220-1101 Networking Practice Question
A small office wants to provide guest Wi-Fi access without allowing guests to access the internal company network. Which of the following is the BEST way to isolate guest traffic?
⚠ Common exam trap
CompTIA often tests the misconception that encryption or authentication alone (like WPA2 or MAC filtering) provides network segmentation, when in fact only Layer 2 or Layer 3 isolation methods (VLANs, subnets, firewalls) can prevent lateral movement between guest and corporate traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a separate VLAN for guest traffic.
A separate VLAN (Virtual Local Area Network) segments guest traffic at Layer 2, preventing it from reaching the internal company network. By assigning guest Wi-Fi traffic to a dedicated VLAN with no inter-VLAN routing to the corporate VLAN, guests are logically isolated even though they share the same physical infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a separate VLAN for guest traffic.
Why this is correct
A separate VLAN segments the guest traffic into its own Layer 2 broadcast domain, isolated from internal VLANs. Because inter-VLAN routing is controlled by the router/firewall, guests can only reach the internet and designated public resources, not internal endpoints. This is the standard approach for secure guest Wi-Fi.
- ✗
Set a strong WPA2 password.
Why it's wrong here
A strong WPA2 password protects the wireless link from unauthorized eavesdropping and prevents casual attackers from joining the Wi-Fi. However, once a guest successfully authenticates, they are placed on the same IP subnet and Layer 2 segment as internal devices, giving them unrestricted access to internal file shares, printers, and administrative interfaces. Strong encryption alone does not enforce network segregation.
When this WOULD be correct
A small office wants to secure its wireless network from unauthorized access. Which of the following is the BEST way to prevent unauthorized users from connecting?
- ✗
Enable MAC address filtering.
Why it's wrong here
MAC address filtering restricts which devices can associate based on hardware addresses, but it does not restrict what authenticated devices can access. An intruder can spoof an approved MAC address using simple software, and even a legitimate guest device, once allowed, can freely communicate with internal network hosts. This method is an access control, not a traffic isolation mechanism, so it fails to protect internal resources from connected guests.
When this WOULD be correct
A question asking for the best method to prevent unauthorized devices from connecting to a Wi-Fi network, where the goal is to restrict access to only known devices, would make MAC address filtering the correct answer.
- ✗
Disable SSID broadcast.
Why it's wrong here
Disabling SSID broadcast merely prevents the access point from announcing the network name in beacon frames. Tools like airmon-ng or Kismet can still discover the hidden SSID by passively monitoring probe requests and association frames. Once connected, the guest remains in the same flat network, with no isolation from internal resources, so it is purely a visibility control with no security benefit.
When this WOULD be correct
A question asking for the best way to reduce network visibility to casual users, such as 'A coffee shop wants to prevent customers from easily seeing the Wi-Fi network name in their device list. Which of the following should be configured?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓Configure a separate VLAN for guest traffic.Correct answer▾
Why this is correct
A separate VLAN segments the guest traffic into its own Layer 2 broadcast domain, isolated from internal VLANs. Because inter-VLAN routing is controlled by the router/firewall, guests can only reach the internet and designated public resources, not internal endpoints. This is the standard approach for secure guest Wi-Fi.
✗Set a strong WPA2 password.Wrong answer — click to see why▾
Why this is wrong here
Setting a strong WPA2 password secures the Wi-Fi network but does not isolate guest traffic from the internal network; guests can still access internal resources once authenticated.
★ When this WOULD be the correct answer
A small office wants to secure its wireless network from unauthorized access. Which of the following is the BEST way to prevent unauthorized users from connecting?
Why candidates choose this
Candidates may think that a strong password prevents guests from accessing the internal network, but it only controls access to the wireless network itself, not traffic isolation.
✗Enable MAC address filtering.Wrong answer — click to see why▾
Why this is wrong here
MAC address filtering controls which devices can connect based on their MAC addresses, but it does not isolate guest traffic from the internal network. Once a guest device is authenticated, it can still access internal resources unless additional network segmentation is in place.
★ When this WOULD be the correct answer
A question asking for the best method to prevent unauthorized devices from connecting to a Wi-Fi network, where the goal is to restrict access to only known devices, would make MAC address filtering the correct answer.
Why candidates choose this
Candidates may think MAC filtering provides security by only allowing approved devices, but they overlook that it does not address traffic isolation between guest and internal networks.
✗Disable SSID broadcast.Wrong answer — click to see why▾
Why this is wrong here
Disabling SSID broadcast only hides the network name from passive scans; it does not isolate guest traffic from the internal network. Guests can still access internal resources if connected to the same subnet.
★ When this WOULD be the correct answer
A question asking for the best way to reduce network visibility to casual users, such as 'A coffee shop wants to prevent customers from easily seeing the Wi-Fi network name in their device list. Which of the following should be configured?'
Why candidates choose this
Candidates may think hiding the SSID prevents unauthorized access or isolates traffic, confusing security through obscurity with network segmentation.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.