Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester intercepts a JWT and changes the algorithm header to 'none' with an empty signature. Which attack is being attempted?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JWT alg:none attack

Setting algorithm to 'none' is a JWT algorithm confusion attack where the server accepts unsigned tokens.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is a server-side attack that injects malicious SQL payloads into database queries to manipulate data retrieval or bypass authentication. It has no connection to JSON Web Token handling or signature verification. The presence of JWT manipulation indicates a flaw in the token parsing and validation logic, not in database query construction, making SQLi an incorrect explanation.

  • ✗

    SSRF

    Why it's wrong here

    SSRF (Server-Side Request Forgery) is a vulnerability where an attacker tricks the server into making unintended HTTP requests to internal or external resources. This attack focuses on server-side URL fetching and network access, not on token integrity or cryptographic verification. A JWT alg:none attack instead involves altering the token header client-side to disable signature checking, which is a completely distinct attack vector and impact.

  • ✓

    JWT alg:none attack

    Why this is correct

    A JWT alg:none attack works by changing the token's `alg` header field to `none`, signaling that the token is unsecured. Vulnerable JWT libraries that accept this value will skip signature verification entirely, allowing an attacker to forge tokens with arbitrary claims, such as elevating privileges, without knowing the secret key. This directly exploits the server's failure to enforce strict algorithm allowlists.

  • ✗

    IDOR

    Why it's wrong here

    IDOR (Insecure Direct Object Reference) is an access control flaw where an application exposes internal object identifiers, such as record IDs, and fails to verify the user's authorization to access the referenced object. It does not involve manipulating token metadata or cryptographic signatures. The alg:none attack, by contrast, is a token forgery technique that bypasses authentication entirely by tricking the JWT validator, not by guessing or modifying object references.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.