Security & Risk Management Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Security & Risk Management flashcards as text
A cryptocurrency exchange operating in multiple jurisdictions discovers that one of its liquidity providers is flagged by OFAC's SDN list only AFTER a series of transactions have already settled on-chain. Under U.S. Treasury guidance, which response sequence is most legally defensible?
Answer: File a Suspicious Activity Report (SAR) within 30 days, freeze remaining funds of the counterparty, and self-report to OFAC using the voluntary disclosure program to seek penalty mitigation
OFAC violations carry strict liability regardless of intent. When a post-settlement SDN match is discovered, the exchange should file a SAR per FinCEN rules, freeze any residual exposure, and proactively self-disclose to OFAC. Voluntary self-disclosure is formally recognized in OFAC's penalty mitigation framework and can reduce penalties significantly. Reversing settled on-chain transactions is generally impossible and legally irrelevant to the OFAC violation. Notifying SEC/CFTC is not the primary obligation for sanctions violations, and deferring all reporting increases liability.
A DeFi protocol's smart contract contains an upgradeable proxy pattern. A white-hat researcher discovers that the proxy admin key is held by a 2-of-3 multisig where one signer is a pseudonymous developer who has since become unresponsive. From a governance and operational risk perspective, what is the PRIMARY concern?
Answer: The protocol faces key-person concentration risk combined with a degraded multisig threshold, effectively reducing the real quorum to 1-of-2 signers
With one signer unresponsive, the effective signing threshold has collapsed from 2-of-3 to requiring both remaining signers (2-of-2), eliminating the redundancy that the multisig was designed to provide. This creates both concentration risk (two single points of failure instead of none) and liveness risk if either remaining signer becomes unavailable. The proxy pattern itself is a separate design choice, not inherently a risk requiring migration. Pseudonymity does not automatically create AML exposure for token holders. There is no evidence of key compromise — unresponsiveness alone does not imply compromise.
Under the NIST Cybersecurity Framework adapted for a crypto-asset custodian, which control best addresses the threat of a 'time-of-check to time-of-use' (TOCTOU) race condition vulnerability in a hot wallet withdrawal pipeline?
Answer: Implementing atomic database transactions with pessimistic locking on balance records during the full withdrawal authorization-to-broadcast sequence
TOCTOU vulnerabilities arise when a system checks a condition (e.g., sufficient balance) and then acts on it (broadcasts a transaction) as separate non-atomic steps — allowing an attacker to alter state between check and use. Atomic database transactions with pessimistic locking ensure the balance check and debit occur as an indivisible operation, preventing concurrent requests from exploiting the window between check and use. 2FA addresses authentication, not race conditions. WAFs address network-layer attacks. Redis nonces prevent replay attacks, which are a related but distinct threat class.
A crypto asset manager uses a deterministic (HD) wallet where the master extended public key (xpub) has been inadvertently exposed in a public GitHub repository for 72 hours. The master private key remains secure in cold storage. What is the MOST accurate characterization of the resulting risk?
Answer: All current and future derived addresses and their balances are now publicly linkable to the entity, destroying address-based privacy and enabling targeted phishing, dust attacks, and front-running of on-chain activity
An exposed xpub does NOT allow derivation of private keys (making option B incorrect), but it allows any observer to derive ALL child public keys and addresses in the HD tree. This completely destroys the privacy model of HD wallets — every deposit address, change address, and future address can be linked to the entity. This enables sophisticated attacks: targeted spear-phishing using balance knowledge, blockchain surveillance, dust attacks to further track funds, and front-running large known incoming deposits. Option C understates the privacy damage. Option D is incorrect because the xpub covers the entire derivation tree, not just used paths.
A crypto exchange's risk committee is evaluating whether to list a new Layer-1 token. The token uses a novel consensus mechanism where the top 21 validators by stake control block production. Due diligence reveals that the top 3 validators collectively control 34% of stake and are all operated by entities affiliated with the founding team. Which specific risk factor should be the PRIMARY blocker for listing?
Answer: The 34% stake concentration among affiliated validators means the founding team can execute a 34% attack to disrupt liveness or, in a Practical Byzantine Fault Tolerance variant, potentially halt the chain — creating exchange-level settlement finality risk
In BFT-style consensus (common in DPoS chains with 21 validators), a 33%+ stake share controlled by colluding validators can halt the chain by refusing to finalize blocks — this is the BFT liveness threshold. With 34% concentrated among founding-team affiliates, the exchange faces direct settlement finality risk: transactions confirmed on the chain could become unconfirmed if the chain halts or forks. This is the most operationally critical risk for an exchange. While validator count, securities risk, and MEV are all valid concerns, none create the same direct, quantifiable threat to settlement integrity that the 34% BFT threshold does.
A regulated crypto custodian is designing its key management architecture and must choose between two HSM (Hardware Security Module) deployment models: (A) a FIPS 140-2 Level 3 HSM cluster with automatic failover, or (B) a FIPS 140-2 Level 4 HSM in a geographically isolated cold facility requiring manual m-of-n quorum for any operation. A risk assessment must weigh confidentiality, integrity, availability, and regulatory standing. For a custodian holding assets on behalf of institutional clients under SOC 2 Type II and state trust company regulations, which statement best captures the correct trade-off analysis?
Answer: Model B provides superior key confidentiality and physical tamper resistance but introduces availability risk and operational latency; Model A is more appropriate for hot/warm operational keys while Model B is appropriate for root keys or master secrets, suggesting a tiered architecture is optimal
This question tests understanding of the CIA triad trade-offs in HSM architecture. FIPS 140-2 Level 4 adds physical security against environmental attacks but the manual quorum requirement creates liveness risk — incompatible with real-time hot wallet operations. Level 3 with automatic failover optimizes availability, suitable for operational signing keys. The correct institutional answer is a tiered architecture: Level 4 for root/master keys (rarely accessed, maximum protection warranted) and Level 3 clusters for operational keys (frequent access, availability critical). Option B ignores the availability dimension. Option C mischaracterizes SOC 2 — it evaluates availability controls holistically, not by penalizing manual quorums. Option D overstates MPC as a replacement rather than a complement.