WPA3
The Wi-Fi security certification that replaces pre-shared key authentication with SAE in Personal mode and requires protected management frames.
WPA3 is the Wi-Fi Alliance security certification introduced in 2018 as the successor to WPA2. In WPA3-Personal, pre-shared key authentication is replaced by Simultaneous Authentication of Equals (SAE), a password-based key exchange. SAE is commonly described as resisting offline guessing of the passphrase from a captured handshake, because each guess needs a live exchange with the network, and as giving forward secrecy, so a passphrase learned later does not decrypt traffic recorded earlier. WPA3 also requires protected management frames, and its Enterprise mode, still built on IEEE 802.1X, adds an optional higher-security mode.
Candidates commonly miss that SAE moves the attack rather than removing it. An attacker can still try passphrases one at a time against the live network, so a weak passphrase remains weak. A transition mode that lets WPA2 and WPA3 clients share one network also leaves room to push clients back to WPA2. Open networks are covered by a separate certification, Enhanced Open, which uses Opportunistic Wireless Encryption (OWE) to encrypt traffic without authenticating anyone.
Exam relevance: a scenario is likely to ask what WPA3 improves over WPA2. Candidates are expected to point to SAE and its resistance to offline guessing, forward secrecy and protected management frames, and to avoid the claim that WPA3 makes a weak passphrase safe or that Enhanced Open authenticates users.