N10-009 exam dumps

N10-009 practice question 274 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 274

Single answer4.3 Given a scenario, apply network security features, defense techniques, and solutions.

A company has deployed a guest Wi-Fi network in the lobby for visitors. The network team discovers that guests can reach an internal file server because the guest SSID is bridged to the same VLAN as several employee workstations. Management wants guests to have internet access only, while preventing access to internal resources with the least disruption to the existing employee network. Which of the following is the BEST solution?

  1. A

    Place the guest SSID on its own VLAN and apply an ACL or firewall policy that denies access to internal subnets while allowing internet access

  2. B

    Enable MAC filtering on the guest wireless network so only approved devices can connect

  3. C

    Disable SSID broadcast for the guest network so unauthorized users cannot discover it

  4. D

    Increase the wireless encryption from WPA2-Personal to WPA3-Personal on the guest SSID

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement network segmentation for the guest wireless network by placing it on a separate VLAN and enforcing access restrictions with an ACL or firewall. In enterprise network design, guest networks are treated as untrusted zones and should be isolated from production resources. This aligns with common security best practices such as segmentation, least privilege, and defense in depth. CompTIA Network+ objectives for network security features and defense techniques emphasize using VLANs, ACLs, and firewalls to limit lateral access and reduce exposure. Vendor design guides from Cisco, Aruba, and similar enterprise networking providers also recommend placing guest SSIDs in dedicated VLANs with policies that allow only required services such as DHCP, DNS, and internet access while blocking private/internal address ranges.

  • A. Correct.

    Correct. Segmenting the guest network into a dedicated VLAN is the standard way to isolate untrusted traffic from corporate devices and servers. Applying an ACL or firewall policy to block RFC1918/internal subnets while permitting DNS, DHCP, and internet-bound traffic enforces the business requirement of internet-only guest access. This is the least disruptive approach because it does not require redesigning the employee network; it isolates the guest network at Layer 2 and controls traffic at Layer 3/4.

  • B. Incorrect.

    Incorrect. MAC filtering provides only weak access control because MAC addresses can be spoofed easily, and it does not solve the core problem of network segmentation. Even if only approved guest devices could connect, those devices would still be on the wrong VLAN and could potentially reach internal resources.

  • C. Incorrect.

    Incorrect. Disabling SSID broadcast does not provide meaningful security or segmentation. Hidden SSIDs can still be discovered through normal wireless traffic analysis, and this change would not prevent connected guest devices from accessing internal systems once associated with the network.

  • D. Incorrect.

    Incorrect. WPA3-Personal improves wireless encryption and protects the confidentiality of the wireless connection better than WPA2-Personal, but it does not separate guest traffic from internal resources by itself. The issue in the scenario is improper network placement and lack of traffic restrictions, not weak encryption.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam