โ† All CCA Flashcard Decks

Blockchain Forensic Analysis Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Blockchain Forensic Analysis flashcards as text
  1. What is the main forensic challenge posed by the Lightning Network compared to on-chain Bitcoin transactions?

    Answer: Lightning payment channels route funds off-chain, leaving minimal publicly traceable records

    Only channel open and close transactions are broadcast on-chain; intermediate routing payments are private, creating significant gaps in the on-chain audit trail.

  2. A suspect's wallet shows a pattern of transactions just below $10,000 in crypto converted to fiat at multiple exchanges over several days. This behavior is best described as:

    Answer: Structuring (smurfing) to evade CTR reporting thresholds

    Structuring (smurfing) involves breaking large sums into sub-threshold transactions to avoid triggering Currency Transaction Reports required above $10,000.

  3. When analyzing a Monero transaction, which feature makes traditional blockchain tracing techniques largely ineffective?

    Answer: Ring signatures, stealth addresses, and RingCT obscure sender, recipient, and amount

    Monero's combination of ring signatures (sender obfuscation), stealth addresses (recipient obfuscation), and RingCT (amount hiding) defeats standard UTXO clustering heuristics.

  4. In blockchain forensics, what does 'graph analysis' specifically refer to?

    Answer: Modeling addresses and transactions as nodes and edges to identify clusters, flows, and patterns

    Transaction graph analysis maps addresses as nodes and value transfers as directed edges, enabling analysts to visualize fund flows and identify entity clusters.

  5. An investigator receives an exchange's KYC record linking a deposit address to a verified user. What is the next forensic step to expand attribution across the suspect's entire wallet?

    Answer: Apply clustering heuristics to the known address to identify co-owned addresses across the blockchain

    Once a seed address is attributed, applying CIOH and change-address heuristics expands the cluster to reveal the full scope of the suspect's on-chain activity.

  6. Which on-chain indicator would most strongly suggest that a DeFi protocol was exploited via a flash loan attack?

    Answer: A single transaction borrowing, manipulating, and repaying a large amount within the same block

    Flash loan exploits are atomic: the entire borrow-manipulate-repay sequence must occur within one transaction, leaving a distinctive single-transaction signature with massive temporary liquidity.

  7. What is 'transaction graph pruning' in the context of large-scale blockchain forensic investigations?

    Answer: Filtering out known benign entities (exchanges, miners) from a transaction graph to focus on high-risk flows

    Pruning removes well-attributed, low-risk nodes (e.g., major exchanges, mining pools) from the graph so analysts can concentrate on unexplained or high-risk transaction paths.