No, that is not correct. EAPOL frames, including Group Key Handshake,
has to be encrypted when WPA is used and pairwise keys are set. In other
words, EAPOL frames are never encrypted with non-WPA IEEE 802.1X or
during the initial WPA 4-Way Handshake (or IEEE 802.1X/EAP
authentication before this), but they are encrypted during rekeying and
reauthentication (including IEEE 802.1X re-authentication with WPA).

