PT0-002 Attacks and Exploits Practice Question
During a web application test, the tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester modifies the JWT header to set the algorithm to 'none' and removes the signature. The server accepts the token. What type of attack is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT algorithm confusion (alg:none)
Setting the JWT algorithm to 'none' exploits a misconfiguration where the server does not enforce signature verification, leading to JWT algorithm confusion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
JWT algorithm confusion (alg:none)
Why this is correct
This is a JWT algorithm confusion attack where the attacker modifies the JWT header to set the `alg` field to `none`, removing the signature entirely. If the server's JWT library naively trusts the header and skips signature verification for `alg:none`, the attacker can forge arbitrary tokens and impersonate any user. Modern libraries should enforce an explicit algorithm allowlist, but misconfigured legacy systems remain vulnerable.
- ✗
JWT injection
Why it's wrong here
JWT injection generally refers to injecting malicious content into the token's payload, such as adding extra claims (e.g., `"role":"admin"`) or embedding payloads that trigger SQL injection or XSS when consumed by the application. That is a payload manipulation or deserialization issue, not an algorithm-level bypass. Here the core flaw is the server accepting `alg:none`, which eliminates signature validation entirely rather than relying on injected data.
- ✗
JWT session stealing
Why it's wrong here
JWT session stealing involves the attacker obtaining a valid, already-issued token from another user, such as via network sniffing, HTTP header leakage, logging, or browser storage theft, then replaying it to hijack that session. It doesn't require altering the token's header or algorithm. In this test, the tester actively crafts a malicious token with `alg:none`, which is fundamentally different from passively or actively stealing a legitimate session token.
- ✗
JWT secret brute-force
Why it's wrong here
JWT secret brute-force is an offline or online attack where the attacker attempts to guess the symmetric HMAC secret used to sign tokens, often using dictionary or wordlist attacks on captured legitimate tokens. However, when `alg:none` is accepted, no signature is present at all, so there is no secret to guess. The vulnerability is that the server skips verification, not that the cryptographic secret is weak or compromised.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.