← All CCE Flashcard Decks

Security & Risk Management Flashcards

7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Risk Management flashcards as text
  1. What is the main purpose of a bug bounty program in the cryptocurrency ecosystem?

    Answer: Incentivize ethical hackers to find and report vulnerabilities

    Bug bounty programs pay security researchers to responsibly disclose vulnerabilities before malicious actors exploit them.

  2. Which risk specifically affects DeFi protocols due to their reliance on external price feeds?

    Answer: Oracle manipulation risk

    Oracle manipulation risk arises when attackers manipulate the price feeds that DeFi protocols rely on to value assets, enabling exploits like flash loan attacks.

  3. What is 'key ceremony' in the context of cryptocurrency infrastructure?

    Answer: A formal, witnessed process for generating and distributing cryptographic keys securely

    A key ceremony is a formal, audited procedure where cryptographic keys are generated in a secure, multi-party environment to ensure no single party controls them.

  4. What does 'operational security' (OPSEC) mean for a cryptocurrency holder?

    Answer: Protecting sensitive information and behaviors that could reveal crypto holdings to adversaries

    OPSEC for crypto holders involves minimizing information leakage about wallet addresses, holdings, and security practices to reduce targeting risk.

  5. Which regulatory framework most commonly requires cryptocurrency exchanges to implement AML programs in the United States?

    Answer: Bank Secrecy Act (BSA)

    The Bank Secrecy Act requires US money services businesses, including many crypto exchanges, to implement AML/KYC programs and file SARs.

  6. What is the role of a 'time-lock' mechanism in smart contract security?

    Answer: Delays execution of sensitive operations, giving time to detect and respond to exploits

    Time-locks impose a mandatory delay before critical functions (like admin upgrades) execute, giving the community time to detect malicious changes.

  7. What is the key risk introduced by using a custodial cryptocurrency service?

    Answer: Counterparty risk — the custodian controls your private keys

    Custodial services hold users' private keys, meaning users bear counterparty risk if the custodian is hacked, insolvent, or fraudulent.