Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, the tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester modifies the JWT header to set the algorithm to 'none' and removes the signature. The server accepts the token. What type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JWT algorithm confusion (alg:none)

Setting the JWT algorithm to 'none' exploits a misconfiguration where the server does not enforce signature verification, leading to JWT algorithm confusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    JWT algorithm confusion (alg:none)

    Why this is correct

    This is a JWT algorithm confusion attack where the attacker modifies the JWT header to set the `alg` field to `none`, removing the signature entirely. If the server's JWT library naively trusts the header and skips signature verification for `alg:none`, the attacker can forge arbitrary tokens and impersonate any user. Modern libraries should enforce an explicit algorithm allowlist, but misconfigured legacy systems remain vulnerable.

  • ✗

    JWT injection

    Why it's wrong here

    JWT injection generally refers to injecting malicious content into the token's payload, such as adding extra claims (e.g., `"role":"admin"`) or embedding payloads that trigger SQL injection or XSS when consumed by the application. That is a payload manipulation or deserialization issue, not an algorithm-level bypass. Here the core flaw is the server accepting `alg:none`, which eliminates signature validation entirely rather than relying on injected data.

  • ✗

    JWT session stealing

    Why it's wrong here

    JWT session stealing involves the attacker obtaining a valid, already-issued token from another user, such as via network sniffing, HTTP header leakage, logging, or browser storage theft, then replaying it to hijack that session. It doesn't require altering the token's header or algorithm. In this test, the tester actively crafts a malicious token with `alg:none`, which is fundamentally different from passively or actively stealing a legitimate session token.

  • ✗

    JWT secret brute-force

    Why it's wrong here

    JWT secret brute-force is an offline or online attack where the attacker attempts to guess the symmetric HMAC secret used to sign tokens, often using dictionary or wordlist attacks on captured legitimate tokens. However, when `alg:none` is accepted, no signature is present at all, so there is no secret to guess. The vulnerability is that the server skips verification, not that the cryptographic secret is weak or compromised.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.