Incident Response and Blockchain Forensics Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident Response and Blockchain Forensics flashcards as text
What is a 'dust attack' in blockchain security, and what is the attacker's primary objective?
Answer: Sending tiny cryptocurrency amounts to target wallets to deanonymize users through subsequent transaction graph analysis
Dust attacks send negligible amounts of crypto to target wallets; when owners spend those funds combined with others, the transaction reveals wallet connections that attackers use for deanonymization.
In blockchain forensics, what does 'heuristic clustering' refer to?
Answer: Grouping blockchain addresses likely controlled by the same entity based on shared transaction input patterns
Heuristic clustering applies patterns like common-input-ownership to group addresses, enabling investigators to identify wallets belonging to the same person or organization.
What is the primary purpose of a post-mortem analysis conducted after a blockchain security incident?
Answer: To identify root causes and implement improvements that prevent recurrence of similar incidents
A post-mortem examines what failed, why it failed, and what systemic improvements can prevent recurrence — the core purpose is organizational learning, not blame.
Which type of evidence is considered most reliable in a blockchain forensic investigation?
Answer: Immutable, cryptographically verified on-chain transaction records
On-chain transaction records are cryptographically verified and stored immutably on the distributed ledger, making them the most trustworthy evidence type in blockchain forensics.
What is 'transaction graph analysis' used for in a blockchain forensic investigation?
Answer: Mapping fund flows between addresses to identify patterns, cluster entities, and trace stolen assets
Transaction graph analysis creates visual maps of cryptocurrency movements between addresses, enabling investigators to trace stolen assets and identify behavioral patterns.
How should an organization respond when a private key controlling significant funds is confirmed compromised?
Answer: Immediately transfer all remaining funds to a new wallet secured with a different private key
When a private key is compromised, immediate fund transfer to a freshly generated secure wallet is the highest priority action to prevent further theft.
What role do blockchain explorers such as Etherscan play during incident response?
Answer: They provide public, real-time access to on-chain data enabling rapid transaction tracing and address monitoring
Blockchain explorers give responders immediate access to transaction histories, wallet balances, and contract interaction logs, significantly accelerating the investigation process.