Blockchain System Testing Flashcards
7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Blockchain System Testing flashcards as text
Which testing technique is most effective for discovering re-entrancy vulnerabilities in smart contracts?
Answer: Fuzz testing with recursive call injection
Fuzz testing with recursive call injection generates unexpected re-entrant call sequences that static analysis may miss.
A blockchain tester wants to verify that a node correctly enforces the longest-chain rule during a network partition. Which test environment best supports this?
Answer: Simulated network with configurable partition controls
A simulated network with configurable partition controls lets testers isolate node clusters and observe fork-resolution behavior.
During penetration testing of a blockchain node's RPC interface, which attack vector should be tested first?
Answer: Unauthenticated JSON-RPC method exposure
Unauthenticated JSON-RPC exposure is the most common and immediately exploitable misconfiguration on blockchain nodes.
What does a negative gas limit test in Ethereum smart contract testing verify?
Answer: That the EVM rejects transactions with an invalid or zero gas limit
Testing with zero or invalid gas limits verifies that the EVM correctly rejects malformed transactions before execution.
In a blockchain security audit, which property is verified by 'liveness testing'?
Answer: That the network eventually processes valid transactions
Liveness testing confirms that the blockchain system continues to make progress and process valid transactions under normal and adverse conditions.
Which tool is specifically designed for automated security testing of Solidity smart contracts via symbolic execution?
Answer: Mythril
Mythril uses symbolic execution and taint analysis to automatically detect security vulnerabilities in Solidity contracts.
A tester discovers that a DeFi protocol's oracle aggregator accepts a single data source. What vulnerability class does this represent?
Answer: Single point of failure / oracle manipulation
Relying on a single oracle source creates a single point of failure that attackers can manipulate to feed false price data.