PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?
⚠ Common exam trap
Many candidates confuse the 'none' algorithm vulnerability with algorithm confusion or weak key attacks, when in fact it is a straightforward signature bypass that allows arbitrary token forgery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT signature bypass due to 'none' algorithm acceptance, enabling token forgery
Accepting JWTs with the 'none' algorithm means the application does not verify the token's integrity. An attacker can craft a token with any claims and set the algorithm to 'none', and the server will trust it. This is a critical authentication bypass. The immediate impact is that the tester can impersonate any user or escalate privileges by modifying the token payload. Proper validation should reject tokens with 'none' unless explicitly intended and secured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Weak signing key vulnerability, allowing brute-force of the HMAC secret
Why it's wrong here
Weak signing keys are a concern when the algorithm is HMAC-based (e.g., HS256) and the secret is guessable. Here, the algorithm is 'none', meaning there is no signature at all. Brute-forcing is irrelevant because there is no key to crack. The vulnerability is the acceptance of unsigned tokens, not a weak key.
- ✗
Token replay attack due to lack of expiration validation
Why it's wrong here
Token replay attacks occur when an attacker reuses a valid token, often because it lacks an expiration or is not invalidated. While the JWT might also lack expiration, the specific issue described is the 'none' algorithm. Replay is a different class of vulnerability and does not directly result from accepting unsigned tokens. The tester could replay a forged token, but the root cause is the signature bypass.
- ✓
JWT signature bypass due to 'none' algorithm acceptance, enabling token forgery
Why this is correct
When a JWT is signed with the 'none' algorithm, it has no signature. If the application accepts such tokens, an attacker can modify the payload (e.g., change the username or role) and set the algorithm to 'none', and the token will be considered valid. This allows privilege escalation or impersonation. The immediate impact is that the tester can forge tokens with arbitrary claims, bypassing authentication and authorization.
- ✗
Algorithm confusion attack, allowing token forgery with arbitrary claims
Why it's wrong here
Algorithm confusion typically involves tricking the server into using a different algorithm, such as switching from RS256 to HS256, by manipulating the 'alg' header. In this scenario, the algorithm is already 'none', which is a separate issue. While both can lead to token forgery, the specific vulnerability here is not algorithm confusion but the acceptance of unsigned tokens.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.