โ† All CBSE Flashcard Decks

Node and Network Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Node and Network Security flashcards as text
  1. Which attack vector allows a malicious node to return false transaction data to lightweight blockchain clients that rely on SPV (Simplified Payment Verification)?

    Answer: Eclipse attack

    An eclipse attack isolates an SPV client by surrounding it with attacker-controlled peers, enabling the attacker to feed false block headers or transaction confirmations.

  2. What is the primary purpose of a blockchain node's mempool (memory pool) from a security perspective?

    Answer: Holding unconfirmed transactions pending inclusion in a block

    The mempool temporarily holds unconfirmed transactions; attackers can exploit it via transaction pinning or fee manipulation to delay or block legitimate transactions.

  3. A blockchain node operator notices abnormally high CPU usage caused by peers repeatedly requesting the same large block. Which denial-of-service technique is being used?

    Answer: Bandwidth exhaustion via block re-request flooding

    Flooding a node with repeated large-block requests wastes CPU and bandwidth resources, constituting a bandwidth exhaustion DoS against that node.

  4. Which TLS/SSL configuration weakness most directly endangers communications between blockchain node peers over an encrypted channel?

    Answer: Allowing TLS 1.0 with RC4 cipher suites

    TLS 1.0 with RC4 is cryptographically broken; RC4 has known biases that allow plaintext recovery, compromising the confidentiality of peer communications.

  5. In Ethereum's devp2p protocol, what cryptographic mechanism is used during the initial handshake to establish a shared session key between two nodes?

    Answer: ECDH (Elliptic Curve Diffie-Hellman) with secp256k1

    Ethereum's RLPx transport uses ECDH on secp256k1 during the auth handshake to derive a shared session key without transmitting the key directly.

  6. What security risk arises when a blockchain node exposes its JSON-RPC interface on 0.0.0.0 without authentication?

    Answer: Unauthorized callers can drain wallets or manipulate node state

    An unauthenticated RPC interface exposed to all interfaces allows any network host to call privileged methods such as eth_sendTransaction or personal_unlockAccount.

  7. Which network-layer defense is most effective at preventing IP-spoofing-based amplification attacks targeting blockchain gossip protocols?

    Answer: BCP 38 ingress filtering at the ISP or router level

    BCP 38 (RFC 2827) ingress filtering drops packets with spoofed source IPs at the network perimeter, preventing spoofed-source amplification attacks.