Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?

⚠ Common exam trap

Many candidates confuse the 'none' algorithm vulnerability with algorithm confusion or weak key attacks, when in fact it is a straightforward signature bypass that allows arbitrary token forgery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JWT signature bypass due to 'none' algorithm acceptance, enabling token forgery

Accepting JWTs with the 'none' algorithm means the application does not verify the token's integrity. An attacker can craft a token with any claims and set the algorithm to 'none', and the server will trust it. This is a critical authentication bypass. The immediate impact is that the tester can impersonate any user or escalate privileges by modifying the token payload. Proper validation should reject tokens with 'none' unless explicitly intended and secured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Weak signing key vulnerability, allowing brute-force of the HMAC secret

    Why it's wrong here

    Weak signing keys are a concern when the algorithm is HMAC-based (e.g., HS256) and the secret is guessable. Here, the algorithm is 'none', meaning there is no signature at all. Brute-forcing is irrelevant because there is no key to crack. The vulnerability is the acceptance of unsigned tokens, not a weak key.

  • ✗

    Token replay attack due to lack of expiration validation

    Why it's wrong here

    Token replay attacks occur when an attacker reuses a valid token, often because it lacks an expiration or is not invalidated. While the JWT might also lack expiration, the specific issue described is the 'none' algorithm. Replay is a different class of vulnerability and does not directly result from accepting unsigned tokens. The tester could replay a forged token, but the root cause is the signature bypass.

  • ✓

    JWT signature bypass due to 'none' algorithm acceptance, enabling token forgery

    Why this is correct

    When a JWT is signed with the 'none' algorithm, it has no signature. If the application accepts such tokens, an attacker can modify the payload (e.g., change the username or role) and set the algorithm to 'none', and the token will be considered valid. This allows privilege escalation or impersonation. The immediate impact is that the tester can forge tokens with arbitrary claims, bypassing authentication and authorization.

  • ✗

    Algorithm confusion attack, allowing token forgery with arbitrary claims

    Why it's wrong here

    Algorithm confusion typically involves tricking the server into using a different algorithm, such as switching from RS256 to HS256, by manipulating the 'alg' header. In this scenario, the algorithm is already 'none', which is a separate issue. While both can lead to token forgery, the specific vulnerability here is not algorithm confusion but the acceptance of unsigned tokens.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.