โ† All CCA Flashcard Decks

Security & Risk Analysis Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Risk Analysis flashcards as text
  1. Which attack vector specifically targets cryptocurrency users by redirecting them to a fake exchange website through DNS manipulation?

    Answer: DNS spoofing

    DNS spoofing (cache poisoning) redirects users to malicious sites by corrupting DNS resolver caches with fraudulent records.

  2. In a 51% attack on a proof-of-work blockchain, what is the primary capability the attacker gains?

    Answer: Double-spending previously confirmed transactions

    A majority hashrate attacker can reorganize the chain and reverse recently confirmed transactions to double-spend coins.

  3. What is the primary risk associated with a cryptocurrency exchange holding user funds in a single omnibus hot wallet?

    Answer: Concentration risk enabling large-scale theft

    A single omnibus hot wallet concentrates all user funds in one target, making a single compromise catastrophic.

  4. Which risk management framework is most commonly adapted for assessing cybersecurity risks in cryptocurrency custody operations?

    Answer: NIST Cybersecurity Framework

    The NIST Cybersecurity Framework provides identify, protect, detect, respond, and recover functions directly applicable to crypto custody security.

  5. A DeFi protocol's smart contract has an unchecked external call that allows reentrancy. Which audit finding category does this fall under?

    Answer: Critical severity

    Reentrancy vulnerabilities are classified as critical because they can drain all funds from a contract, as demonstrated by the DAO hack.

  6. What does the term 'slippage risk' refer to in the context of decentralized exchange (DEX) trading?

    Answer: Difference between expected and actual execution price due to liquidity changes

    Slippage risk is the price difference between when a trade is submitted and when it executes, especially severe in low-liquidity pools.

  7. In cryptocurrency auditing, what is 'address reuse' primarily a risk to?

    Answer: User privacy and potentially key security through reduced entropy

    Address reuse links transactions together on the public ledger, degrading privacy and exposing spending patterns to blockchain analysis.