← All CBSE Flashcard Decks

Blockchain Threat Modeling Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Blockchain Threat Modeling flashcards as text
  1. A blockchain threat model categorizes a threat as affecting 'availability' of the network. Which specific attack does this BEST describe?

    Answer: A transaction flooding DoS attack that fills the mempool and blocks legitimate transactions

    Transaction flooding is a denial-of-service attack that exhausts mempool capacity, preventing legitimate transactions from being included in blocks.

  2. In a blockchain threat model, what role does the 'assume breach' principle play?

    Answer: It designs security controls assuming an attacker has already gained partial access

    The assume breach principle shifts focus to detection, containment, and recovery by designing systems that limit blast radius even after an initial compromise.

  3. Which threat to blockchain node software is BEST categorized under the 'Elevation of Privilege' component of STRIDE?

    Answer: A bug in the consensus client allowing a peer to trigger admin RPC calls without authentication

    Elevation of Privilege occurs when an attacker gains capabilities beyond their authorized level, such as triggering privileged RPC calls via a client vulnerability.

  4. A threat model for a blockchain wallet identifies seed phrase backup as a critical asset. Which threat to this asset is classified as an 'insider threat'?

    Answer: A malicious wallet developer embedding a seed exfiltration backdoor in the app

    An insider threat originates from a trusted party with privileged access, such as a developer intentionally inserting malicious code to steal seed phrases.

  5. Which technique in blockchain threat modeling specifically evaluates whether smart contract state transitions can lead to unintended final states?

    Answer: Formal verification using model checkers

    Formal verification uses mathematical model checkers to exhaustively prove or disprove that all possible smart contract state transitions conform to specified invariants.

  6. In threat modeling a blockchain's governance mechanism, which attack does vote delegation with no time-lock primarily enable?

    Answer: A flash loan governance attack where borrowed tokens manipulate a vote within a single block

    Without a time-lock between delegation and voting, an attacker can borrow a large token balance via flash loan, cast a decisive vote, then repay the loan—all in one transaction.

  7. A threat model document lists 'gas griefing' as a threat. What does this attack involve?

    Answer: A caller passing insufficient gas to a sub-call so it fails while the outer call succeeds, corrupting contract state

    Gas griefing exploits contracts that forward user-supplied gas to sub-calls; by providing too little gas, an attacker causes a sub-call revert without reverting the outer call.