PEN-200 Web Application Attacks Practice Question
A web application uses JSON Web Tokens for authentication. You capture a token whose header is `{"alg":"HS256","typ":"JWT"}` and payload is `{"user":"guest","role":"user"}`. The server verifies the signature with a symmetric secret. Which attack is most likely to let you forge a token with `"role":"admin"` if the application is misconfigured?
⚠ Common exam trap
The trap here is jumping to `alg:none` or algorithm confusion, when the scenario specifies symmetric verification, pointing instead to secret cracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Crack the HS256 secret offline with a wordlist using a tool like hashcat or john, then re-sign a modified payload.
When HS256 is enforced but the secret is weak, the practical attack is an offline dictionary or brute-force attack against the HMAC using a captured token. Recovering the secret allows the attacker to mint arbitrary tokens, including one with elevated privileges. Algorithm-confusion and `alg:none` attacks require different misconfigurations that are not present in this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Crack the HS256 secret offline with a wordlist using a tool like hashcat or john, then re-sign a modified payload.
Why this is correct
HS256 uses a shared secret, and if the application chose a weak or default secret, an attacker who possesses a valid token can perform an offline dictionary attack against the HMAC. Once the secret is recovered, the attacker can sign any payload, including one with `"role":"admin"`. This is the most realistic path when signature verification is enforced but the key is guessable.
- ✗
Replay the captured token after changing only the payload `role` field to `admin`, keeping the original signature.
Why it's wrong here
Modifying the payload invalidates the HMAC signature, so the server rejects the token. The whole point of the signature is to detect tampering with the header or payload. This option tests whether the candidate understands that JWT payloads are integrity-protected and cannot be edited without re-signing, which requires the secret.
- ✗
Switch the header `alg` to `RS256` and sign the token with the server's public key as an HMAC secret.
Why it's wrong here
The RS256-to-HS256 confusion attack requires the server to accept both algorithms and to use the public key as an HMAC secret, which is a specific misconfiguration not stated here. The scenario says the server uses a symmetric secret, so there is no public key to abuse. This technique is powerful but inapplicable without the asymmetric setup, making it a knowledgeable-sounding but wrong choice.
- ✗
Change the header `alg` to `none` and remove the signature segment, then submit the token.
Why it's wrong here
The `alg:none` attack only works if the server explicitly accepts unsigned tokens, which most modern libraries reject by default. Since the scenario says the server verifies with a symmetric secret, the library likely enforces a signing algorithm and will reject an unsigned token. This is a well-known but frequently patched misconfiguration, making it a plausible-sounding distractor rather than the most likely path.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.