Cryptocurrency Transaction Auditing Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cryptocurrency Transaction Auditing flashcards as text
What does the term 'dusting attack' refer to in the context of cryptocurrency transaction auditing?
Answer: Sending tiny amounts to target wallets to link addresses and de-anonymize users when dust is spent
Dusting attacks send minimal amounts to many addresses; when recipients spend the dust combined with other UTXOs, address clustering reveals wallet ownership.
An auditor reviewing a mining pool's payout transactions finds that payouts occur at irregular intervals with varying amounts. What accounting method does this suggest the pool uses?
Answer: Pay Per Last N Shares (PPLNS)
PPLNS pays miners based on shares submitted during a variable window around when a block is found, resulting in irregular payout timing and amounts that vary with luck.
Which regulatory framework requires US cryptocurrency businesses to file a Currency Transaction Report (CTR) for transactions exceeding $10,000?
Answer: The Bank Secrecy Act (BSA) as enforced by FinCEN
The Bank Secrecy Act requires money services businesses, including qualifying crypto exchanges, to file CTRs for cash transactions exceeding $10,000 as enforced by FinCEN.
When tracing funds through a Tornado Cash-style mixer, which analytical approach provides the best chance of breaking the anonymity?
Answer: Timing analysis correlating deposit and withdrawal amounts with temporal patterns
Timing correlation attacks compare deposit and withdrawal timing, amounts, and patterns to probabilistically link deposits to withdrawals despite cryptographic anonymity.
A VASP's transaction monitoring system flags a customer who makes many small purchases just below the $3,000 record-keeping threshold. What BSA violation does this suggest?
Answer: Structuring (smurfing) to evade FinCEN record-keeping requirements
Structuring involves deliberately breaking transactions into smaller amounts below reporting thresholds to evade BSA record-keeping or CTR filing requirements.
Which attribute of a blockchain transaction provides cryptographic proof that the transaction has not been altered after broadcast?
Answer: The transaction hash (TXID), derived from a cryptographic hash of the transaction data
The TXID is a cryptographic hash of all transaction fields; any alteration would produce a completely different hash, making tampering detectable.
In a Proof-of-Work blockchain audit, what does a sudden significant drop in mining difficulty combined with an increase in block time suggest about network health?
Answer: A substantial portion of the hash rate left the network, reducing competitive mining power
Difficulty automatically adjusts downward when blocks take longer than target intervals, indicating that a meaningful portion of mining nodes went offline or switched networks.