hardMultiple Select
FC0-U71 Practice Question: Which THREE of the following are common methods…
Which THREE of the following are common methods for securing a wireless network?
⚠ Common exam trap
Test-takers frequently think WEP is still acceptable for security because it was once a standard, but the exam expects you to know it is deprecated and easily broken, while changing the IP range is a common misconception that offers no real security benefit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing MAC address filtering
MAC address filtering (A) is a common wireless security method because the access point maintains an allow-list of client hardware addresses and drops frames from any NIC whose MAC is not listed, adding a layer of access control. Disabling SSID broadcast (B) is also commonly used, since the AP omits the SSID in its beacon frames, making the network less visible to casual scanners and requiring clients to know the network name. WPA2 encryption (D) is the strongest of the listed options and is a standard method for securing wireless traffic, using AES-CCMP under the 802.11i standard to provide confidentiality and integrity. WEP (C) is not a valid answer because it is a deprecated, easily cracked encryption scheme, and changing the default IP address range (E) is a general network-hardening step that does not secure the wireless medium itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing MAC address filtering
Why this is correct
MAC address filtering configures an access point to accept only listed hardware addresses, restricting which devices associate. It satisfies the wireless-hardening requirement by adding a device-level allow-list, though addresses can be spoofed so it complements rather than replaces encryption.
- ✓
Disabling SSID broadcast
Why this is correct
Disabling SSID broadcast stops the access point advertising its network name in beacon frames, hiding it from casual scanning. This satisfies the wireless-security requirement by reducing discoverability, though determined attackers can still detect the traffic, so it is obscurity rather than true protection.
- ✗
Enabling WEP encryption
Why it's wrong here
WEP is easily cracked.
- ✓
Using WPA2 encryption
Why this is correct
WPA2 encrypts wireless traffic using AES-CCMP, so intercepted frames cannot be read and only clients with the pre-shared key or valid credentials associate. This satisfies the wireless-security requirement by providing genuine confidentiality and access control, unlike filtering or hidden SSIDs.
- ✗
Changing the default IP address range
Why it's wrong here
Altering the DHCP scope's IP range is address management, not a security control; it neither authenticates clients nor encrypts radio traffic, so any attacker still associates and reads frames. It is tempting because obscurity feels protective, and re-addressing is legitimately correct when avoiding subnet conflicts or segmenting address space during network redesign.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.