Skip to article
Security+ study guide

CompTIA Security+ PBQ Practice: Secure a Wireless Network

To secure a wireless network in this CompTIA Security+ practice task, separate guest, staff and management access, apply the stated authentication and boundary rules, then test required connections and prohibited paths. Different SSID names alone do not establish isolation. The result must preserve useful staff work and restrict guest and administrative access.

BE The Best Exam Apps team ·
Share

What are the five required results in this case?

The fictional Northbank network needs guest internet access, staff report access and management-workstation access to AP administration. Guests must be refused access to both reports and AP administration. Write those five outcomes before choosing the settings.

Staff use individual authentication in the selected enterprise design. A guest connecting to Wi-Fi is not automatically authorised to use internal reports. An administrator’s management request also has a different target from an ordinary staff report request.

The supplied logs show guests reaching both internal targets through a broad LAN rule. The observed problem is that permitted path. Renaming the guest network would not repair it.

Does a separate SSID prove that guests are isolated?

A separate SSID identifies a wireless network name; the actual forwarding and policy configuration determines which destinations its clients can reach. Check the segment assignment and enforced boundaries, then test them.

Our lab uses a stated default-deny design. Remove the broad guest-to-LAN permit and keep narrow rules for guest web access, staff reports and the management source. The exact configuration screens and evaluation order of a real product need its own documentation.

NIST’s WLAN security guidance provides a general security-management foundation. Its 2012 publication date means it should not be used as a current list of wireless feature support or modern product defaults.

How do authentication and network boundaries work together?

Authentication establishes the accepted identity or credential evidence; boundaries and application permissions restrict the allowed destinations and actions. They solve related parts of the task.

Individual staff authentication supports accountable assignments. It does not eliminate the need for appropriate report permissions. A guest network can offer internet access while preventing an internal path, provided the actual rules enforce that design.

Trace each request from client to its destination using the network controls guide. Keep the AP’s administrative interface separate from the application service you want staff to use.

Which connection tests should I record?

Record all five required outcomes from the intended client segments. Successful guest internet access alone would leave two important prohibited paths untested. Successful management access from a staff laptop would not prove the intended restriction.

Use the permissions table to write the expected result, and the response sheet to record the fresh observed request. For an allowed result, identify the narrow rule and target that permit it. For a refusal, check that the refusal occurred at the expected control rather than through an unrelated broken connection.

Give visitors internet access without internal or management access. Staff need individual authentication and report access; only the management workstation may administer the AP.
Original fictional evidence for this exercise. View the full-size diagram
Build the expected wireless test results

Select the required outcome in this fictional network, after repairing the broad guest rule.

How can I change the case to check my understanding?

Change one legitimate requirement, then revise the relevant path and tests. For example, a guest needs a public training portal but still no internal reports. Add the narrow intended path and verify that the two internal refusals remain intact.

Do not treat a failed TLS identity check as evidence that the segmentation rule is wrong. Use the broken-connection case to separate a boundary failure from a later secure-service failure. An effective repair addresses the failed stage and preserves the protections that are still required.

Frequently asked questions

What are the five required results in this case?
The fictional Northbank network needs guest internet access, staff report access and management-workstation access to AP administration. Guests must be refused access to both reports and AP administration. Write those five outcomes before choosing the settings.
Does a separate SSID prove that guests are isolated?
A separate SSID identifies a wireless network name; the actual forwarding and policy configuration determines which destinations its clients can reach. Check the segment assignment and enforced boundaries, then test them.
How do authentication and network boundaries work together?
Authentication establishes the accepted identity or credential evidence; boundaries and application permissions restrict the allowed destinations and actions. They solve related parts of the task.
Best Exam Apps

Prepare with CompTIA Security+ Practice

Concept lessons, explained practice, a firewall exercise and a daily study route across the five SY0-701 domains.

See the app
Download on the App StoreGet it on Google Play