
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 1)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 1–5
- 1
In a JWT none algorithm attack, what does the attacker set the 'alg' header to?
Select an answer first - 2
What is the primary requirement for cracking a JWT secret offline?
Select an answer first - 3
You are analyzing a JWT captured from an API. The token has the following header: {"alg":"HS256"}. The payload includes "iss":"https://auth.example.com", "exp":1600000000, "sub":"user123". You suspect the token is vulnerable to a weak secret. Which action is most appropriate to confirm this?
Select an answer first - 4
During an API assessment, you notice that the API returns detailed stack traces in error responses. This is an example of which security misconfiguration?
Select an answer first - 5
In a JSON Web Token (JWT), which part is Base64Url-encoded and contains the signing algorithm and token type?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.