Security & Risk Analysis Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Risk Analysis flashcards as text
Which attack vector specifically targets cryptocurrency users by redirecting them to a fake exchange website through DNS manipulation?
Answer: DNS spoofing
DNS spoofing (cache poisoning) redirects users to malicious sites by corrupting DNS resolver caches with fraudulent records.
In a 51% attack on a proof-of-work blockchain, what is the primary capability the attacker gains?
Answer: Double-spending previously confirmed transactions
A majority hashrate attacker can reorganize the chain and reverse recently confirmed transactions to double-spend coins.
What is the primary risk associated with a cryptocurrency exchange holding user funds in a single omnibus hot wallet?
Answer: Concentration risk enabling large-scale theft
A single omnibus hot wallet concentrates all user funds in one target, making a single compromise catastrophic.
Which risk management framework is most commonly adapted for assessing cybersecurity risks in cryptocurrency custody operations?
Answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides identify, protect, detect, respond, and recover functions directly applicable to crypto custody security.
A DeFi protocol's smart contract has an unchecked external call that allows reentrancy. Which audit finding category does this fall under?
Answer: Critical severity
Reentrancy vulnerabilities are classified as critical because they can drain all funds from a contract, as demonstrated by the DAO hack.
What does the term 'slippage risk' refer to in the context of decentralized exchange (DEX) trading?
Answer: Difference between expected and actual execution price due to liquidity changes
Slippage risk is the price difference between when a trade is submitted and when it executes, especially severe in low-liquidity pools.
In cryptocurrency auditing, what is 'address reuse' primarily a risk to?
Answer: User privacy and potentially key security through reduced entropy
Address reuse links transactions together on the public ledger, degrading privacy and exposing spending patterns to blockchain analysis.