220-1102 exam dumps

220-1102 practice question 535 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 535

Select 22.10 Given a scenario, apply security settings on SOHO wireless and wired networks.

A small medical office uses a SOHO router with built-in Wi-Fi for staff laptops, tablets, and a network printer. Recently, a former employee was seen sitting in the parking lot, and the office manager is concerned that the person may still know the wireless password. The office also wants to prevent visitors from plugging into unused Ethernet wall jacks in the lobby. Which TWO actions should the technician take to improve security while keeping normal office devices working with minimal disruption?

  1. A

    Change the Wi-Fi security to WPA3-Personal and set a new strong passphrase; if some devices do not support WPA3, use WPA2/WPA3 mixed mode temporarily

  2. B

    Disable DHCP on the SOHO router so only users who know the correct IP settings can connect

  3. C

    Disable unused switch ports or wall-jack connections and place guest devices on a separate guest network

  4. D

    Hide the SSID broadcast so former employees cannot detect the wireless network

  5. E

    Enable WEP because it is compatible with older devices and uses encryption

Show answer and explanation

Correct answers: A, C

Explanation

The best answers are to change the wireless security credentials using the strongest supported standard and to secure unused wired access points while isolating guest access. In this scenario, the risk is both wireless credential compromise and unauthorized wired access through public-facing jacks. WPA3-Personal is the preferred SOHO wireless security setting when supported, with WPA2/WPA3 transitional mode being a practical fallback during upgrades. Rotating the passphrase is essential because a former employee may still know the old one. On the wired side, disabling unused switch ports or jack connections helps prevent visitors from joining the internal network. A guest network is also a common SOHO best practice because it segments untrusted devices from business systems. By contrast, disabling DHCP and hiding the SSID are not strong security controls, and WEP is deprecated due to serious vulnerabilities. These recommendations are consistent with general vendor guidance from router manufacturers and wireless security best practices promoted by industry bodies such as the Wi-Fi Alliance and NIST guidance favoring strong encryption and segmentation.

  • A. Correct.

    This is correct. Changing the wireless passphrase is the most direct response when a former employee may know the current credentials. Using WPA3-Personal provides stronger protection than older methods, and WPA2/WPA3 mixed mode is a practical transitional choice in a SOHO environment if some existing devices are not yet WPA3-capable. This aligns with current wireless security best practices: use the strongest supported encryption and rotate compromised credentials.

  • B. Incorrect.

    This is incorrect. Disabling DHCP does not meaningfully secure the network because an attacker can manually configure an IP address if they can associate to the wireless network or connect to the LAN. It also creates unnecessary administrative overhead for staff devices and is not a recommended primary security control for a SOHO network.

  • C. Correct.

    This is correct. Disabling unused wired ports or wall-jack connections reduces the risk of unauthorized physical access from lobby areas. Separating guest devices onto a guest network is also a standard SOHO security measure because it limits guest access to internal office resources such as printers, file shares, and medical workstations. This combination improves both wired and wireless security with minimal disruption to normal users.

  • D. Incorrect.

    This is incorrect. Hiding the SSID is not an effective security control. The network name can still be discovered through wireless scanning and client traffic, and authorized devices may have connectivity issues or increased management complexity. SSID suppression is security through obscurity and should not be relied on to prevent access.

  • E. Incorrect.

    This is incorrect. WEP is obsolete and insecure. It has well-known weaknesses and can be cracked quickly with widely available tools. Choosing WEP for compatibility would significantly reduce security and would not meet modern best-practice standards for protecting business wireless traffic.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam