Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 10)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 46–50

  1. 46expert · hard

    You are testing an API that uses JWTs. You have a valid token with the payload {"user":"alice","role":"user"}. The token is signed with HS256. You suspect the secret is weak. Which approach is most efficient to escalate to admin?

    Select an answer first
  2. 47foundation · easy

    What is the first step an attacker typically takes to manipulate a JWT payload?

    Select an answer first
  3. 48foundation · easy

    What is the purpose of using wordlists during API endpoint enumeration?

    Select an answer first
  4. 49application · medium

    You are assessing an API that uses JWT for authentication. The server uses RS256 for signing. You want to test whether the server is vulnerable to algorithm confusion. What is the key prerequisite for this attack?

    Select an answer first
  5. 50foundation · easy

    Which tool is commonly used to crack weak JWT secrets offline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.