FC0-U71 Security Practice Question
An employee working from a coffee shop connects a laptop to an open wireless network to check webmail. The employee wants to prevent other patrons on that same network from capturing the login credentials in transit. Which technology BEST provides this protection?
⚠ Common exam trap
Many candidates confuse controls that protect data at rest or the physical screen with a control that protects data in transit over an untrusted network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A virtual private network (VPN) tunnel to the company network
On an open wireless network, frames are broadcast over a shared medium where any nearby device can capture them, so confidentiality must come from encryption applied to the traffic itself. A VPN creates an encrypted tunnel from the laptop to a trusted endpoint, hiding credentials and content from local eavesdroppers. Firewalls, screen filters, and disk encryption each defend different assets and none encrypts data in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A virtual private network (VPN) tunnel to the company network
Why this is correct
A VPN encrypts traffic from the laptop to the company gateway, so other users sharing the open wireless link see only ciphertext even if they capture the frames. Because the tunnel is established before the webmail session travels, credentials and content are shielded from local eavesdroppers. This directly addresses the risk of interception on an untrusted network.
- ✗
Full-disk encryption enabled on the laptop drive
Why it's wrong here
Full-disk encryption protects data at rest, meaning it renders the drive unreadable if the laptop is lost or stolen and the attacker lacks the key. While the machine is powered on and the user is logged in, the volume is unlocked and the protection does not extend to network traffic. It therefore cannot stop credential capture on the coffee shop wireless link.
- ✗
A screen privacy filter placed over the laptop display
Why it's wrong here
A privacy filter narrows the viewing angle so people nearby cannot read the screen, which defends against visual eavesdropping, sometimes called shoulder surfing. It has no effect on data traveling across the wireless network, so an attacker capturing packets can still recover the login details. This control protects what is displayed, not what is transmitted.
- ✗
A host-based firewall enabled on the laptop
Why it's wrong here
A host-based firewall filters which inbound and outbound connections the laptop permits, which helps block unwanted access to the machine itself. It does not encrypt the data leaving the laptop, so a nearby attacker monitoring the shared wireless medium can still read the webmail credentials in transit. Filtering traffic and protecting its confidentiality are separate functions.
Visual reference
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.