← All CCA Flashcard Decks

Blockchain Forensic Analysis Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Blockchain Forensic Analysis flashcards as text
  1. What is the primary purpose of a 'peeling chain' pattern in blockchain forensics?

    Answer: To obfuscate the origin of funds by repeatedly splitting and forwarding small amounts

    A peeling chain moves funds through a series of transactions where one output is sent onward and the remainder is kept, creating a chain that obscures the original source.

  2. Which heuristic assumes that all inputs in a Bitcoin transaction belong to the same wallet owner?

    Answer: Common input ownership heuristic (CIOH)

    The Common Input Ownership Heuristic (CIOH) is a foundational blockchain clustering technique that groups addresses whose UTXOs are co-spent in the same transaction.

  3. In Ethereum forensics, what does analyzing the 'internal transactions' (traces) reveal that standard transaction logs do not?

    Answer: Value transfers triggered by smart contract execution

    Internal transactions (message calls) capture ETH movements that occur within smart contract logic and are not recorded as top-level transactions.

  4. A suspect uses a centralized mixer that pools funds from many users and redistributes equivalent amounts. Which forensic indicator most reliably links the deposit to the withdrawal?

    Answer: Timing correlation and matched denomination amounts

    Timing analysis combined with denomination matching is the strongest available signal when a mixer disrupts direct UTXO linkage between deposit and withdrawal.

  5. What distinguishes a 'hot wallet' from a 'cold wallet' in the context of exchange forensics?

    Answer: Hot wallets are internet-connected and used for daily operations; cold wallets are offline and hold reserves

    Hot wallets remain online for operational liquidity, making them higher-risk targets, while cold wallets are air-gapped to protect bulk reserves.

  6. Which blockchain data element would a forensic analyst primarily use to identify a 'dusting attack' victim?

    Answer: Addresses that received tiny, unsolicited micro-transactions below the dust limit

    Dusting attacks send sub-dust amounts to target addresses so that if the victim later co-spends the dust, the attacker can cluster and deanonymize their wallet.

  7. When reconstructing a DeFi exploit on Ethereum, which tool provides the most granular trace of every internal call and state change during a specific transaction?

    Answer: A transaction debugger/tracer such as Tenderly or Foundry's cast run

    Debuggers like Tenderly replay transactions step-by-step, exposing every CALL, DELEGATECALL, and storage slot change that a receipt or basic explorer view omits.