โ† All CBSE Flashcard Decks

Architectural and Design Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Architectural and Design Security flashcards as text
  1. Which layer of the blockchain stack is most directly responsible for preventing Sybil attacks in a public, permissionless network?

    Answer: Consensus mechanism with economic or computational cost

    Proof-of-Work and Proof-of-Stake impose real costs (computation or capital) that make creating vast numbers of fake identities economically infeasible.

  2. A security architect wants to enable contract upgradability while preserving immutability guarantees. Which pattern achieves this?

    Answer: Use a proxy contract that delegates calls to a separate, swappable logic contract

    The proxy-delegate pattern keeps a stable address and storage while allowing the implementation logic contract to be replaced by the owner.

  3. What is the key security difference between an on-chain random number generated from block hash versus a commit-reveal scheme?

    Answer: Block-hash randomness can be manipulated by miners; commit-reveal eliminates that vector

    Miners can selectively discard blocks with unfavorable hashes, biasing block-hash-based randomness, while commit-reveal binds participants before outcomes are known.

  4. In a cross-chain bridge architecture, which attack surface is introduced specifically by the relay/validator set responsible for verifying source-chain events?

    Answer: Collusion or compromise of the bridge validator set to forge transfer proofs

    Bridge validators who attest to cross-chain events can collude or be compromised to mint fraudulent assets on the destination chain without corresponding source deposits.

  5. Which cryptographic primitive allows multiple parties to generate a shared secret without any single party knowing all inputs, critical for distributed key generation in blockchain nodes?

    Answer: Distributed Key Generation (DKG) protocol

    DKG protocols allow a group of participants to collectively generate a public/private key pair where no single party ever holds the complete private key.

  6. A smart contract uses `tx.origin` for authorization instead of `msg.sender`. What attack does this enable?

    Answer: Phishing via a malicious intermediate contract that inherits the original sender's authorization

    tx.origin returns the externally owned account that initiated the call chain, so a malicious contract called by a legitimate user can pass authorization checks intended for that user.

  7. Which architectural decision most directly reduces the blast radius of a compromised smart contract in a DeFi protocol?

    Answer: Implementing circuit breakers with emergency pause functionality per module

    Per-module circuit breakers allow operators to halt only the compromised component, preserving the rest of the protocol during an incident.