โ† All CBSE Flashcard Decks

Enterprise Blockchain Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Enterprise Blockchain Security flashcards as text
  1. In enterprise blockchain security audits, what does 'front-running' refer to?

    Answer: Exploiting knowledge of pending transactions to gain unfair advantage

    Front-running occurs when an actor observes a pending transaction in the mempool and submits their own transaction with a higher fee to be processed first.

  2. A smart contract written in Solidity uses the pattern 'transfer()' instead of 'call()' for ETH transfers. What security benefit does this provide?

    Answer: It forwards exactly 2300 gas, preventing reentrancy in fallback functions

    The 2300 gas stipend forwarded by transfer() is insufficient for the recipient to perform state-changing calls, effectively blocking reentrancy attacks.

  3. Which NIST framework publication is most directly applicable to evaluating cryptographic controls in an enterprise blockchain system?

    Answer: NIST SP 800-57

    NIST SP 800-57 provides recommendations for key management, which is foundational to the cryptographic integrity of any blockchain system.

  4. An attacker gains access to the private key of an ordering node in Hyperledger Fabric. What is the most severe immediate consequence?

    Answer: Injecting arbitrary transaction ordering and censoring transactions

    The ordering service controls transaction sequencing; a compromised orderer key allows an attacker to manipulate ordering, censor transactions, or create forks.

  5. What is the purpose of a 'time-lock' mechanism in enterprise blockchain smart contracts?

    Answer: Delaying the execution of critical functions to allow governance review

    Time-locks introduce a mandatory delay before sensitive actions execute, giving stakeholders a window to detect and respond to malicious proposals.

  6. During a penetration test of an enterprise Ethereum node, a tester finds the JSON-RPC port (8545) is publicly accessible. What is the highest-severity attack this enables?

    Answer: Calling eth_sendTransaction to drain unlocked accounts

    An exposed JSON-RPC endpoint with unlocked accounts allows an attacker to sign and broadcast transactions without knowing the private key.

  7. Which key management practice is considered the enterprise gold standard for protecting blockchain signing keys in production?

    Answer: Using Hardware Security Modules (HSMs) with FIPS 140-2 Level 3 certification

    FIPS 140-2 Level 3 HSMs provide tamper-evident physical protection and ensure private keys never leave the secure boundary in plaintext.