A+ Lesson

Wireless and Firewall Hardening Settings for A+

Last updated: 6/10/2026

Short answer

A practical rule: choose strong encryption (WPA3 or WPA2 with AES) for primary wireless networks, use a separate guest SSID with client isolation for visitors, avoid using SSID hiding as a security measure, and minimize exposed services by disabling unused firewall ports and avoiding unnecessary port forwarding. When port forwarding is needed, document and apply least-privilege mapping and consider internal service hardening.

Why it appears on the exam

- Given device compatibility constraints, choose the best wireless encryption setting (prefer WPA3 if supported; otherwise WPA2-AES). - Given a network diagram with a forwarded port to an internal server, identify the increased exposure and recommend mitigation. - Recognize correct guest network configuration that isolates guest clients from internal resources.

Key concepts

Concept 1

Required terms

SSID broadcast: The router option to advertise the wireless network name; disabling broadcast hides the SSID but is not a strong security control. WPA2/WPA3: Common wireless encryption standards; prefer the strongest supported (WPA3 > WPA2) that client devices support. port forwarding: Configuration that exposes a specific internal service to the Internet by mapping an external port to an internal IP and port.

Example

Selecting WPA2/WPA3 mixed mode if some clients do not support full WPA3.

Concept 2

How Wireless and Firewall Hardening Settings works

A practical rule: choose strong encryption (WPA3 or WPA2 with AES) for primary wireless networks, use a separate guest SSID with client isolation for visitors, avoid using SSID hiding as a security measure, and minimize exposed services by disabling unused firewall ports and avoiding unnecessary port forwarding. When port forwarding is needed, document and apply least-privilege mapping and consider internal service hardening.

Example

Creating a guest SSID that is isolated from the main LAN and uses a different passphrase.

Concept 3

Common confusion

Hiding an SSID is commonly thought to be protective but can break client behavior and is not a substitute for encryption and strong passphrases. Another confusion is equating guest SSID with no security; guest networks should still use encryption but segregate traffic.

Example

Removing a previously configured port-forward rule for an unused game server.

Concept 4

Core 2 (220-1202) question cues

Given device compatibility constraints, choose the best wireless encryption setting (prefer WPA3 if supported; otherwise WPA2-AES); Given a network diagram with a forwarded port to an internal server, identify the increased exposure and recommend mitigation; Recognize correct guest network configuration that isolates guest clients from internal resources.

Example

Disabling unused inbound ports in the router firewall configuration.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.An A+ support scenario describes this situation: Selecting WPA2/WPA3 mixed mode if some clients do not support full WPA3. Which answer fits best?

Q2.A technician sees this situation: Selecting WPA2/WPA3 mixed mode if some clients do not support full WPA3. Which answer should they choose?

Q3.A user reports this support situation: Removing a previously configured port-forward rule for an unused game server. Which option should the technician choose?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8