← All Blockchain Technology Flashcard Decks

Mixed Deck — All Blockchain Technology Topics Flashcards

100 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All Blockchain Technology Topics flashcards as text
  1. What does a VRF (Verifiable Random Function) provide in consensus protocols like Algorand?

    Answer: Unpredictable yet verifiable random leader selection

    A VRF generates randomness that is unpredictable in advance but publicly verifiable afterward, used for secret committee selection.

  2. In Bitcoin's HD wallets (BIP-32), what is the role of the chain code alongside an extended key?

    Answer: It provides additional entropy to prevent child key derivation without it

    The chain code is 256 bits of extra entropy combined with the key, ensuring child key derivation requires both components to proceed.

  3. What exactly is a blockchain?

    Answer: A peer-to-peer network distributed ledger

    A blockchain is fundamentally a decentralized, distributed ledger technology that operates on a peer-to-peer network. It consists of a continuously growing list of records, called blocks, which are cryptographically linked together. This structure ensures transparency, immutability, and resistance to censorship, allowing participants to maintain and validate transactions without a central authority.

  4. Why might a dApp emit indexed event parameters rather than non-indexed ones?

    Answer: Indexed parameters become filterable topics, enabling efficient log queries

    Indexed event params are stored as topics, letting clients efficiently filter logs by their values.

  5. Which practice best protects a validator node's signing keys?

    Answer: Store keys in a hardware security module or remote signer

    Isolating signing keys in an HSM or remote signer keeps them off the internet-facing node and limits exposure.

  6. A network attacker successfully manipulates the Network Time Protocol (NTP) responses received by a blockchain node, causing its system clock to be significantly skewed. The node begins rejecting new, valid blocks because their timestamps appear to be too far in the future according to its incorrect local time. This attack is known as:

    Answer: Timejacking

    Timejacking involves manipulating a node's perception of time, typically by attacking its time source (like NTP). By skewing the node's clock, an attacker can cause it to reject valid blocks or accept invalid ones by exploiting the timestamp rules within a blockchain's protocol.

  7. In a reentrancy attack, what must the vulnerable contract do BEFORE updating its internal state?

    Answer: Make an external call that transfers value

    Reentrancy occurs when an external call is made before state changes, letting the callee re-enter and exploit stale state.

  8. A DAO wants to mitigate the risk of treasury mismanagement. Which control is most effective?

    Answer: Spending caps with multisig approval and on-chain transparency

    Caps, multisig, and transparency create accountability and limit unilateral spending.

  9. A DeFi lending protocol's smart contract has a `withdraw()` function that follows this sequence: 1. Checks the user's balance. 2. Sends the Ether to the user's address. 3. Updates the user's balance to zero. An attacker creates a malicious contract with a fallback function. When the attacker calls `withdraw()`, their fallback function is triggered by the incoming Ether and immediately calls the `withdraw()` function again before the original call can update the balance. What type of vulnerability is being exploited?

    Answer: Reentrancy

    This is a classic example of a Reentrancy attack. The vulnerability exists because the contract sends Ether (an external call) before it updates its internal state (the user's balance). An attacker's contract can use its fallback function to 're-enter' the vulnerable function and repeatedly withdraw funds until the contract is drained or the gas limit is hit.

  10. In Hierarchical Deterministic (HD) wallets, what cryptographic function derives child keys from a parent key?

    Answer: HMAC-SHA512

    HD wallets use HMAC-SHA512 with the parent key and chain code to derive child private and public keys deterministically (BIP-32).

  11. What is the recommended first step when a user suspects their non-custodial wallet private key has been compromised?

    Answer: Immediately transfer all assets to a new wallet with freshly generated keys

    Once a key is suspected compromised, moving assets to a clean wallet is the only reliable mitigation, since the attacker may exploit the key at any moment.

  12. Why should a withdrawal pattern be preferred over pushing funds to users in a loop?

    Answer: It avoids failures and DoS when one recipient reverts

    Letting users pull funds prevents one failing transfer from blocking payouts to everyone else.

  13. A public blockchain network prioritizes maximum censorship resistance and security above all else, following the original model set by Bitcoin. The developers accept high energy consumption and probabilistic finality as necessary trade-offs. Which consensus mechanism is best aligned with these goals?

    Answer: Proof of Work (PoW)

    Proof of Work (PoW) provides the highest level of security and censorship resistance in a permissionless environment through the expenditure of real-world resources (computational power and energy). This makes it extremely expensive for any single entity to control the network (a 51% attack), thus ensuring its robustness. Other mechanisms often trade some of this raw security for benefits like higher speed or lower energy usage.

  14. What is a state channel in the context of blockchain scalability?

    Answer: An off-chain communication channel where participants exchange signed state updates without touching the blockchain for each transaction

    State channels allow participants to lock funds on-chain, then exchange signed messages off-chain, only posting the final state to the blockchain when closing the channel.

  15. What is 'selfish mining'?

    Answer: Withholding found blocks to gain a disproportionate share of rewards

    Selfish miners withhold newly found blocks and release them strategically to waste honest miners' work and capture more than their fair reward share.

  16. Why is the delegatecall function considered dangerous when used with untrusted contracts?

    Answer: It allows the called contract to execute code in the context of the calling contract's storage

    Delegatecall executes the target contract's code but uses the calling contract's storage and context, so a malicious target can overwrite critical storage variables.

  17. A flash loan enables an attacker to do what within a single transaction?

    Answer: Borrow large uncollateralized funds that must be repaid before the transaction ends

    Flash loans provide large capital with no collateral as long as repayment happens atomically in the same transaction.

  18. What is 'MEV' (Maximal Extractable Value) related to consensus?

    Answer: Value validators/miners extract by reordering, including, or censoring transactions

    MEV is profit block producers can capture by controlling transaction ordering within blocks.

  19. Which mitigation addresses the risk of an upgradeable proxy being pointed at a malicious implementation?

    Answer: Restricting upgrade rights to a timelocked multisig with public visibility

    Timelocked, multisig-controlled, visible upgrades prevent stealthy malicious implementation swaps.

  20. A retailer wants to verify that diamonds in its supply chain are conflict-free. Which blockchain property makes this possible?

    Answer: Immutable provenance records at each custody transfer

    Each custody transfer is recorded as an immutable on-chain event, creating an auditable provenance trail from mine to retailer.