Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

A small office's wireless router still ships with the administrator username and default password printed in its manual. A technician is asked to harden the device before it goes into production. Which action BEST addresses this specific risk?

⚠ Common exam trap

The trap here is assuming that enabling strong wireless encryption also secures the router's management login, when the two are entirely separate layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the default administrative credentials to a unique strong password

Factory-default administrative credentials are documented publicly, so a device left with them can be taken over by anyone who reaches its management interface. Replacing those credentials with unique, strong values eliminates the known login path and hardens the device's configuration. Wireless encryption, SSID hiding, and power protection each address different concerns and do not remove the default-account exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the SSID broadcast so the network name is hidden

    Why it's wrong here

    Hiding the SSID only removes the network name from casual scan results; the network is still discoverable with common wireless analysis tools, and clients still connect. More importantly, hiding the SSID has no effect on the router's management login page, so the default credential exposure described in the scenario remains fully exploitable by an attacker.

  • ✓

    Change the default administrative credentials to a unique strong password

    Why this is correct

    Default credentials are published in manuals and vendor documentation, so anyone with physical or network access to the management interface can authenticate. Replacing the factory username and password with unique, strong values removes that known-entry path and directly closes the risk described. This is the specific remediation for a device that still uses out-of-box login details.

  • ✗

    Enable WPA3 encryption on the wireless network

    Why it's wrong here

    Enabling WPA3 protects the traffic sent over the air between clients and the access point, but it does nothing about the fact that anyone holding the manual can log in to the router's management page. The default credential risk exists on the administrative interface regardless of which wireless encryption standard is selected, so this step leaves the reported exposure untouched.

  • ✗

    Place the router behind a surge protector in the wiring closet

    Why it's wrong here

    A surge protector guards hardware against electrical damage, which is an availability concern, not an access-control concern. It cannot stop someone from opening the router's web interface and typing the documented default username and password. This choice addresses a physical power risk and leaves the authentication weakness completely unmitigated.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.