Security & Risk Management Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Risk Management flashcards as text
What is a 'flash loan attack' in DeFi?
Answer: Exploiting uncollateralized loans to manipulate markets and drain protocols within one transaction
Flash loans allow uncollateralized borrowing within a single transaction; attackers use them to manipulate prices or exploit vulnerabilities and return the loan atomically.
Which practice helps protect against supply chain attacks on cryptocurrency software?
Answer: Verifying software checksums and cryptographic signatures before installation
Verifying SHA-256 checksums and developer PGP signatures confirms that downloaded software hasn't been tampered with in the distribution chain.
What is 'Miner Extractable Value' (MEV) and why is it a security concern?
Answer: Value miners or validators extract by reordering, inserting, or censoring transactions for profit
MEV allows block producers to profit by reordering or inserting transactions, creating unfair advantages and potentially harming regular users through sandwich attacks.
What security vulnerability does a 'backdoored' random number generator (RNG) introduce in cryptocurrency?
Answer: Predictable private keys that attackers can compute without brute force
A backdoored RNG produces seemingly random but actually predictable outputs, allowing the backdoor creator to derive private keys generated using that RNG.
Which control best mitigates the risk of an insider threat at a cryptocurrency exchange?
Answer: Implementing separation of duties and privileged access management
Separation of duties ensures no single employee can complete a sensitive action alone, while privileged access management limits and logs elevated access.
What is 'address poisoning' in cryptocurrency?
Answer: Sending transactions from look-alike addresses to trick users into copying wrong recipient addresses
Attackers send tiny transactions from addresses visually similar to a victim's frequent contacts, hoping the victim copies the fake address from their transaction history.
Which standard defines best practices for information security management systems (ISMS) applicable to cryptocurrency businesses?
Answer: ISO/IEC 27001
ISO/IEC 27001 is the internationally recognized standard for establishing, implementing, and maintaining an ISMS, widely adopted by crypto firms to demonstrate security rigor.