C4 Risk Management & Mitigation 3 — Questions and Answers
Question 1: What is 'slippage' in cryptocurrency trading and which risk category does it fall under?
- A protocol bug — operational risk
- The difference between expected and executed trade price — market risk (Correct answer)
- An exchange withdrawal delay — counterparty risk
- An incorrect wallet address — user error risk
Correct answer: The difference between expected and executed trade price — market risk
Slippage is the difference between the anticipated price and the actual execution price, caused by low liquidity or rapid price movement, and is classified as market risk.
Question 2: Which risk mitigation strategy involves using futures or options contracts to offset potential losses in a cryptocurrency portfolio?
- Staking
- Yield farming
- Hedging (Correct answer)
- Arbitrage
Correct answer: Hedging
Hedging uses derivative instruments such as futures or options to create offsetting positions that limit downside exposure in a portfolio.
Question 3: An organization holds Bitcoin and wants to reduce exposure to BTC price volatility without selling. Which approach best achieves this?
- Buying more BTC on margin
- Shorting BTC futures (Correct answer)
- Moving BTC to a hardware wallet
- Staking BTC in a liquidity pool
Correct answer: Shorting BTC futures
Shorting BTC futures creates a position that profits when BTC falls, offsetting losses in the spot holding without requiring a sale.
Question 4: Which term describes the risk that a counterparty in a cryptocurrency transaction will fail to fulfill their contractual obligation?
- Systemic risk
- Counterparty risk (Correct answer)
- Regulatory risk
- Concentration risk
Correct answer: Counterparty risk
Counterparty risk is the danger that the other party in a trade, loan, or contract defaults before the transaction is settled.
Question 5: Why is key ceremony documentation important in cryptocurrency risk management?
- It records user trading activity for tax purposes
- It provides an auditable record of how cryptographic keys were generated and stored (Correct answer)
- It outlines the marketing strategy for a new token launch
- It describes the network's consensus algorithm
Correct answer: It provides an auditable record of how cryptographic keys were generated and stored
Key ceremony documentation creates a verifiable, tamper-evident record of private key generation, ensuring accountability and enabling audits of custody procedures.
Question 6: A DeFi protocol relies on a single external price feed. What risk does this create?
- Regulatory arbitrage risk
- Oracle manipulation risk (Correct answer)
- Smart contract upgrade risk
- Front-running risk
Correct answer: Oracle manipulation risk
A single-source oracle can be manipulated by an attacker who moves that source's price, feeding incorrect data to the protocol and enabling exploits like flash loan attacks.
Question 7: What does 'threat modeling' involve in the context of a cryptocurrency custody solution?
- Predicting future token prices
- Systematically identifying potential attack vectors and vulnerabilities in the custody system (Correct answer)
- Auditing smart contract code for bugs
- Analyzing regulatory compliance requirements
Correct answer: Systematically identifying potential attack vectors and vulnerabilities in the custody system
Threat modeling maps out all potential adversaries, attack surfaces, and failure modes so that defenses can be prioritized and implemented before incidents occur.
What is 'slippage' in cryptocurrency trading and which risk category does it fall under?