Courseiva
Security →easyMultiple Choice

FC0-U71 Security Practice Question

A small business owner installs a wireless access point in a coffee shop for customers. The owner wants to prevent strangers outside the building from reading the wireless traffic of paying customers. Which security feature should be enabled on the access point?

⚠ Common exam trap

The trap here is assuming that hiding the network name or filtering MAC addresses keeps wireless traffic private, when neither actually encrypts the data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3 encryption with a shared passphrase

Wireless signals travel through walls and into public spaces, so the only reliable way to keep outsiders from reading customer traffic is strong over-the-air encryption. WPA3 with a shared passphrase encrypts every frame using SAE, preventing passive eavesdroppers from recovering data even if they capture the radio transmissions. Hiding the SSID, filtering MAC addresses, and lowering power are obscurity or access measures that leave traffic readable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAC address filtering on the access point

    Why it's wrong here

    MAC filtering maintains an allow-list of client hardware addresses, but addresses are transmitted in cleartext in every frame and can be spoofed trivially with a single command. It also does nothing to encrypt traffic, so a passive outsider still reads customer data. This control addresses unauthorized association, not confidentiality of the wireless traffic itself.

  • ✓

    WPA3 encryption with a shared passphrase

    Why this is correct

    WPA3 encrypts wireless frames between client devices and the access point using SAE, so anyone capturing the radio signals cannot read the customer traffic. It also replaces the weak WPA2 handshake, resisting offline dictionary attacks. Enabling WPA3 with a shared passphrase directly satisfies the goal of stopping outsiders from reading over-the-air data in the coffee shop.

  • ✗

    Disabling the SSID broadcast

    Why it's wrong here

    Hiding the network name only removes it from casual scan lists; the beacon still exists in probe responses, and tools like airodump-ng reveal the hidden SSID in seconds. It provides no encryption, so an outsider who knows or discovers the SSID can still capture and read all customer traffic in cleartext. This does not meet the confidentiality requirement.

  • ✗

    Reducing the transmit power of the access point

    Why it's wrong here

    Lowering transmit power shrinks the radio footprint but cannot contain it inside a building; signals still leak to parking lots and adjacent streets, and directional antennas can capture them from far away. More importantly, reduced power provides no cryptographic protection, so any captured frames remain readable. It is a coverage-tuning measure, not an encryption control.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.