mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a wireless site survey, a technician…
During a wireless site survey, a technician discovers that an employee has set up a personal wireless router in their cubicle, connected to the corporate network. This rogue access point is broadcasting an open SSID. Which security risk is most immediately concerning?
⚠ Common exam trap
The 220-1202 exam often tests the distinction between operational nuisances (interference, DHCP conflicts, power draw) and actual security threats, so the trap here is that candidates may focus on the technical annoyance of a rogue AP rather than the critical security implication of an unencrypted entry point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rogue AP provides an unencrypted entry point for attackers to access the corporate network.
The most immediate security risk of a rogue access point broadcasting an open SSID is that it provides an unencrypted entry point into the corporate network. Any attacker within range can associate with the open SSID and, because the AP is connected to the corporate LAN, gain direct access to internal resources without authentication or encryption, bypassing perimeter security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The rogue AP may cause radio frequency interference with the corporate WLAN.
Why it's wrong here
While a rogue access point operating on overlapping channels can indeed introduce radio frequency interference, degrading the performance and reliability of the legitimate corporate WLAN, this is typically a performance issue rather than the most critical immediate security threat. The primary concern with a rogue AP is its potential to bypass network security controls, making interference a secondary operational problem that does not directly compromise data integrity or confidentiality.
- ✓
The rogue AP provides an unencrypted entry point for attackers to access the corporate network.
Why this is correct
A rogue access point, especially one configured without encryption or authentication (an open SSID), creates a critical vulnerability by providing an unauthorized and unsecured entry point directly into the corporate network. Attackers can easily connect to this unencrypted network, bypass perimeter defenses, and then launch various attacks, such as sniffing traffic, performing man-in-the-middle attacks, or attempting to access internal resources and sensitive data, posing an immediate and severe security breach.
- ✗
The rogue AP will consume additional power from the corporate UPS.
Why it's wrong here
While a rogue access point, like any active network device, will draw some electrical power, potentially from a corporate UPS if plugged into a protected outlet, this power consumption is a negligible operational concern compared to the significant security risks it introduces. The minimal power draw does not constitute a security threat or a primary reason to identify and remove a rogue device; the focus remains on unauthorized network access and data compromise.
- ✗
The rogue AP's DHCP server may conflict with the corporate DHCP server.
Why it's wrong here
A rogue access point often includes its own DHCP server, which, if active and connected to the corporate network, could indeed issue conflicting IP addresses to legitimate clients, leading to network connectivity issues and service disruptions. However, while DHCP conflicts are an operational nuisance that can hinder network functionality, the more immediate and severe threat posed by a rogue AP is the unauthorized and potentially unencrypted access it grants to the internal network, which directly compromises data security and integrity.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.