Courseiva
mediumMultiple Choice

FC0-U71 Practice Question: A small business wants to set up a wireless…

A small business wants to set up a wireless network for employees and guests. The owners are concerned about unauthorized access. Which of the following security measures would be MOST effective to prevent outsiders from connecting?

⚠ Common exam trap

A common mix-up: candidates think MAC filtering or hiding the SSID are strong security measures, but these are 'security through obscurity' techniques that provide no real protection against a determined attacker.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use WPA2 encryption with a strong passphrase

WPA2 encryption with a strong passphrase is the most effective measure because it encrypts all wireless traffic and requires authentication before a device can join the network. Without the correct pre-shared key (PSK), an attacker cannot decrypt the data or gain access, even if they can see the network. This directly prevents unauthorized outsiders from connecting, unlike the other options which are easily bypassed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MAC address filtering

    Why it's wrong here

    MAC filtering only checks a spoofable hardware identifier, so an attacker who observes a permitted address can clone it and associate. It provides no cryptographic authentication of the client. Filtering suits small environments restricting known devices, not deterring outsiders who can capture and reuse MACs.

  • ✗

    Disable SSID broadcast

    Why it's wrong here

    Hiding the SSID stops the network appearing in casual client scans, but determined outsiders still detect it through probe requests and connect once the name is known. Encryption with strong authentication is what actually blocks unauthorised association. Disabling broadcast suits reducing casual discovery, not preventing access.

  • ✗

    Disable DHCP on the router

    Why it's wrong here

    Disabling DHCP merely forces clients to configure addresses manually; outsiders can still associate and set a static IP within the subnet. It does not authenticate anyone before connection. This suits controlling address assignment on trusted wired segments, not preventing wireless intrusion.

  • ✓

    Use WPA2 encryption with a strong passphrase

    Why this is correct

    WPA2 encrypts the wireless traffic and enforces authentication via a strong passphrase, so devices lacking the credential cannot associate with the access point. This directly prevents outsiders from connecting, satisfying the owners' stated concern about unauthorised access.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.