Courseiva
mediumMultiple Choice

PT0-002 Practice Question: Has a web application that stores session tokens…

An organization has a web application that stores session tokens in a cookie named 'auth_token'. The token is a base64-encoded JSON object containing the username, role, and expiration timestamp. Which attack is most likely to succeed if the encryption is not used?

⚠ Common exam trap

CompTIA often tests the distinction between encoding and encryption, and the trap here is that candidates confuse base64 encoding with actual security, assuming it protects the token's integrity or confidentiality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cookie tampering

The session token is a base64-encoded JSON object without encryption, making it trivially easy to decode, modify (e.g., change the role to 'admin' or extend the expiration timestamp), re-encode, and send back to the server. This is a classic cookie tampering attack, as the server trusts the client-provided data without integrity verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session replay

    Why it's wrong here

    Session replay attacks involve capturing a legitimate session identifier (via packet sniffing, logs, or browser storage) and re-presenting it verbatim to the server to impersonate the victim. The attacker never alters the cookie's contents—no decoding, changing, or re-encoding occurs—so the attack is purely a reuse of a valid token. Because the scenario explicitly describes manipulating the cookie's values to escalate privileges, session replay does not match that action.

  • ✗

    Cross-site request forgery

    Why it's wrong here

    Cross-site request forgery (CSRF) tricks an authenticated user's browser into sending a forged HTTP request to a vulnerable application, often via a malicious link or form, while the user's existing session cookie is automatically attached by the browser. The attacker neither reads nor modifies the session token; instead, they rely on the server's implicit trust in the ambient session. Since cookie tampering requires actively changing the cookie's payload, CSRF is incorrect because it leverages an existing session rather than altering it.

  • ✓

    Cookie tampering

    Why this is correct

    Cookie tampering is the correct classification: the tester captures the session cookie, decodes it (e.g., Base64 or URL-decoded JSON), changes a value such as a role, privilege level, or account identifier, and re-encodes it before sending it back to the server. This attack is successful only when the server fails to encrypt or cryptographically sign the cookie, allowing a client-side alteration to be accepted. The result is privilege escalation through direct manipulation of the session token itself, distinguishing it from attacks that leave the token unchanged.

  • ✗

    Session hijacking

    Why it's wrong here

    Session hijacking occurs when an attacker steals a valid, active session identifier—via network sniffing, cross-site scripting, or session prediction—and uses it to assume the victim's authenticated identity. The stolen token is presented exactly as captured; there is no modification of its internal values or recreation of a privileged cookie. Because the described exploit involves re-encoding a modified cookie to escalate privileges, session hijacking (which revolves around token theft, not alteration) does not fit the scenario.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.