220-1102 exam dumps

220-1102 practice question 394 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 394

Single answerWi-Fi Protected Access 2 (WPA2)

A small medical office uses a wireless router configured for WPA2-Personal. Staff members connect company-owned laptops and tablets with a shared passphrase. A recently terminated employee knew the Wi-Fi password, and management wants to prevent that person from reconnecting without replacing all of the wireless hardware. Which action should the technician take FIRST to secure the wireless network while keeping the environment practical for a small office?

  1. A

    Change the WPA2 pre-shared key on the wireless router and reconnect authorized devices with the new passphrase

  2. B

    Disable SSID broadcasting so the former employee can no longer detect the wireless network

  3. C

    Enable MAC address filtering and leave the current WPA2 passphrase unchanged

  4. D

    Downgrade to WEP temporarily because it is easier to reconfigure on older devices

Show answer and explanation

Correct answer: A

Explanation

WPA2-Personal uses a shared pre-shared key, so anyone who knows that key can authenticate until it is changed. In a small office without an enterprise authentication server, rotating the WPA2 passphrase is the correct first response when a user with prior knowledge of the key should no longer have access. Measures such as hiding the SSID or relying on MAC filtering are not considered strong security controls and should not replace proper credential rotation. Best practices from Wi-Fi security guidance and vendor documentation consistently recommend using WPA2 or stronger security and changing shared credentials when access must be revoked. In larger organizations, WPA2-Enterprise with individual user authentication is preferred because it allows disabling one user's account without changing every device's Wi-Fi password.

  • A. Correct.

    Correct. In a WPA2-Personal environment, all users share the same pre-shared key (PSK). If a former employee knows that passphrase, the most effective immediate step is to change the PSK on the access point/router and then update authorized devices. This directly revokes access for anyone who only had the old shared secret.

  • B. Incorrect.

    Incorrect. Disabling SSID broadcast does not provide meaningful security. The network can still be discovered through wireless scanning and normal client activity. It may reduce casual visibility, but it does not prevent someone who already knows the network details and passphrase from attempting to connect.

  • C. Incorrect.

    Incorrect. MAC address filtering is weak as a primary control because MAC addresses can often be observed and spoofed. It may add administrative overhead, but it does not adequately address the core problem that the former employee knows the valid WPA2-Personal passphrase.

  • D. Incorrect.

    Incorrect. WEP is obsolete and insecure due to well-known vulnerabilities. Downgrading from WPA2 to WEP would significantly reduce security and is not an acceptable remediation. Older device compatibility is not a valid reason to weaken wireless security in this scenario.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam