A rogue access point (AP) can be configured to mimic the legitimate network's SSID but broadcast a weaker security protocol like WPA2. Many WPA3-capable clients are configured to prefer WPA3 but will fall back to WPA2 if WPA3 is unavailable or if a stronger WPA2 signal appears more legitimate. By deauthenticating the client from the real WPA3 AP, the rogue WPA2 AP can entice the client to connect, effectively downgrading its security and allowing for WPA2-specific attacks.
Why this answer
WPA3 clients are designed to fall back to WPA2 when the access point only supports WPA2. By setting up a rogue AP with the same SSID but configured for WPA2, the client will attempt to connect using WPA2, allowing you to capture the 4-way handshake and potentially recover the PSK if the same password is used for both security modes.
Exam trap
EC-Council often tests the misconception that deauthentication alone can force a protocol downgrade, but in WPA3, deauthentication only triggers a reconnection using the same security protocol unless the AP changes its capabilities.
How to eliminate wrong answers
Option A is wrong because a PMKID attack targets WPA2/3 access points that expose the PMKID in the first EAPOL frame, but it does not downgrade a WPA3 client; it is used to recover the PSK without a full handshake, not to capture a handshake from a downgraded client. Option B is wrong because WPS PIN brute-force attacks target WPS-enabled access points, not clients, and WPA3-Personal does not use WPS; this attack is irrelevant for downgrading a WPA3 client. Option C is wrong because sending deauthentication packets to a WPA3 client will only cause it to reconnect using WPA3 (if the AP supports it), not downgrade to WPA2; the client will re-authenticate with its current security protocol, not fall back automatically.