Courseiva
easyMultiple Choice

220-1102 Practice Question: During a security audit, a technician discovers…

During a security audit, a technician discovers that a company's wireless network uses WEP encryption. The network has been in place for 10 years and still uses the original router. What is the most immediate security risk?

⚠ Common exam trap

CompTIA often tests the distinction between a hardware limitation (e.g., outdated firmware or lack of protocol support) and a protocol-level cryptographic weakness, where candidates may incorrectly choose a less direct risk instead of the immediate, proven exploitability of WEP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WEP keys can be easily cracked using tools like Aircrack-ng.

WEP encryption is fundamentally flawed because it uses the RC4 cipher with a weak initialization vector (IV) that is transmitted in plaintext. Tools like Aircrack-ng can capture enough IVs (typically 20,000–40,000) to derive the WEP key within minutes, regardless of key length. This makes the network trivially vulnerable to unauthorized access and data decryption, which is the most immediate and exploitable risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The router may not support modern encryption protocols.

    Why it's wrong here

    Lack of modern protocol support is a capability limitation, not the immediate exploitable risk; WEP itself is already broken regardless of router age. It tempts because legacy hardware often cannot run WPA3, which matters when planning upgrades, but the audit question targets active compromise.

  • ✓

    WEP keys can be easily cracked using tools like Aircrack-ng.

    Why this is correct

    WEP's RC4 stream cipher with short, reused initialisation vectors allows key recovery from captured traffic in minutes using tools such as Aircrack-ng. This makes the wireless network's confidentiality effectively broken, the most immediate risk given the decade-old router still running WEP.

  • ✗

    The router's firmware is likely outdated and vulnerable to exploits.

    Why it's wrong here

    Outdated firmware is a plausible secondary concern, but the question asks for the most immediate risk, which is WEP's cryptographic weakness enabling key recovery within minutes. It tempts because ten-year-old hardware commonly lacks patches, a valid finding in audits, yet it is not the direct consequence of WEP.

  • ✗

    WEP does not support WPA2-PSK, so clients must use a different protocol.

    Why it's wrong here

    WEP's flaw is that its RC4 keystream and static keys are crackable, not that it cannot coexist with WPA2-PSK; clients can simply be reconfigured. It tempts because protocol incompatibility sounds like a migration blocker, but the immediate risk is unauthorised network access through key recovery.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.