Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is testing a web application…

A penetration tester is testing a web application that uses JSON Web Tokens (JWTs) for authentication. The tester discovers that the server does not verify the JWT signature properly. The tester crafts a JWT with an arbitrary payload and sets the algorithm to 'none'. Which attack does this enable?

⚠ Common exam trap

Many exam-takers confuse JWT algorithm manipulation with injection attacks (SQLi) or server-side request forgery (SSRF), but the core of this question is about signature verification failure leading to authentication bypass.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication bypass

Setting the JWT algorithm to 'none' removes all cryptographic verification. If the server does not validate the signature, it will accept a token with an arbitrary payload, allowing the attacker to impersonate any user without knowing the secret key. This directly results in an authentication bypass, as the server trusts the forged token.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is a database-layer attack that works by injecting SQL syntax into user-controlled input to manipulate queries. The JWT algorithm 'none' flaw has nothing to do with SQL; it exploits the token validation process where an attacker modifies the JWT header to 'alg:none' and removes the signature. No SQL statement is executed or altered because the vulnerability targets the authentication middleware's trust in the token header, not a query builder or database interface.

  • ✗

    Server-side request forgery

    Why it's wrong here

    Server-side request forgery (SSRF) occurs when an attacker causes the web application to make HTTP requests to arbitrary URLs, often hitting internal services or localhost. In contrast, the JWT 'none' attack is performed entirely by crafting a token on the client side and sending it in the request; the server does not initiate any outbound requests as part of the exploit. The weakness is in signature verification logic, not in server-side URL fetching or request routing, so SSRF does not apply here.

  • ✓

    Authentication bypass

    Why this is correct

    Setting the JWT header's algorithm to 'none' and stripping the signature allows the attacker to forge a token with arbitrary claims, such as an administrator username or elevated role. If the server's JWT library accepts unsigned tokens when it should require a signature, the middleware trusts the forged payload and grants access without verifying the token's authenticity. This is a direct authentication bypass because the attacker impersonates any user by simply crafting a valid-looking token, completely circumventing credential validation.

  • ✗

    Cross-site request forgery

    Why it's wrong here

    Cross-site request forgery (CSRF) tricks a victim's browser into sending an unintended, authenticated request to a web application, relying on cookies being sent automatically. The JWT 'none' attack is a direct token-forging technique that does not involve the victim's browser, session, or cookies; the attacker creates the malicious token themselves and submits it. It also does not require the victim to perform any action, so the forced-request delivery mechanism of CSRF is irrelevant to this signature-verification flaw.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.