hardMultiple Choice
PT0-002 Practice Question: A penetration tester is assessing a custom web…
A penetration tester is assessing a custom web application that uses JSON Web Tokens (JWT) for authentication. The tester suspects the token may be using a weak secret. Which tool is best suited to attempt cracking the JWT secret?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hashcat
Hashcat is a powerful password cracking tool that can crack JWT secrets using dictionary or brute-force attacks. John the Ripper is similar but hashcat is generally faster and more GPU-optimized. DirBuster is for directory discovery, sqlmap for SQL injection, and Burp Suite Intruder can be used but is less efficient for offline cracking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hashcat
Why this is correct
Hashcat's mode 16500 is designed specifically for cracking JSON Web Tokens signed with HMAC-SHA (HS256, HS384, HS512). It extracts the header and payload from the token, then performs an offline dictionary or brute-force attack against the signature, comparing the SHA-256 HMAC for each candidate secret. Because hashcat leverages multiple GPUs and optimized kernels, it can test billions of guesses per second, making it the go-to tool for weak JWT secrets.
- ✗
DirBuster
Why it's wrong here
DirBuster is a web application content discovery tool that brute-forces directories and filenames on a target web server, looking for hidden resources such as admin panels or backup files. It operates at the HTTP layer and sends GET requests to paths, so it never inspects or attacks the JWT itself. A JWT crack requires taking the token offline and testing the HMAC signature against a dictionary, which is outside DirBuster's functionality.
- ✗
Burp Suite Intruder
Why it's wrong here
Burp Suite Intruder can be used to send a JWT to a server with different candidate secrets in place of the signature, but each attempt requires a full HTTP request and incurs network latency and server processing. This online approach is inherently slower and more detectable than offline cracking, and Burp's threading model cannot match the GPU-accelerated throughput of hashcat. While Intruder might work for a very small secrets list, it is inefficient for realistic password cracking of HMAC keys.
- ✗
sqlmap
Why it's wrong here
sqlmap is a specialized tool for automating the detection and exploitation of SQL injection vulnerabilities, allowing a tester to extract database contents, enumerate database management systems, and even read files on the host. It does not perform any JWT parsing or HMAC computation. Since SQL injection and JWT secret cracking are entirely different attack surfaces, sqlmap has no role in recovering the symmetric signing key from a captured token.
Go deeper
Related to this question
Learn chapter
OAuth 2.0 and SSO Attacks
Key term
Hashcat
Hashcat is a powerful password recovery tool that uses various attack methods to crack password hashes, widely used by security professionals and penetration testers.
Key term
John the Ripper
John the Ripper is a free and open-source password cracking tool used by security professionals to test password strength and by attackers to guess credentials.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.