โ† All CBSE Flashcard Decks

Node and Network Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Node and Network Security flashcards as text
  1. Which network segmentation practice best reduces the blast radius if a single blockchain node in an enterprise deployment is compromised?

    Answer: Isolating each node in its own network segment with strict inter-node firewall rules

    Network microsegmentation limits lateral movement; a compromised node cannot directly reach other nodes' RPC ports or internal services if each segment has dedicated ACLs.

  2. What is the role of 'checkpoint' blocks in Bitcoin's security model against certain network-level history-rewriting attacks?

    Answer: They prevent a node from accepting a chain that diverges before a known-good block hash, blocking deep reorg attacks

    Hardcoded checkpoints make it computationally infeasible to feed a node a completely different chain history before those points, protecting against long-range reorg attacks.

  3. In the context of blockchain node security, what does 'peer banning' accomplish?

    Answer: It blacklists a misbehaving peer's IP address so the node will not reconnect to it

    Peer banning records an offending IP in a ban list and refuses future connections from that address for a configurable period, isolating misbehaving or malicious peers.

  4. An attacker compromises DNS servers used by a blockchain node to resolve seed node hostnames. What class of attack does this represent, and what is the best mitigation?

    Answer: A DNS hijacking attack; mitigated by using hardcoded seed IP addresses or DNSSEC-validated lookups

    DNS hijacking redirects seed node lookups to attacker-controlled IPs; hardcoded seed IPs or DNSSEC prevents reliance on a poisoned DNS response for initial peer discovery.

  5. Which log event on a blockchain node most strongly indicates an active brute-force attack against its JSON-RPC authentication?

    Answer: Hundreds of 401 Unauthorized responses from the RPC server in a short window

    Rapid repeated 401 errors on the RPC port indicate an automated tool is cycling through password guesses, constituting a brute-force credential attack.

  6. What security property does 'onion routing' (Tor) provide when used to connect blockchain nodes to the P2P network?

    Answer: IP address anonymization, preventing network-level deanonymization of node operators

    Tor masks the node's real IP address by routing traffic through multiple encrypted relays, preventing adversaries from linking a transaction to a specific IP address.

  7. A smart contract platform node is exhibiting 'chain bloat' where adversarial contracts fill state storage to degrade node performance. Which mitigation strategy directly addresses this at the protocol level?

    Answer: Introducing state rent or storage fees that charge for persistent on-chain storage over time

    State rent mechanisms impose ongoing costs for occupying blockchain state, making it economically prohibitive for attackers to permanently bloat node storage with dust contracts.