← All CCE Flashcard Decks

Security & Risk Management Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Security & Risk Management flashcards as text
  1. A DeFi protocol's smart contract contains a reentrancy guard, but an attacker exploits a cross-function reentrancy vulnerability by calling a different public function during a callback. Which risk control failure best explains why the standard reentrancy guard failed to prevent this?

    Answer: The reentrancy guard used a mutex lock scoped only to the function it decorated, not shared across all state-modifying functions in the contract

    A standard per-function reentrancy guard (e.g., OpenZeppelin's nonReentrant modifier) protects only the function it is applied to. Cross-function reentrancy occurs when an attacker re-enters a *different* function in the same contract during a callback, one that shares mutable state but lacks the guard. The fix is a contract-wide mutex (a single storage flag checked by all state-modifying functions) or adopting the Checks-Effects-Interactions pattern universally.

  2. An exchange holds 40% of customer BTC in hot wallets to meet daily withdrawal demand. A risk analyst proposes reducing hot wallet exposure to 5% and routing large withdrawals through a time-locked multi-sig cold wallet. Which threat model consideration most directly justifies the 5% threshold over a lower figure like 1%?

    Answer: Liquidity risk: a threshold too low creates withdrawal delays that can trigger a bank-run dynamic, amplifying reputational and solvency risk

    Setting the hot wallet threshold requires balancing security risk against liquidity risk. If the threshold is too low (e.g., 1%), sudden spikes in withdrawal volume could exhaust the hot wallet, forcing delays. Visible delays can trigger panic withdrawals — a bank-run dynamic — which is itself a catastrophic risk event. The 5% figure represents a calibrated buffer to absorb normal demand variance without exposing excess funds to online attack surfaces.

  3. A blockchain forensics firm identifies that a wallet address linked to a sanctioned entity has 'peeled' funds through 47 intermediate hops, each sending 99.9% of the received amount onward within seconds. What is the primary risk this technique poses to a VASP's AML controls, and what control best addresses it?

    Answer: It obscures the ultimate source of funds by creating a long provenance chain that exceeds the default look-back depth of many blockchain analytics tools; addressed by configuring risk scoring to include indirect exposure beyond direct counterparties

    A 'peel chain' is a layering technique that creates a long sequence of hops to distance funds from their illicit origin. Many blockchain analytics platforms default to scoring only direct (1-hop) counterparties. If the analytics tool's look-back depth is shallower than the chain length, the destination wallet may show a clean direct score even though it is indirectly exposed. The correct control is configuring indirect exposure scoring (sometimes called 'taint analysis' up to N hops) so that inherited risk from the sanctioned entity propagates through the chain.

  4. During a post-incident review, a crypto lending platform discovers that a $120M undercollateralized loan position was liquidated too slowly because the liquidation bot's gas price oracle relied on a 15-minute TWAP that lagged during extreme network congestion. Which risk category does this failure primarily represent, and what is the most targeted remediation?

    Answer: Operational risk arising from oracle design; remediated by implementing a dual-oracle system that switches to a real-time mempool gas estimator when TWAP deviation exceeds a threshold

    This is an operational risk failure rooted in oracle design. The liquidation mechanism itself was functional, but its dependency on a lagging gas price oracle caused it to underbid during congestion, delaying execution. The targeted fix is a dual-oracle with a fallback to real-time mempool data (e.g., EIP-1559 base fee + priority fee from recent blocks) when the TWAP diverges significantly. Increasing collateral ratios (credit risk) or hedging (market risk) would not address the operational failure in the liquidation pipeline.

  5. A Tier-1 crypto custodian uses Shamir's Secret Sharing (SSS) to split a master private key into 7 shards with a 4-of-7 recovery threshold. A security auditor flags that storing all 7 shards within the same geopolitical region violates a key principle. Which risk principle is violated and what is the specific threat it leaves unmitigated?

    Answer: The principle of geographic distribution; the threat is correlated loss — a single legal jurisdiction, natural disaster, or physical seizure event could simultaneously compromise enough shards to meet the recovery threshold

    SSS provides redundancy and access-control benefits, but those benefits are negated if the shards are geographically co-located. A correlated event — government seizure under a single legal jurisdiction, a regional earthquake, or a targeted physical attack — could compromise 4 or more shards simultaneously, meeting the recovery threshold without the custodian's authorization. Best practice distributes shards across multiple jurisdictions and different physical facilities to ensure that no single correlated event can expose a quorum.

  6. A crypto hedge fund's risk committee reviews a scenario where a large arbitrage position across two DEXs becomes unprofitable mid-execution because a MEV bot front-ran the second leg of the trade on-chain. The fund wants to quantify this as a distinct risk category in its risk register. What is the most precise classification?

    Answer: Extractable value risk (a sub-category of operational/execution risk) — losses attributable to validator/miner ordering of transactions that extract value from the fund's pending transactions

    MEV (Maximal Extractable Value) risk is a distinct execution-layer risk where block producers or bots observing the mempool reorder, insert, or censor transactions to extract value at the expense of the original submitter. It differs from standard slippage (market risk) because the price move is *caused* by the fund's own observable transaction, not by exogenous market movement. It differs from liquidity risk because sufficient depth existed — the bot simply inserted a competing trade first. Leading risk frameworks now classify MEV exposure as a separate line item under execution or operational risk.