FC0-U71 Security Practice Question
A small business owner wants to secure the wireless network at a retail store. The owner wants customers to have internet access without needing a password, but also wants to keep the internal point-of-sale (POS) network separate and protected. Which of the following should the owner configure?
⚠ Common exam trap
The trap here is assuming that hiding the SSID or filtering MAC addresses provides security equivalent to network segmentation for guest access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up a guest network with SSID isolation and client isolation enabled.
The requirement is to give customers open internet access while keeping the POS network protected. A separate guest network with client isolation achieves this by segmenting traffic and preventing guests from reaching internal devices. Other options either require credentials, do not segment traffic, or rely on easily bypassed controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable WPA3-Personal on the main network and share the passphrase only with employees.
Why it's wrong here
WPA3-Personal with a shared passphrase protects the network, but it does not allow unauthenticated guest access. Customers would need the passphrase, which would also give them access to the POS network segment. This does not meet the requirement of open customer access while isolating internal systems.
- ✗
Configure MAC address filtering to allow only known customer devices on the wireless network.
Why it's wrong here
MAC address filtering restricts access to a predefined list of devices, which is impractical for a retail store with many unknown customers. It also does not separate guest traffic from the POS network, and MAC addresses can be spoofed, so it fails to meet the goal of open access with internal protection.
- ✗
Disable SSID broadcasting on the wireless access point.
Why it's wrong here
Disabling SSID broadcasting hides the network name but does not prevent determined users from connecting, and it does not provide guest access or isolation. Customers would still need the SSID and credentials, and the POS network would remain on the same broadcast domain, so this fails the scenario requirements.
- ✓
Set up a guest network with SSID isolation and client isolation enabled.
Why this is correct
A guest network with a separate SSID, VLAN, and client isolation allows customers to connect without a password while keeping their traffic and the internal POS network separate. This is the standard method to provide public access without exposing internal resources, and it directly meets both stated requirements.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.