WPA3 makes Protected Management Frames mandatory, whereas WPA2 left PMF optional. PMF cryptographically protects management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks. This mandatory enforcement is a specific WPA3 security improvement over WPA2 that the stem asks you to identify.
Why this answer
Option B is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protect management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks that were possible under WPA2 where PMF was optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security suite aligned with CNSA guidance, using stronger cryptographic algorithms (GCMP-256, HMAC-SHA-384, ECDHE with a 384-bit curve) that WPA2-Enterprise did not provide. Option D is correct because WPA3 replaces the WPA2 Pre-Shared Key handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that provides forward secrecy and resists offline dictionary attacks against captured handshakes.
Option A is incorrect because WPA3 does not support backward compatibility with WEP, a deprecated and broken encryption protocol; WPA3 requires modern ciphers such as CCMP-128 or GCMP-256. Option E is incorrect because TKIP is a legacy, deprecated encryption protocol from WPA/WPA2 and is not used by WPA3, which relies on AES-based CCMP and GCMP instead.