Security Principles Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Principles flashcards as text
What is the primary security purpose of a multisignature wallet?
Answer: Requiring multiple keys to approve a transaction
Multisig requires M-of-N signatures, removing single points of failure for key compromise.
A 51% attack on a Proof-of-Work blockchain allows an attacker to do what?
Answer: Double-spend by reorganizing the chain
Controlling majority hash power lets an attacker rewrite recent blocks and double-spend coins.
Which storage location should NEVER be used for secrets like passwords in a smart contract?
Answer: On-chain contract storage, since it is publicly readable
All on-chain storage is publicly visible even if marked private, so secrets must never be stored there.
What does the principle of least privilege recommend for smart contract roles?
Answer: Grant each account only the minimum permissions it needs
Limiting each role to the minimum required permissions reduces the blast radius of a compromise.
An unprotected delegatecall to an untrusted contract is dangerous because it can do what?
Answer: Execute foreign code in the caller's storage context
delegatecall runs the target's code against the caller's storage, letting malicious code overwrite state.
Why should a withdrawal pattern be preferred over pushing funds to users in a loop?
Answer: It avoids failures and DoS when one recipient reverts
Letting users pull funds prevents one failing transfer from blocking payouts to everyone else.
Hardcoding a privileged owner address with no transfer mechanism creates which risk?
Answer: Permanent loss of control if that key is lost or compromised
Without ownership transfer, a lost or stolen key cannot be replaced, freezing or endangering the contract.