โ† All Blockchain Technology Flashcard Decks

Incident Response and Blockchain Forensics Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response and Blockchain Forensics flashcards as text
  1. What is 'taint analysis' in the context of blockchain forensics?

    Answer: Tracking the movement of funds originating from a known malicious address through subsequent transactions across the blockchain

    Taint analysis propagates a 'taint' marker from a known malicious address through the transaction graph, flagging all downstream addresses and wallets that received those funds.

  2. How do cryptocurrency mixers and tumblers complicate blockchain forensic investigations?

    Answer: They obfuscate fund flows by pooling cryptocurrency from multiple users and redistributing it in different amounts, breaking the traceable transaction trail

    Mixers pool funds from many users and redistribute them to different addresses in varied amounts, severing the direct link between source and destination addresses.

  3. What is the forensic significance of block timestamps in a blockchain investigation?

    Answer: They provide an approximate time reference for event sequencing, but miners can manipulate them within protocol-defined tolerances

    Block timestamps provide rough time ordering for events, but since miners can set them within allowed tolerances, they cannot be treated as authoritative real-world timestamps.

  4. What constitutes the 'audit trail' of a smart contract in a security incident investigation?

    Answer: The immutable record of all events emitted and state changes made by the contract, stored on-chain

    Smart contract audit trails consist of emitted event logs and state change records stored immutably on-chain, providing investigators a complete history of all contract interactions.

  5. Which type of attack involves gradually draining funds from a smart contract through many small transactions specifically designed to stay below monitoring thresholds?

    Answer: Salami slicing attack

    Salami slicing attacks steal funds incrementally through many small transactions, each below alert thresholds, allowing the total theft to accumulate undetected over time.

  6. What is the primary role of a Security Operations Center (SOC) in blockchain incident response?

    Answer: Continuously monitoring blockchain activity and on-chain metrics for anomalies and coordinating the incident response lifecycle

    A SOC monitors systems continuously for threats, detects suspicious on-chain activity, and coordinates the investigation and response across technical and business teams.

  7. What does 'address poisoning' mean in the context of blockchain security incidents?

    Answer: Creating lookalike addresses nearly identical to a victim's frequently used addresses to trick them into sending funds to the attacker

    Address poisoning sends transactions from attacker-controlled addresses that closely resemble the victim's frequent contacts, exploiting the habit of copying addresses from transaction history.