Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is setting up a wireless network for…

A technician is setting up a wireless network for a small office that handles sensitive client data. The office has a mix of modern laptops and a few legacy printers that only support WEP. What should the technician do to maintain security while keeping the printers functional?

⚠ Common exam trap

Watch out — candidates often think mixed mode (WEP + WPA2) is a valid compromise, but CompTIA A+ tests the understanding that mixed mode on a single SSID downgrades security for all devices, whereas VLAN segmentation isolates the weak protocol without affecting the secure network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a separate VLAN for the printers using WEP and a strong passphrase, and keep the main network on WPA2.

It isolates the insecure WEP-based printers on a separate VLAN, preventing their weak encryption from compromising the main network which uses WPA2. This allows the legacy printers to remain functional while sensitive client data on the main network is protected by the stronger WPA2 protocol.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable WEP on the main router and set a complex 128-bit key.

    Why it's wrong here

    Enabling WEP (Wired Equivalent Privacy) on the main router, even with a complex 128-bit key, is fundamentally insecure. WEP has well-documented cryptographic weaknesses, such as weak Initialization Vectors (IVs) and static key management, making it highly susceptible to brute-force attacks and packet injection within minutes. Implementing WEP across the entire network compromises the security of all connected devices and data, exposing sensitive information to potential interception and unauthorized access, thus failing to meet modern security standards.

  • Replace the printers with modern ones that support WPA2.

    Why it's wrong here

    Replacing the printers with WPA2-compatible models would resolve the encryption weakness of WEP, but the scenario explicitly requires keeping the legacy printers functional. The correct approach must accommodate the printers’ WEP-only hardware, not eliminate it. This option is tempting because upgrading hardware is a straightforward way to enforce a stronger encryption standard like WPA2, and it would be correct if the requirement were to eliminate all WEP devices rather than maintain existing ones.

  • Create a separate VLAN for the printers using WEP and a strong passphrase, and keep the main network on WPA2.

    Why this is correct

    Creating a separate Virtual Local Area Network (VLAN) for the legacy WEP printers effectively segments the network, isolating the inherent security weaknesses of WEP to a dedicated subnet. This ensures that the main network, which carries sensitive data, can maintain robust WPA2 encryption without being compromised by the less secure WEP traffic. Network segmentation prevents an attacker who might compromise the WEP VLAN from easily accessing resources on the more secure WPA2 network, thus mitigating risk while accommodating legacy hardware.

  • Set the router to mixed mode (WEP + WPA2) and use a single SSID.

    Why it's wrong here

    Setting a router to mixed mode (WEP + WPA2) with a single SSID forces the entire wireless network to operate at the security level of its weakest link, which is WEP. Even if WPA2-capable devices connect, the presence of WEP-enabled devices on the same SSID means that an attacker can exploit WEP vulnerabilities to gain access to the network, potentially compromising all traffic. This configuration undermines the stronger WPA2 encryption for all users, failing to provide adequate protection for sensitive data.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.