WPA3 is the current Wi-Fi security standard and the successor to WPA2. The headline change is how each one protects the password during the handshake, which is exactly where WPA2 is vulnerable.
Last updated July 2026
| Aspect | WPA2 | WPA3 |
|---|---|---|
| Released | 2004 | 2018 |
| Personal handshake | Pre-Shared Key (PSK) with the 4-way handshake | SAE (Simultaneous Authentication of Equals), the Dragonfly handshake |
| Encryption | AES with CCMP | AES with CCMP; a 192-bit GCMP-256 suite in Enterprise |
| Offline password guessing | Vulnerable: capture the handshake and brute force it | Resisted: SAE stops offline dictionary attacks |
| Forward secrecy | No | Yes |
| Known weakness | KRACK attack on the 4-way handshake | Early Dragonblood flaws, since patched |
| Open networks | Traffic is unencrypted | Opportunistic Wireless Encryption (OWE) encrypts open networks |
WPA3 fixes WPA2 where it matters most: the handshake. WPA2 lets an attacker capture the 4-way handshake and grind the password offline, and it fell to the KRACK attack. WPA3 replaces PSK with SAE, which blocks offline guessing and adds forward secrecy. Use WPA3 where supported, with WPA2-AES (never WPA or WEP) as the fallback.
Reading the difference is a start. SecPlus Mastery drills it with over 1,000 practice questions, timed mock exams, and spaced review across all five SY0-701 domains, so it sticks for exam day.
Written to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.