โ† All CBSE Flashcard Decks

Architectural and Design Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Architectural and Design Security flashcards as text
  1. In a Merkle tree-based blockchain, which security property allows a lightweight client to verify transaction inclusion without downloading the full ledger?

    Answer: Merkle proof (SPV proof) against the block's Merkle root

    A Merkle inclusion proof provides a logarithmic-length path from a transaction to the block's Merkle root, enabling Simplified Payment Verification (SPV) without the full chain.

  2. What is the primary design risk of using a single externally owned account (EOA) as the owner of a critical protocol contract on a public blockchain?

    Answer: Single private key compromise results in total protocol control loss

    A single-key owner creates a critical single point of failure; compromise of that one key grants an attacker complete administrative control over the protocol.

  3. Which consensus property is sacrificed when a blockchain network prioritizes availability and partition tolerance according to the CAP theorem?

    Answer: Safety (consistency)

    Per CAP theorem, choosing availability and partition tolerance means the system may return stale or conflicting state, sacrificing strong consistency (safety).

  4. A blockchain architect wants to ensure that even the infrastructure provider cannot read stored contract state. Which technique best achieves confidential smart contract execution?

    Answer: Trusted Execution Environments (TEE) such as Intel SGX for contract computation

    TEEs provide hardware-enforced enclaves where code executes and state remains encrypted even from the host operating system and infrastructure provider.

  5. What design flaw makes 'timestamp dependency' a security vulnerability in smart contracts?

    Answer: Miners can adjust block timestamps within protocol tolerance to influence timestamp-dependent outcomes

    Ethereum allows miners to set block.timestamp within a ~900-second window, enabling manipulation of time-sensitive contract logic like lottery draws or expiry checks.

  6. Which architectural pattern ensures that a blockchain network can continue operating and reaching consensus even when a minority of validator nodes go offline simultaneously?

    Answer: Byzantine Fault Tolerant protocol with liveness under (n - f) > 2f honest nodes

    BFT protocols guarantee liveness as long as more than two-thirds of nodes are honest and responsive, so a minority outage does not halt the network.

  7. In a token-curated registry (TCR) implemented as a smart contract, which governance attack involves an adversary accumulating a majority of voting tokens to control list inclusion decisions?

    Answer: Plutocracy / token concentration attack

    Token concentration allows a wealthy adversary to dominate votes on which entries are included or excluded, centralizing control of a supposedly decentralized registry.