mediumMultiple ChoiceObjective-mapped
FC0-U71 Practice Question: A small business wants to secure its wireless…
A small business wants to secure its wireless network. Which configuration provides the strongest encryption?
⚠ Common exam trap
Test-takers frequently confuse 'strongest' with 'most common' and select WPA2 because it is widely deployed, forgetting that WPA3 is the current gold standard and explicitly tested as the most secure option in the CompTIA FC0-U61 objectives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3
WPA3 (Wi-Fi Protected Access 3) is the latest wireless security standard, introduced in 2018, which provides the strongest encryption through mandatory use of 192-bit AES encryption in WPA3-Enterprise and 128-bit AES in WPA3-Personal, along with Simultaneous Authentication of Equals (SAE) to replace the vulnerable Pre-Shared Key (PSK) exchange used in WPA2. This makes it resistant to offline dictionary attacks and provides forward secrecy, ensuring that even if a password is compromised, past sessions remain secure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA
Why it's wrong here
WPA improves on WEP but is still less secure than WPA2 and WPA3.
- ✗
WEP
Why it's wrong here
WEP is outdated and easily cracked due to weak encryption.
- ✗
WPA2
Why it's wrong here
WPA2 is strong but has been superseded by WPA3, which is more secure.
- ✓
WPA3
Why this is correct
WPA3 offers stronger encryption and improved security features over older standards.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.