← All CBSE Flashcard Decks

Blockchain Threat Modeling Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Blockchain Threat Modeling flashcards as text
  1. In a blockchain threat model, which data flow diagram (DFD) element represents the PostgreSQL database storing off-chain transaction metadata?

    Answer: Data store

    A data store in a DFD represents any persistent storage system, such as a database holding off-chain metadata.

  2. Which blockchain-specific threat involves an attacker deliberately delaying block propagation to increase the chance that their competing block is accepted?

    Answer: Selfish mining

    Selfish mining withholds discovered blocks to gain a disproportionate share of block rewards by forcing honest miners to waste work on orphaned chains.

  3. A threat model for a cross-chain bridge identifies that the bridge's multi-sig wallet requires only 2-of-5 signers. What threat does this primarily expose?

    Answer: Threshold compromise allowing unauthorized fund transfers with only 2 colluding signers

    A low threshold means only 2 signers need to be compromised or collude for an attacker to authorize fraudulent cross-chain transfers.

  4. Which LINDDUN privacy threat category is most relevant when a blockchain's transaction graph allows de-anonymization of user identities?

    Answer: Linkability

    Linkability in LINDDUN describes the ability to correlate transactions or identities across a system, enabling de-anonymization in transparent blockchains.

  5. In threat modeling a smart contract upgrade proxy pattern, what is the primary security concern introduced by the upgradeability mechanism?

    Answer: An unauthorized party could replace contract logic to drain funds or change behavior

    If the upgrade authorization is misconfigured or compromised, an attacker can swap in malicious logic, undermining the immutability assumption of deployed contracts.

  6. A threat modeler identifies that validators in a PoS network can be bribed to sign conflicting blocks. Which countermeasure is specifically designed to deter this threat?

    Answer: Slashing conditions that penalize validators for equivocation

    Slashing destroys a portion of a validator's staked collateral when they sign conflicting blocks, making equivocation economically irrational.

  7. When applying PASTA threat modeling to a blockchain application, which phase involves simulating realistic attack scenarios using threat intelligence?

    Answer: Phase 6 – Attack Enumeration and Modeling

    Phase 6 of PASTA focuses on enumerating and simulating attacker-centric scenarios using threat intelligence to model how identified weaknesses could be exploited.