Network & Node Security Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network & Node Security flashcards as text
A validator node's signing keys are stored on the same internet-facing server that runs the public RPC. What is the safer design?
Answer: Use a separate hardened remote signer or HSM
Isolating signing keys in a remote signer or HSM limits exposure if the public-facing node is compromised.
What is a key risk of running a validator without slashing protection (anti-double-sign) database?
Answer: Accidental double-signing leading to slashed stake
Without anti-slash tracking, a restarted or duplicated validator may sign conflicting blocks and be penalized.
Which is the best practice for a validator's high-availability setup?
Answer: Active-passive failover with strict double-sign prevention
Active-passive with double-sign protection avoids the slashing risk of two live signers.
A node operator notices abnormal CPU and bandwidth from a single peer flooding invalid transactions. What is this?
Answer: A denial-of-service / resource-exhaustion attack
Flooding invalid data to exhaust CPU/bandwidth is a classic DoS technique against nodes.
Which mitigation directly addresses transaction-flood DoS on a node?
Answer: Peer rate-limiting, scoring, and banning misbehaving peers
Rate-limiting and reputation scoring let a node throttle or ban peers sending abusive traffic.
Why should node operators monitor peer count and chain head height continuously?
Answer: To detect eclipse, partition, or stalled-sync conditions early
Sudden drops in peers or a frozen chain head can indicate isolation or a network attack.
What is the security benefit of pinning trusted bootstrap nodes during initial sync?
Answer: Reduces risk of connecting to malicious peers feeding a fake chain
Trusted bootstrap peers help ensure the node joins the honest network rather than an attacker-controlled view.