PT0-002 Attacks and Exploits Practice Question
During a web application penetration test, the tester discovers a JWT token in the Authorization header. The token uses the 'none' algorithm. What attack should the tester attempt?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT algorithm confusion attack (alg:none)
If the server accepts the 'none' algorithm, the tester can forge tokens by setting the algorithm to 'none' and removing the signature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
JWT algorithm confusion attack (alg:none)
Why this is correct
In an alg:none attack, the tester modifies the JWT header to set the algorithm to 'none' and removes the signature from the token. If the server-side JWT library is misconfigured to accept the 'none' algorithm or fails to enforce an explicit algorithm allowlist, it will treat the token as valid without verifying any cryptographic signature. This effectively bypasses integrity checks and allows the attacker to forge arbitrary claims, making it a true algorithm confusion vulnerability.
- ✗
JWT timing attack
Why it's wrong here
A JWT timing attack is a side-channel technique that measures response-time differences to infer a secret key or other sensitive data, such as during signature verification. It does not exploit the 'none' algorithm; rather, it requires the server to actually perform cryptographic verification and attempts to extract the secret through timing variations. Since the question involves bypassing signature verification via 'alg:none', a timing attack is not a relevant alternative explanation.
- ✗
JWT kid injection
Why it's wrong here
In a 'kid' injection attack, the attacker manipulates the 'kid' (key ID) header field to point to an attacker-controlled key or a file path (e.g., SQL injection, path traversal), tricking the server into using that key for signature verification. This still requires the server to verify a signature using the substituted key; it does not eliminate the signature requirement. The 'kid' header controls which key is used, not the algorithm, so it cannot directly achieve an 'alg:none' bypass.
- ✗
JWT brute-force of the secret
Why it's wrong here
Brute-forcing the JWT secret is an offline attack where the tester guesses the HMAC secret by trying many candidate values and comparing the resulting signatures, which is only relevant when the token is signed with a symmetric algorithm like HS256. If the server accepts 'alg:none', there is no signature to brute-force because the token is accepted without one. Thus, brute-forcing is unnecessary and does not explain the discovery of an unsigned token being accepted.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.