easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is setting up a wireless network for…
A technician is setting up a wireless network for a home office. The client is concerned about neighbors accessing their internet. The technician enables WPA2-PSK with a strong passphrase. Which additional step should the technician take to ensure the network is as secure as possible?
⚠ Common exam trap
CompTIA often tests the misconception that hiding the SSID or using MAC filtering provides meaningful security, when in reality the WPS vulnerability is a far more critical and exploitable flaw that must be addressed first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable WPS on the router.
WPA2-PSK with a strong passphrase already provides robust encryption, but WPS (Wi-Fi Protected Setup) introduces a significant vulnerability. WPS allows devices to connect via an 8-digit PIN, which can be brute-forced in a matter of hours using tools like Reaver, exposing the network to unauthorized access. Disabling WPS eliminates this attack vector, making the network as secure as possible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable WPS for easy device pairing.
Why it's wrong here
Enabling Wi-Fi Protected Setup (WPS) simplifies device connection by allowing users to press a button or enter a short PIN. However, WPS is critically flawed due to a design vulnerability that allows brute-force attacks against its 8-digit PIN. This vulnerability can reveal the entire wireless network's passphrase in a matter of hours, making it a significant security risk. Therefore, enabling WPS compromises network security rather than enhancing it.
- ✗
Disable SSID broadcast.
Why it's wrong here
Disabling the Service Set Identifier (SSID) broadcast attempts to hide the network from casual observation, but it offers negligible security benefits. Tools readily available can easily detect non-broadcasting SSIDs, especially when client devices attempt to connect. Furthermore, hiding the SSID can complicate network setup and troubleshooting for legitimate users, as devices may struggle to automatically discover and connect to the network. It's a security theater rather than a robust defense.
- ✓
Disable WPS on the router.
Why this is correct
Disabling Wi-Fi Protected Setup (WPS) on the router is a crucial security best practice for wireless networks. The WPS protocol, particularly its PIN-based method, is susceptible to brute-force attacks that can rapidly determine the network's WPA/WPA2 passphrase. By deactivating WPS, a technician eliminates this significant attack vector, forcing potential intruders to attempt more resource-intensive and time-consuming methods, such as direct brute-forcing of the WPA2 passphrase, which is far more difficult to achieve.
- ✗
Enable MAC address filtering.
Why it's wrong here
Enabling MAC address filtering attempts to restrict network access to only devices with pre-approved Media Access Control (MAC) addresses. While seemingly secure, this method is easily circumvented because MAC addresses are transmitted unencrypted and can be readily spoofed by an attacker. An intruder can simply capture a legitimate MAC address from network traffic and configure their own device to use it, thereby bypassing the filter entirely. Consequently, MAC filtering provides a false sense of security and should not be relied upon as a primary defense.
Go deeper
Related to this question
Learn chapter
Windows Command Line Tools
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.