PT0-002 Attacks and Exploits Practice Question
You are testing a web application and notice that it uses JSON Web Tokens (JWT) for authentication. You change the algorithm to 'none' and remove the signature, and the token is accepted. Which JWT vulnerability did you exploit?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Algorithm none attack
Alg:none attack exploits weak validation that accepts unsigned tokens.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
KID injection
Why it's wrong here
KID injection targets the 'kid' (key ID) header by changing it to point to an attacker-controlled file or value, such as via path traversal or SQL injection, making the server fetch a key the attacker supplies. This still verifies the token's signature with that attacker-known key, so it does not remove or disable signature validation. The behavior described here—altering the alg header to 'none' to skip verification—is a distinct attack. Thus it is incorrect as the identified attack.
- ✓
Algorithm none attack
Why this is correct
In an algorithm none attack, the attacker modifies the JWT header to set 'alg':'none' and strips the signature segment, causing a vulnerable server to accept the token without cryptographic verification. Many JWT libraries only execute signature verification for asymmetric or HMAC algorithms and skip it entirely when alg is 'none' unless explicitly forbidden. This directly matches the observation of bypassing signature verification, so it is the correct answer.
- ✗
Weak secret brute-force
Why it's wrong here
A weak-secret brute-force attack works against HS256 tokens by capturing a legitimate token and testing many candidate passwords offline to recover the HMAC secret, then forging new tokens. It does not alter the alg header, and it requires the server to verify signatures normally; no signature bypass occurs. Because the observed flaw is a direct manipulation of the algorithm header, this option is incorrect.
- ✗
Token replay
Why it's wrong here
Token replay involves intercepting a valid, signed JWT and resubmitting it to the server to impersonate the user without any header modification. It does not create a forged or unauthorized token, and it cannot explain how an attacker gains signing capabilities or bypasses verification. Since this scenario centers on alg header manipulation, token replay is not the correct answer.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.