Courseiva
Web App API Attacks →hardMultiple Choice

GCIH Web App API Attacks Practice Question

When analyzing a JSON Web Token (JWT) for potential security weaknesses in an API, which scenario indicates a 'None' algorithm attack is possible?

⚠ Common exam trap

Candidates frequently look for weak secrets or expired tokens, overlooking the explicit algorithmic header directive that allows the server to bypass signature verification entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The header contains 'alg': 'none'

A 'None' algorithm attack occurs when the JWT header specifies 'alg': 'none'. If the API backend fails to strictly validate the algorithm field and accepts this header, it treats the token as unsigned. An attacker can then modify the payload (e.g., changing 'user_id' to 'admin') and submit the token without a valid cryptographic signature, effectively bypassing authentication controls because the backend skips signature verification for 'none' algorithms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The token expires in less than 60 seconds

    Why it's wrong here

    Token expiration is a standard security control to limit the window of opportunity for intercepted tokens. It is unrelated to the algorithm field validation. A short expiration does not prevent an attacker from modifying the header to 'none' if the backend fails to validate signatures.

  • ✓

    The header contains 'alg': 'none'

    Why this is correct

    If the 'alg' header is set to 'none', the token is effectively unsigned. If the API implementation is vulnerable, it will trust the payload without requiring a cryptographic signature, allowing attackers to forge arbitrary tokens by modifying the payload content to elevate privileges or impersonate other users.

  • ✗

    The token uses RS256 instead of HS256

    Why it's wrong here

    RS256 is an asymmetric algorithm and is generally considered more secure than symmetric HS256. Using RS256 does not inherently indicate a vulnerability. The vulnerability lies in the improper handling of the algorithm header, regardless of whether asymmetric or symmetric keys are used for signing.

  • ✗

    The secret key is stored in an environment variable

    Why it's wrong here

    Storing secret keys in environment variables is a standard security practice, provided those variables are protected. This does not relate to the JWT 'alg' field vulnerability, which is an implementation flaw in how the API processes the incoming token's signature requirements and the algorithm specified.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.