N10-009 Network Security Practice Question
A small business uses a wireless network for employees and guests. The owner wants to ensure that guest devices cannot access internal resources such as file servers and printers. Which network security technique should be implemented?
⚠ Common exam trap
Many candidates confuse encryption (WPA2) with network segmentation, assuming that securing the wireless link inherently protects internal resources, when in fact encryption only protects data in transit and does not control east-west traffic between devices on the same SSID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VLAN segmentation with separate SSID for guests
VLAN segmentation with a separate SSID for guests is the correct approach because it creates a logical network boundary that isolates guest traffic from internal resources. By assigning the guest SSID to a distinct VLAN, the network can enforce access control lists (ACLs) at the Layer 3 switch or firewall, preventing guest devices from reaching file servers, printers, or other internal subnets while still allowing internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VLAN segmentation with separate SSID for guests
Why this is correct
Implementing VLAN segmentation with a dedicated SSID for guests effectively isolates guest traffic from the internal employee network at Layer 2. This separation, often combined with firewall rules or Access Control Lists (ACLs) on the router or Layer 3 switch, prevents guest devices from accessing sensitive internal resources while still providing them internet connectivity. This robust security measure ensures that potential compromises on guest devices do not impact the business's operational network.
- ✗
MAC address filtering
Why it's wrong here
MAC address filtering attempts to control network access by allowing only devices with specific hardware addresses to connect to the wireless network. However, MAC addresses can be easily spoofed, making this a weak security control. Crucially, it offers no capability to segment different types of traffic or restrict access to internal resources for connected devices, meaning an authorized guest device could still access internal employee subnets.
When this WOULD be correct
An exam question might ask: 'A company wants to prevent unauthorized devices from connecting to its Wi-Fi network by allowing only pre-approved devices. Which technique should be used?' In that context, MAC address filtering would be correct.
- ✗
WPA2 encryption
Why it's wrong here
WPA2 encryption primarily secures the confidentiality and integrity of data transmitted wirelessly between a client and an access point, preventing unauthorized eavesdropping. However, it does not provide any mechanism for segmenting network traffic or enforcing access policies between different user groups once they are authenticated onto the same network. All authenticated users, whether employees or guests, would still reside on the same logical network segment.
When this WOULD be correct
A question asking which security method prevents unauthorized wireless access to the network, with no mention of internal resource isolation, would make WPA2 encryption the correct answer.
- ✗
Disabling SSID broadcast
Why it's wrong here
Disabling SSID broadcast, while preventing casual discovery by untrained users, is a negligible security measure against determined attackers. Tools readily available can still detect hidden SSIDs, rendering this technique ineffective for true network security or traffic segmentation. It offers no mechanism to separate guest traffic from employee traffic or protect internal resources once a device successfully connects.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓VLAN segmentation with separate SSID for guestsCorrect answer▾
Why this is correct
Implementing VLAN segmentation with a dedicated SSID for guests effectively isolates guest traffic from the internal employee network at Layer 2. This separation, often combined with firewall rules or Access Control Lists (ACLs) on the router or Layer 3 switch, prevents guest devices from accessing sensitive internal resources while still providing them internet connectivity. This robust security measure ensures that potential compromises on guest devices do not impact the business's operational network.
✗MAC address filteringWrong answer — click to see why▾
Why this is wrong here
MAC address filtering controls which devices can connect based on hardware addresses, but it does not prevent guest devices from accessing internal resources once connected; it also fails to isolate traffic between guest and internal networks.
★ When this WOULD be the correct answer
An exam question might ask: 'A company wants to prevent unauthorized devices from connecting to its Wi-Fi network by allowing only pre-approved devices. Which technique should be used?' In that context, MAC address filtering would be correct.
Why candidates choose this
Candidates may think MAC filtering provides strong access control, but they overlook that it does not segment network traffic and is easily bypassed by spoofing MAC addresses.
✗WPA2 encryptionWrong answer — click to see why▾
Why this is wrong here
WPA2 encryption secures wireless communication but does not prevent guest devices from accessing internal resources; it only protects data in transit.
★ When this WOULD be the correct answer
A question asking which security method prevents unauthorized wireless access to the network, with no mention of internal resource isolation, would make WPA2 encryption the correct answer.
Why candidates choose this
Candidates may confuse encryption with access control, thinking that encrypting the network also blocks internal resource access.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Network Device Hardening
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This N10-009 question is part of Courseiva's 464-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.