Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

You are testing a web application and notice that it uses JSON Web Tokens (JWT) for authentication. You change the algorithm to 'none' and remove the signature, and the token is accepted. Which JWT vulnerability did you exploit?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Algorithm none attack

Alg:none attack exploits weak validation that accepts unsigned tokens.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KID injection

    Why it's wrong here

    KID injection targets the 'kid' (key ID) header by changing it to point to an attacker-controlled file or value, such as via path traversal or SQL injection, making the server fetch a key the attacker supplies. This still verifies the token's signature with that attacker-known key, so it does not remove or disable signature validation. The behavior described here—altering the alg header to 'none' to skip verification—is a distinct attack. Thus it is incorrect as the identified attack.

  • ✓

    Algorithm none attack

    Why this is correct

    In an algorithm none attack, the attacker modifies the JWT header to set 'alg':'none' and strips the signature segment, causing a vulnerable server to accept the token without cryptographic verification. Many JWT libraries only execute signature verification for asymmetric or HMAC algorithms and skip it entirely when alg is 'none' unless explicitly forbidden. This directly matches the observation of bypassing signature verification, so it is the correct answer.

  • ✗

    Weak secret brute-force

    Why it's wrong here

    A weak-secret brute-force attack works against HS256 tokens by capturing a legitimate token and testing many candidate passwords offline to recover the HMAC secret, then forging new tokens. It does not alter the alg header, and it requires the server to verify signatures normally; no signature bypass occurs. Because the observed flaw is a direct manipulation of the algorithm header, this option is incorrect.

  • ✗

    Token replay

    Why it's wrong here

    Token replay involves intercepting a valid, signed JWT and resubmitting it to the server to impersonate the user without any header modification. It does not create a forged or unauthorized token, and it cannot explain how an attacker gains signing capabilities or bypasses verification. Since this scenario centers on alg header manipulation, token replay is not the correct answer.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.