control, not a replacement for encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3 with AES encryption and MAC address filtering.
WPA3 with AES encryption provides the strongest wireless security standard, ensuring robust data confidentiality and integrity. MAC address filtering adds an additional layer of access control, allowing only company-issued devices (with pre-approved MAC addresses) to connect, which aligns with the requirement to restrict access to authorized devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2 with TKIP encryption and SSID broadcast disabled.
Why it's wrong here
TKIP is deprecated and lacks the stronger encryption of AES-CCMP; disabling SSID broadcast hides the network name but does not restrict which devices connect. It is tempting because WPA2 sounds secure and hidden SSIDs feel exclusive, and would suit legacy hardware needing WPA2-TKIP compatibility.
- ✓
WPA3 with AES encryption and MAC address filtering.
Why this is correct
WPA3 with AES encrypts over-the-air traffic using the strongest current Wi-Fi cipher, while MAC address filtering restricts association to company-issued device hardware addresses. Together they satisfy both stated constraints: encryption of transmitted data and limiting connectivity to approved devices.
- ✗
WEP with 128-bit key and a strong password.
Why it's wrong here
WEP's RC4 keystream is trivially cracked regardless of key length, so it cannot encrypt over-the-air data securely, and it offers no device-identity mechanism. It is tempting because WEP was the original 802.11 privacy standard and 128-bit keys sound strong, but it would only suit legacy hardware that cannot support WPA2/WPA3 or 802.1X.
- ✗
Open network with a captive portal requiring employee login.
Why it's wrong here
An open network with a captive portal provides no over-the-air encryption and authenticates users, not company-issued devices. It is tempting because captive portals gate access via login, and would be correct for guest Wi-Fi where per-user authentication, not device restriction or link encryption, is required.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Fire Suppression Systems in Data Center
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.