Courseiva
mediumMultiple ChoiceObjective-mapped

FC0-U71 Practice Question: A small business wants to secure its wireless…

A small business wants to secure its wireless network. Which configuration provides the strongest encryption?

⚠ Common exam trap

Test-takers frequently confuse 'strongest' with 'most common' and select WPA2 because it is widely deployed, forgetting that WPA3 is the current gold standard and explicitly tested as the most secure option in the CompTIA FC0-U61 objectives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

WPA3

WPA3 (Wi-Fi Protected Access 3) is the latest wireless security standard, introduced in 2018, which provides the strongest encryption through mandatory use of 192-bit AES encryption in WPA3-Enterprise and 128-bit AES in WPA3-Personal, along with Simultaneous Authentication of Equals (SAE) to replace the vulnerable Pre-Shared Key (PSK) exchange used in WPA2. This makes it resistant to offline dictionary attacks and provides forward secrecy, ensuring that even if a password is compromised, past sessions remain secure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WPA

    Why it's wrong here

    WPA improves on WEP but is still less secure than WPA2 and WPA3.

  • WEP

    Why it's wrong here

    WEP is outdated and easily cracked due to weak encryption.

  • WPA2

    Why it's wrong here

    WPA2 is strong but has been superseded by WPA3, which is more secure.

  • WPA3

    Why this is correct

    WPA3 offers stronger encryption and improved security features over older standards.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.