A: You probably don't want non-employees accessing your corporate network. Keeping them on a separate network while providing Internet access is important.
You can implement a second WiFi network with separate access points (APs), routers, and infrastructure. That solution is reliable but somewhat expensive.
However, many modern APs can expose two or more service set identifier (SSID) strings. You can configure each AP to expose two SSIDs: a guest network that is restricted to communicate only with the Internet, and an employee network that is blocked from communicating with the guest network.
If you use the second solution, you'll need to set up your switches to support the separate guest network, typically as a virtual LAN (VLAN). Virtually all switches support VLAN segmentation, but the configuration semantics will vary from model to model.