220-1101 exam dumps

220-1101 practice question 327 of 471

A+ Core 1. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1101 Question 327

Single answerSecurity

A small medical office asks a technician to improve the security of its wireless network. Staff members use office-owned laptops to access patient records, and visitors often request Internet access while waiting. The office wants guests to have Internet access without being able to reach internal devices or medical systems, and it wants employees to continue using a secure wireless connection. Which of the following is the BEST solution?

  1. A

    Configure a guest SSID that is isolated from the internal LAN, and keep staff on a separate WPA2/WPA3-protected business SSID

  2. B

    Hide the main SSID and give the wireless password only to staff and guests as needed

  3. C

    Use MAC address filtering on the existing wireless network so only approved devices can connect

  4. D

    Disable DHCP on the wireless router so unauthorized users cannot obtain an IP address

Show answer and explanation

Correct answer: A

Explanation

The best answer is to segment guest wireless access from the internal business network by using a dedicated guest SSID with isolation from the LAN. In real-world environments, this is the most practical way to allow visitor Internet access while protecting sensitive internal systems. For staff devices, using WPA2 or preferably WPA3 on a separate business SSID helps secure authentication and traffic. CompTIA A+ Core 1 security objectives commonly emphasize basic wireless security controls such as WPA2/WPA3, changing default settings, and understanding the purpose of guest networks. Vendor and industry best practices also recommend network segmentation for guests rather than relying on weak measures such as hidden SSIDs, MAC filtering, or disabling DHCP.

  • A. Correct.

    Correct. Creating a separate guest SSID with client isolation or guest network isolation is a standard best practice for wireless security. It allows visitors to access the Internet while preventing access to internal resources such as file shares, printers, and medical systems. Keeping employees on a separate secured SSID protected with WPA2 or WPA3 provides stronger protection for business traffic and aligns with common small-office security design.

  • B. Incorrect.

    Incorrect. Hiding an SSID does not meaningfully secure a wireless network because the SSID can still be discovered through wireless analysis tools. Sharing the same password with both staff and guests also increases risk and does not provide network segmentation. This is a common misconception because hidden SSIDs may appear more secure, but they do not replace proper access control.

  • C. Incorrect.

    Incorrect. MAC filtering provides only weak control because MAC addresses can be spoofed, and it does not solve the requirement to give guests Internet access while blocking internal network access. Even if used, it would be an administrative burden and would not provide proper separation between guest and business traffic.

  • D. Incorrect.

    Incorrect. Disabling DHCP may inconvenience unauthorized users, but it does not prevent access because a user can manually configure network settings. It also does nothing to isolate guests from internal devices. This is a weak deterrent rather than an effective security control.

Timed practice exam

Take a 220-1101 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam