Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?

⚠ Common exam trap

The trap here is assuming that hiding the SSID or filtering MAC addresses secures a wireless network, when neither provides encryption for the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable WPA3-Personal with SAE

The reported problem is an open wireless network where traffic is visible to other devices. The fix must add authentication and encryption to the wireless link. WPA3-Personal with SAE provides strong per-session encryption using a shared passphrase, which fits a small office that wants employees to connect with one password while keeping the SSID broadcast for easy discovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable WPA3-Personal with SAE

    Why this is correct

    WPA3-Personal with Simultaneous Authentication of Equals replaces the WPA2 pre-shared key handshake with a password-authenticated key exchange, protecting the wireless traffic and preventing offline dictionary attacks. It keeps a single shared passphrase for employees while encrypting each session, directly addressing the open, unencrypted break-room network described.

  • ✗

    Change the access point to operate on the 5 GHz band only

    Why it's wrong here

    Moving to 5 GHz changes radio frequency and can reduce interference, but it does not add any authentication or encryption. The SSID would still be open and frames would remain readable by any nearby device. Band selection is a performance and coverage decision, not a security control, so it does not solve the reported exposure.

  • ✗

    Disable SSID broadcast on the access point

    Why it's wrong here

    Hiding the SSID does not encrypt traffic and does not stop other devices from monitoring the wireless medium. Any client already associated, or anyone capturing the association handshake, can still see the network name and the unencrypted frames. This leaves the break-room traffic exposed exactly as reported, so it fails the requirement.

  • ✗

    Enable MAC address filtering for known employee devices

    Why it's wrong here

    MAC filtering only limits which hardware addresses may associate; it provides no encryption or confidentiality. An attacker can observe a permitted MAC address in the clear and clone it, then read all other traffic on the open network. Because the traffic remains unencrypted, this does not protect employee data in the break room.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.