Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is setting up a wireless network for…

A technician is setting up a wireless network for a home office. The client is concerned about neighbors accessing their internet. The technician enables WPA2-PSK with a strong passphrase. Which additional step should the technician take to ensure the network is as secure as possible?

⚠ Common exam trap

CompTIA often tests the misconception that hiding the SSID or using MAC filtering provides meaningful security, when in reality the WPS vulnerability is a far more critical and exploitable flaw that must be addressed first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable WPS on the router.

WPA2-PSK with a strong passphrase already provides robust encryption, but WPS (Wi-Fi Protected Setup) introduces a significant vulnerability. WPS allows devices to connect via an 8-digit PIN, which can be brute-forced in a matter of hours using tools like Reaver, exposing the network to unauthorized access. Disabling WPS eliminates this attack vector, making the network as secure as possible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable WPS for easy device pairing.

    Why it's wrong here

    Enabling Wi-Fi Protected Setup (WPS) simplifies device connection by allowing users to press a button or enter a short PIN. However, WPS is critically flawed due to a design vulnerability that allows brute-force attacks against its 8-digit PIN. This vulnerability can reveal the entire wireless network's passphrase in a matter of hours, making it a significant security risk. Therefore, enabling WPS compromises network security rather than enhancing it.

  • Disable SSID broadcast.

    Why it's wrong here

    Disabling the Service Set Identifier (SSID) broadcast attempts to hide the network from casual observation, but it offers negligible security benefits. Tools readily available can easily detect non-broadcasting SSIDs, especially when client devices attempt to connect. Furthermore, hiding the SSID can complicate network setup and troubleshooting for legitimate users, as devices may struggle to automatically discover and connect to the network. It's a security theater rather than a robust defense.

  • Disable WPS on the router.

    Why this is correct

    Disabling Wi-Fi Protected Setup (WPS) on the router is a crucial security best practice for wireless networks. The WPS protocol, particularly its PIN-based method, is susceptible to brute-force attacks that can rapidly determine the network's WPA/WPA2 passphrase. By deactivating WPS, a technician eliminates this significant attack vector, forcing potential intruders to attempt more resource-intensive and time-consuming methods, such as direct brute-forcing of the WPA2 passphrase, which is far more difficult to achieve.

  • Enable MAC address filtering.

    Why it's wrong here

    Enabling MAC address filtering attempts to restrict network access to only devices with pre-approved Media Access Control (MAC) addresses. While seemingly secure, this method is easily circumvented because MAC addresses are transmitted unencrypted and can be readily spoofed by an attacker. An intruder can simply capture a legitimate MAC address from network traffic and configure their own device to use it, thereby bypassing the filter entirely. Consequently, MAC filtering provides a false sense of security and should not be relied upon as a primary defense.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.