Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester attempts to modify the 'alg' header to 'none' and sends the token. The server accepts the forged token. Which vulnerability is being exploited?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

alg:none attack

The 'alg:none' attack exploits JWT libraries that accept tokens without verifying signatures. This allows an attacker to forge tokens. Weak secret brute-force would crack the signing key; kid injection manipulates the key ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kid injection

    Why it's wrong here

    The 'kid' (key ID) header parameter is used by the server to select which key to use for verifying a JWT signature. A kid injection attack attempts to manipulate this identifier via path traversal or SQL injection to point to an attacker-controlled key or file, but it does not disable signature validation—it merely changes which key is trusted. Since the question specifically involves setting alg to none (which skips verification entirely), kid injection is a distinct attack that does not align with the observed behavior.

  • ✓

    alg:none attack

    Why this is correct

    By changing the JWT header's alg parameter to 'none' (or variants like 'None' or 'NONE'), the tester instructs the server that no signing algorithm is used. If the server's token-handling logic does not strictly enforce an allowlisted set of algorithms, it may accept the token with an empty signature, effectively bypassing signature verification. This is the classic JWT 'alg none' attack, which directly manipulates the algorithm field rather than the key or secret.

  • ✗

    Algorithm confusion

    Why it's wrong here

    Algorithm confusion (also known as key confusion) attacks exploit a server that accepts both HMAC and RSA as valid algorithms. The attacker changes the header from RS256 (asymmetric) to HS256 (symmetric) and re-signs the token using the RSA public key as the HMAC secret, which the server then verifies against the same public key. This attack does not set alg to none; it changes the algorithm type while still requiring a valid signature under that changed algorithm, so it is a different failure mode from the 'alg none' bypass.

  • ✗

    Weak signing secret

    Why it's wrong here

    A weak signing secret refers to a scenario where the HMAC secret (e.g., for HS256) is short, predictable, or otherwise vulnerable to offline brute-force attacks. An attacker would first capture a valid token, then crack the secret offline, and finally forge new tokens with arbitrary claims. This process does not involve modifying the JWT header (as seen with alg to none); it relies on guessing the cryptographic key material, making it incorrect for this question about header manipulation.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.