Courseiva
hardMultiple Select

FC0-U71 Practice Question: Which THREE of the following are common methods…

Which THREE of the following are common methods for securing a wireless network?

⚠ Common exam trap

Test-takers frequently think WEP is still acceptable for security because it was once a standard, but the exam expects you to know it is deprecated and easily broken, while changing the IP range is a common misconception that offers no real security benefit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing MAC address filtering

MAC address filtering (A) is a common wireless security method because the access point maintains an allow-list of client hardware addresses and drops frames from any NIC whose MAC is not listed, adding a layer of access control. Disabling SSID broadcast (B) is also commonly used, since the AP omits the SSID in its beacon frames, making the network less visible to casual scanners and requiring clients to know the network name. WPA2 encryption (D) is the strongest of the listed options and is a standard method for securing wireless traffic, using AES-CCMP under the 802.11i standard to provide confidentiality and integrity. WEP (C) is not a valid answer because it is a deprecated, easily cracked encryption scheme, and changing the default IP address range (E) is a general network-hardening step that does not secure the wireless medium itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing MAC address filtering

    Why this is correct

    MAC address filtering configures an access point to accept only listed hardware addresses, restricting which devices associate. It satisfies the wireless-hardening requirement by adding a device-level allow-list, though addresses can be spoofed so it complements rather than replaces encryption.

  • ✓

    Disabling SSID broadcast

    Why this is correct

    Disabling SSID broadcast stops the access point advertising its network name in beacon frames, hiding it from casual scanning. This satisfies the wireless-security requirement by reducing discoverability, though determined attackers can still detect the traffic, so it is obscurity rather than true protection.

  • ✗

    Enabling WEP encryption

    Why it's wrong here

    WEP is easily cracked.

  • ✓

    Using WPA2 encryption

    Why this is correct

    WPA2 encrypts wireless traffic using AES-CCMP, so intercepted frames cannot be read and only clients with the pre-shared key or valid credentials associate. This satisfies the wireless-security requirement by providing genuine confidentiality and access control, unlike filtering or hidden SSIDs.

  • ✗

    Changing the default IP address range

    Why it's wrong here

    Altering the DHCP scope's IP range is address management, not a security control; it neither authenticates clients nor encrypts radio traffic, so any attacker still associates and reads frames. It is tempting because obscurity feels protective, and re-addressing is legitimately correct when avoiding subnet conflicts or segmenting address space during network redesign.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.