GSEC Web Communication Security Practice Question
A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?
⚠ Common exam trap
The trap here is assuming that "none" is a valid secure algorithm or that it provides some form of protection, when in reality it means the token is completely unsigned.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The token is unsigned, allowing an attacker to modify the payload and forge valid tokens.
A JWT with "alg": "none" is unsigned, meaning it has no integrity protection. An attacker can tamper with the payload and, if the server accepts such tokens, forge arbitrary claims. This can lead to authentication bypass or privilege escalation. The correct answer identifies that the token is unsigned and can be modified. The other options mischaracterize the token as encrypted, weakly signed, or solely vulnerable to replay, missing the core issue of missing signature verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The token is unsigned, allowing an attacker to modify the payload and forge valid tokens.
Why this is correct
When the JWT header specifies "alg": "none", it means the token has no signature. An attacker can alter the payload (e.g., change user privileges) and since there is no signature to verify, the server may accept the modified token if it does not properly reject "none" algorithms. This is a critical vulnerability that can lead to authentication bypass and privilege escalation.
- ✗
The token uses a weak signing algorithm that can be brute-forced to recover the secret key.
Why it's wrong here
The "none" algorithm is not a weak signing algorithm; it is the absence of any signature. Brute-forcing is irrelevant because there is no signature to crack. The risk is not about recovering a key but about the lack of integrity protection. Therefore, this option incorrectly describes the nature of the vulnerability.
- ✗
The token is vulnerable to replay attacks because it lacks an expiration claim.
Why it's wrong here
The "alg": "none" header does not inherently relate to expiration claims. While JWTs should include an exp claim to mitigate replay attacks, the absence of a signature is a more severe and immediate risk. The token could have an expiration claim, but without a signature, an attacker could modify it to extend the expiration. Thus, this option does not address the primary risk.
- ✗
The token is encrypted, so the contents cannot be read by an attacker.
Why it's wrong here
The "alg": "none" algorithm indicates that the token is unsecured, not encrypted. In fact, JWTs with "none" have no signature, and their payload is base64url-encoded, which is easily decoded. Encryption would require a different algorithm like RSA or ECDSA for signing, or JWE for encryption. Thus, this option mischaracterizes the token's security properties.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.