easyMultiple Choice
FC0-U71 Practice Question: A small business wants to set up a wireless…
A small business wants to set up a wireless network. Which of the following is the BEST security method to use?
⚠ Common exam trap
Candidates often confuse security features like MAC filtering or hiding the SSID with actual encryption, thinking they provide strong protection, when in fact they are easily bypassed and do not secure the data in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2
WPA2 (Wi-Fi Protected Access 2) is the best security method among the options because it uses AES (Advanced Encryption Standard) with CCMP (Counter Mode CBC-MAC Protocol), providing strong encryption and integrity protection. WEP is outdated and easily cracked, while MAC filtering and disabling SSID broadcast are not encryption methods and offer minimal security against determined attackers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WEP
Why it's wrong here
WEP's RC4 stream cipher with static, reusable keys and weak IVs is trivially cracked, so it cannot secure a new wireless network. It is tempting because legacy hardware supports it, and it would suit only a lab or obsolete device that cannot negotiate WPA2 or WPA3.
- ✓
WPA2
Why this is correct
WPA2 uses AES-based CCMP encryption and per-session keys, resisting the weaknesses that broke WEP and the TKIP compromises. For a small business needing strong, widely compatible wireless security without enterprise infrastructure, WPA2 satisfies the requirement.
- ✗
MAC address filtering
Why it's wrong here
MAC address filtering permits only listed hardware addresses, yet MAC addresses are transmitted in cleartext and can be spoofed, and it provides no encryption. It suits restricting a small, fixed set of known devices, not protecting a business network where credentials and data must be encrypted.
- ✗
Disable SSID broadcast
Why it's wrong here
Hiding the SSID removes the network name from beacon frames only; the SSID still appears in probe requests and association frames, so it is discoverable and adds no encryption or authentication. Disabling broadcast suits reducing casual clutter, not securing a network against determined attackers.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.