Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, a tester discovers a JWT token with the following header: {'alg':'HS256','typ':'JWT'}. The token payload contains 'admin':false. The tester attempts to change the algorithm to 'none' and removes the signature. Which vulnerability is being exploited?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JWT algorithm confusion (alg:none)

JWT alg:none attack exploits servers that accept unsigned tokens. Other options are different attack types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    JWT brute-force

    Why it's wrong here

    JWT brute-force is an offline attack that attempts to discover the HMAC secret key by trying many candidate passwords against the token's existing signature, typically using a dictionary or wordlist. While it is a valid attack vector, it focuses on guessing the secret rather than altering the token's algorithm header to eliminate verification. The discovery here is that the server trusts an unsigned token, so brute-force is not the correct characterization.

  • ✓

    JWT algorithm confusion (alg:none)

    Why this is correct

    JWT algorithm confusion (alg:none) occurs when a server accepts a JWT whose header declares the "alg" parameter as "none" (or "None"/"NONE"), which instructs the verifier that the token has no digital signature. An attacker can modify the token's payload, set alg to none, and remove the signature entirely; if the library does not explicitly reject none, the token is trusted as if it were properly signed. This directly bypasses signature verification without the attacker knowing any secret key.

  • ✗

    JWT kid injection

    Why it's wrong here

    JWT kid injection involves manipulating the "kid" (key ID) header, which the server uses to select which secret or public key to use for verification. An attacker may inject path traversal or SQLi payloads through kid to trick the server into using an attacker-controlled key file or database entry, but this does not involve setting alg to none. In this scenario, the discovered behavior is that the verifier simply skips signature checking, which is fundamentally different from manipulating key selection.

  • ✗

    JWT injection

    Why it's wrong here

    "JWT injection" is not a recognized or standard attack name; it is a vague term that could refer to injecting claims into the payload, such as "role" or "admin", but doing so does not defeat signature verification. The actual attack demonstrated is algorithm confusion, specifically forcing the server to accept an unsigned token by changing the alg header. Unlike claim manipulation, this attack requires no secret and exploits a distinct protocol-level flaw.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.