Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, the tester discovers a JWT token that uses the 'alg:none' header. Which attack does this vulnerability enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signature bypass using alg:none

JWT with 'alg:none' allows an attacker to forge tokens without any signature, bypassing verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Key confusion attack

    Why it's wrong here

    Key confusion attack (also known as algorithm confusion) occurs when an attacker forces the server to verify an RS256-signed token using HMAC-SHA256 with the server's public key as the shared secret. This works because the public key is often publicly available, and the server may not enforce the expected asymmetric algorithm. It is distinct from alg:none because it still requires a signature, whereas alg:none removes signature verification entirely.

  • ✓

    Signature bypass using alg:none

    Why this is correct

    Signature bypass using alg:none exploits a JWT header that sets the algorithm to 'none', which indicates to the parser that the token is unsecured and requires no signature. If the server's library does not explicitly reject 'none' tokens, an attacker can craft a valid-looking token with arbitrary claims simply by setting the header to { 'alg': 'none' } and omitting the signature segment. This effectively bypasses authentication and authorization checks because the token is accepted without any cryptographic proof of origin.

  • ✗

    Algorithm substitution attack

    Why it's wrong here

    Algorithm substitution attack is a broader brute-force or downgrade technique where the attacker changes the algorithm parameter to a weaker or symmetric one (e.g., swapping RS256 to HS256) to forge a valid signature. While 'alg:none' is technically a form of algorithm manipulation, security literature typically distinguishes it as a specific signature bypass, not an algorithm substitution, because substitution still requires signing with a known key or guessed secret. In contrast, alg:none eliminates the need for any key material altogether.

  • ✗

    Timing attack

    Why it's wrong here

    Timing attack is a side-channel technique that measures variations in how long a server takes to process requests, such as during password comparison or HMAC verification. It is unrelated to JWT structure or the alg header; it exploits implementation-specific timing differences to leak secrets like HMAC keys. Since the JWT attack described involves modifying the token's alg field to 'none', timing analysis offers no advantage and does not bypass signature checks.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.