FC0-U71 Security Practice Question
A small business owner installs a wireless access point in a coffee shop for customers. The owner wants to prevent strangers outside the building from reading the wireless traffic of paying customers. Which security feature should be enabled on the access point?
⚠ Common exam trap
The trap here is assuming that hiding the network name or filtering MAC addresses keeps wireless traffic private, when neither actually encrypts the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3 encryption with a shared passphrase
Wireless signals travel through walls and into public spaces, so the only reliable way to keep outsiders from reading customer traffic is strong over-the-air encryption. WPA3 with a shared passphrase encrypts every frame using SAE, preventing passive eavesdroppers from recovering data even if they capture the radio transmissions. Hiding the SSID, filtering MAC addresses, and lowering power are obscurity or access measures that leave traffic readable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC address filtering on the access point
Why it's wrong here
MAC filtering maintains an allow-list of client hardware addresses, but addresses are transmitted in cleartext in every frame and can be spoofed trivially with a single command. It also does nothing to encrypt traffic, so a passive outsider still reads customer data. This control addresses unauthorized association, not confidentiality of the wireless traffic itself.
- ✓
WPA3 encryption with a shared passphrase
Why this is correct
WPA3 encrypts wireless frames between client devices and the access point using SAE, so anyone capturing the radio signals cannot read the customer traffic. It also replaces the weak WPA2 handshake, resisting offline dictionary attacks. Enabling WPA3 with a shared passphrase directly satisfies the goal of stopping outsiders from reading over-the-air data in the coffee shop.
- ✗
Disabling the SSID broadcast
Why it's wrong here
Hiding the network name only removes it from casual scan lists; the beacon still exists in probe responses, and tools like airodump-ng reveal the hidden SSID in seconds. It provides no encryption, so an outsider who knows or discovers the SSID can still capture and read all customer traffic in cleartext. This does not meet the confidentiality requirement.
- ✗
Reducing the transmit power of the access point
Why it's wrong here
Lowering transmit power shrinks the radio footprint but cannot contain it inside a building; signals still leak to parking lots and adjacent streets, and directional antennas can capture them from far away. More importantly, reduced power provides no cryptographic protection, so any captured frames remain readable. It is a coverage-tuning measure, not an encryption control.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.