Security & Risk Management Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Risk Management flashcards as text
What is an 'eclipse attack' in the context of blockchain networks?
Answer: Flooding a node with fake peers to isolate it from the honest network
In an eclipse attack, the attacker surrounds a target node with malicious peers, cutting it off from legitimate network information.
Which cryptographic scheme is considered most vulnerable to future quantum computing attacks?
Answer: Elliptic Curve Digital Signature Algorithm (ECDSA)
Shor's algorithm running on a sufficiently powerful quantum computer could break ECDSA by solving the discrete logarithm problem, exposing private keys.
What does the term 'cold storage' mean in cryptocurrency security?
Answer: Keeping private keys on devices never connected to the internet
Cold storage refers to keeping private keys completely offline (hardware wallets, paper wallets) to protect against remote hacking.
A reentrancy attack exploits which vulnerability in smart contracts?
Answer: A function that calls an external contract before updating its own state
Reentrancy attacks (as in the 2016 DAO hack) exploit contracts that send ETH to external addresses before updating internal balance state, allowing repeated recursive withdrawals.
What is the primary goal of a Know Your Customer (KYC) process at cryptocurrency exchanges?
Answer: Verify user identity to prevent money laundering and fraud
KYC verifies user identities to comply with AML regulations and prevent illicit use of the platform.
Which type of wallet is most suitable for storing a large long-term cryptocurrency position securely?
Answer: Air-gapped hardware wallet
An air-gapped hardware wallet never connects to the internet, minimizing attack vectors for large, long-term holdings.
What is 'dusting attack' in cryptocurrency?
Answer: Sending tiny amounts of crypto to wallets to trace and de-anonymize owners
Dusting attacks send microscopic amounts of crypto to many addresses, then use transaction graph analysis to cluster and identify wallet owners.