Security and Regulatory Compliance Flashcards
7 cards from real Cryptocurrency practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Regulatory Compliance flashcards as text
What is the purpose of a crypto exchange's Proof of Reserves audit?
Answer: To verify the exchange holds sufficient assets to cover customer balances
Proof of Reserves is a cryptographic audit allowing exchanges to demonstrate they hold 1:1 backing for customer funds without revealing individual balances.
Which regulation requires U.S. taxpayers to report cryptocurrency transactions to the IRS?
Answer: Internal Revenue Code Section 6050I
IRS Section 6050I was updated in the Infrastructure Investment and Jobs Act to require reporting of digital asset transactions over $10,000 received in a trade or business.
What is a 'replay attack' in the context of blockchain hard forks?
Answer: Rebroadcasting a valid transaction from one chain to have it executed on the other chain
After a hard fork, a replay attack broadcasts a valid transaction from the original chain on the new chain, potentially draining funds on both chains simultaneously.
What does OFAC's SDN list mean for crypto compliance?
Answer: It lists sanctioned individuals and entities whose crypto addresses must be blocked
OFAC's Specially Designated Nationals list includes wallet addresses of sanctioned parties, and U.S. persons are prohibited from transacting with them.
What is 'seed phrase' security best practice for self-custody wallets?
Answer: Never store it digitally; keep physical copies in secure offline locations
Seed phrases should never be stored digitally; physical copies kept offline in fireproof or geographically distributed locations are the recommended practice.
Under the EU's MiCA regulation, what are Crypto-Asset Service Providers (CASPs) required to obtain?
Answer: An authorization/license from their national competent authority
MiCA (Markets in Crypto-Assets) requires CASPs to be authorized by the competent authority of their EU member state before offering services.
What is a 'dusting attack' in cryptocurrency?
Answer: Sending tiny amounts of crypto to wallets to track and de-anonymize their owners
Attackers send small 'dust' amounts to many wallets, then analyze blockchain transactions to link addresses and de-anonymize wallet owners.