Security & Risk Management Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Risk Management flashcards as text
A hardware wallet stores private keys in which type of secure environment?
Answer: Secure Element (SE) chip
Hardware wallets use a Secure Element chip that keeps private keys isolated from internet-connected devices.
Which attack involves an adversary intercepting and potentially altering communications between two parties without their knowledge?
Answer: Man-in-the-middle (MitM) attack
A MitM attack intercepts communication between two parties, allowing the attacker to eavesdrop or alter data.
What is the primary purpose of a multisignature (multisig) wallet setup?
Answer: Require multiple private keys to authorize transactions
Multisig wallets require M-of-N private key signatures before a transaction can be broadcast, distributing control and reducing single-point-of-failure risk.
In a 51% attack on a proof-of-work blockchain, what can the attacker achieve?
Answer: Reverse confirmed transactions and double-spend
Controlling over 50% of hash power lets an attacker reorganize recent blocks, enabling double-spending of their own funds.
Which risk management concept involves spreading crypto holdings across multiple asset classes and storage methods?
Answer: Diversification
Diversification reduces portfolio risk by distributing holdings so that a loss in one asset or storage method doesn't devastate the entire portfolio.
What is a 'seed phrase' (mnemonic phrase) used for in cryptocurrency security?
Answer: Human-readable backup of a wallet's master private key
A seed phrase (typically 12–24 BIP-39 words) encodes the wallet's master private key, allowing full wallet recovery on any compatible device.
Which security practice best protects against SIM-swapping attacks on cryptocurrency accounts?
Answer: Enabling hardware security key (FIDO2) authentication
Hardware security keys (e.g., YubiKey) use FIDO2/WebAuthn and cannot be hijacked via SIM swapping, unlike SMS-based 2FA.