Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is assessing a custom web…

A penetration tester is assessing a custom web application that uses JSON Web Tokens (JWT) for authentication. The tester suspects the token may be using a weak secret. Which tool is best suited to attempt cracking the JWT secret?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hashcat

Hashcat is a powerful password cracking tool that can crack JWT secrets using dictionary or brute-force attacks. John the Ripper is similar but hashcat is generally faster and more GPU-optimized. DirBuster is for directory discovery, sqlmap for SQL injection, and Burp Suite Intruder can be used but is less efficient for offline cracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Hashcat

    Why this is correct

    Hashcat's mode 16500 is designed specifically for cracking JSON Web Tokens signed with HMAC-SHA (HS256, HS384, HS512). It extracts the header and payload from the token, then performs an offline dictionary or brute-force attack against the signature, comparing the SHA-256 HMAC for each candidate secret. Because hashcat leverages multiple GPUs and optimized kernels, it can test billions of guesses per second, making it the go-to tool for weak JWT secrets.

  • ✗

    DirBuster

    Why it's wrong here

    DirBuster is a web application content discovery tool that brute-forces directories and filenames on a target web server, looking for hidden resources such as admin panels or backup files. It operates at the HTTP layer and sends GET requests to paths, so it never inspects or attacks the JWT itself. A JWT crack requires taking the token offline and testing the HMAC signature against a dictionary, which is outside DirBuster's functionality.

  • ✗

    Burp Suite Intruder

    Why it's wrong here

    Burp Suite Intruder can be used to send a JWT to a server with different candidate secrets in place of the signature, but each attempt requires a full HTTP request and incurs network latency and server processing. This online approach is inherently slower and more detectable than offline cracking, and Burp's threading model cannot match the GPU-accelerated throughput of hashcat. While Intruder might work for a very small secrets list, it is inefficient for realistic password cracking of HMAC keys.

  • ✗

    sqlmap

    Why it's wrong here

    sqlmap is a specialized tool for automating the detection and exploitation of SQL injection vulnerabilities, allowing a tester to extract database contents, enumerate database management systems, and even read files on the host. It does not perform any JWT parsing or HMAC computation. Since SQL injection and JWT secret cracking are entirely different attack surfaces, sqlmap has no role in recovering the symmetric signing key from a captured token.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.