mediumMultiple Choice
PT0-002 Practice Question: Has a web application that stores session tokens…
An organization has a web application that stores session tokens in a cookie named 'auth_token'. The token is a base64-encoded JSON object containing the username, role, and expiration timestamp. Which attack is most likely to succeed if the encryption is not used?
⚠ Common exam trap
CompTIA often tests the distinction between encoding and encryption, and the trap here is that candidates confuse base64 encoding with actual security, assuming it protects the token's integrity or confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cookie tampering
The session token is a base64-encoded JSON object without encryption, making it trivially easy to decode, modify (e.g., change the role to 'admin' or extend the expiration timestamp), re-encode, and send back to the server. This is a classic cookie tampering attack, as the server trusts the client-provided data without integrity verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session replay
Why it's wrong here
Session replay attacks involve capturing a legitimate session identifier (via packet sniffing, logs, or browser storage) and re-presenting it verbatim to the server to impersonate the victim. The attacker never alters the cookie's contents—no decoding, changing, or re-encoding occurs—so the attack is purely a reuse of a valid token. Because the scenario explicitly describes manipulating the cookie's values to escalate privileges, session replay does not match that action.
- ✗
Cross-site request forgery
Why it's wrong here
Cross-site request forgery (CSRF) tricks an authenticated user's browser into sending a forged HTTP request to a vulnerable application, often via a malicious link or form, while the user's existing session cookie is automatically attached by the browser. The attacker neither reads nor modifies the session token; instead, they rely on the server's implicit trust in the ambient session. Since cookie tampering requires actively changing the cookie's payload, CSRF is incorrect because it leverages an existing session rather than altering it.
- ✓
Cookie tampering
Why this is correct
Cookie tampering is the correct classification: the tester captures the session cookie, decodes it (e.g., Base64 or URL-decoded JSON), changes a value such as a role, privilege level, or account identifier, and re-encodes it before sending it back to the server. This attack is successful only when the server fails to encrypt or cryptographically sign the cookie, allowing a client-side alteration to be accepted. The result is privilege escalation through direct manipulation of the session token itself, distinguishing it from attacks that leave the token unchanged.
- ✗
Session hijacking
Why it's wrong here
Session hijacking occurs when an attacker steals a valid, active session identifier—via network sniffing, cross-site scripting, or session prediction—and uses it to assume the victim's authenticated identity. The stolen token is presented exactly as captured; there is no modification of its internal values or recreation of a privileged cookie. Because the described exploit involves re-encoding a modified cookie to escalate privileges, session hijacking (which revolves around token theft, not alteration) does not fit the scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.