PT0-002 Attacks and Exploits Practice Question
During a penetration test, the tester discovers a JWT token that uses the 'alg:none' header. Which attack does this vulnerability enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signature bypass using alg:none
JWT with 'alg:none' allows an attacker to forge tokens without any signature, bypassing verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Key confusion attack
Why it's wrong here
Key confusion attack (also known as algorithm confusion) occurs when an attacker forces the server to verify an RS256-signed token using HMAC-SHA256 with the server's public key as the shared secret. This works because the public key is often publicly available, and the server may not enforce the expected asymmetric algorithm. It is distinct from alg:none because it still requires a signature, whereas alg:none removes signature verification entirely.
- ✓
Signature bypass using alg:none
Why this is correct
Signature bypass using alg:none exploits a JWT header that sets the algorithm to 'none', which indicates to the parser that the token is unsecured and requires no signature. If the server's library does not explicitly reject 'none' tokens, an attacker can craft a valid-looking token with arbitrary claims simply by setting the header to { 'alg': 'none' } and omitting the signature segment. This effectively bypasses authentication and authorization checks because the token is accepted without any cryptographic proof of origin.
- ✗
Algorithm substitution attack
Why it's wrong here
Algorithm substitution attack is a broader brute-force or downgrade technique where the attacker changes the algorithm parameter to a weaker or symmetric one (e.g., swapping RS256 to HS256) to forge a valid signature. While 'alg:none' is technically a form of algorithm manipulation, security literature typically distinguishes it as a specific signature bypass, not an algorithm substitution, because substitution still requires signing with a known key or guessed secret. In contrast, alg:none eliminates the need for any key material altogether.
- ✗
Timing attack
Why it's wrong here
Timing attack is a side-channel technique that measures variations in how long a server takes to process requests, such as during password comparison or HMAC verification. It is unrelated to JWT structure or the alg header; it exploits implementation-specific timing differences to leak secrets like HMAC keys. Since the JWT attack described involves modifying the token's alg field to 'none', timing analysis offers no advantage and does not bypass signature checks.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.