Security Principles Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Principles flashcards as text
A reentrancy attack on a smart contract is best mitigated by which design pattern?
Answer: Checks-effects-interactions pattern
Updating state before making external calls prevents an attacker's fallback from re-entering and draining funds.
Which Solidity construct provides reentrancy protection by locking a function during execution?
Answer: nonReentrant modifier with a mutex
A nonReentrant modifier uses a boolean mutex to block recursive calls into the same function.
Integer overflow vulnerabilities in older Solidity were commonly prevented using which library?
Answer: SafeMath
SafeMath wrapped arithmetic to revert on overflow before Solidity 0.8 made checks built-in.
From Solidity 0.8.0 onward, how is integer overflow handled by default?
Answer: Arithmetic reverts automatically on overflow/underflow
Solidity 0.8+ includes built-in overflow/underflow checks that revert the transaction.
A front-running attack exploits which property of public blockchains?
Answer: Pending transactions are visible in the mempool before mining
Attackers observe pending transactions in the mempool and submit their own with higher gas to execute first.
Which technique helps protect against front-running by hiding transaction intent until confirmation?
Answer: Commit-reveal scheme
Commit-reveal first submits a hashed commitment, then reveals the value later, hiding intent from front-runners.
Why is using tx.origin for authorization considered insecure?
Answer: A malicious intermediary contract can trick the original user into authorizing it
tx.origin returns the original sender, so a phishing contract can pass authorization checks on the victim's behalf.