Courseiva

SSCP Systems and Application Security Practice Question

A security engineer is reviewing the configuration of a web application that uses JSON Web Tokens (JWT) for session management. The engineer notices that the application accepts tokens signed with the 'none' algorithm. Which of the following is the most critical security risk associated with this configuration?

⚠ Common exam trap

The trap here is focusing on transport or performance issues when the core risk is the loss of integrity and authenticity due to missing signature verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attackers can forge tokens with arbitrary claims, leading to privilege escalation.

Accepting the 'none' algorithm means the application does not verify the token's signature. An attacker can craft a token with any claims and set the algorithm to 'none', bypassing authentication and authorization. This is a critical vulnerability that can lead to full account takeover and privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tokens will be transmitted in plaintext, exposing sensitive information.

    Why it's wrong here

    The 'none' algorithm affects signature verification, not transport security. Tokens are typically transmitted over HTTPS, which encrypts the data in transit. The risk of plaintext exposure is unrelated to the algorithm used for signing; it would require a separate misconfiguration like using HTTP instead of HTTPS.

  • ✗

    Tokens will expire prematurely, causing denial of service for legitimate users.

    Why it's wrong here

    The 'none' algorithm does not affect token expiration. Expiration is controlled by the 'exp' claim in the payload, which is independent of the signing algorithm. Premature expiration would be due to misconfigured expiration times, not the algorithm choice.

  • ✗

    The application will experience performance degradation due to lack of signature verification.

    Why it's wrong here

    Skipping signature verification might slightly reduce CPU usage, not degrade performance. Performance is not the primary concern here; the critical issue is the security bypass that allows token forgery. The scenario focuses on security risk, not performance.

  • ✓

    Attackers can forge tokens with arbitrary claims, leading to privilege escalation.

    Why this is correct

    When the 'none' algorithm is accepted, the token's signature is not verified. An attacker can modify the token's payload, such as changing the user role to admin, and set the algorithm to 'none' to bypass signature validation. This allows forging tokens with arbitrary claims, resulting in unauthorized access and privilege escalation.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.