Network and Node Security Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network and Node Security flashcards as text
An attacker monopolizes all of a victim node's peer connections to control its view of the network. What attack is this?
Answer: Eclipse attack
An eclipse attack isolates a node by occupying all its inbound and outbound connections so the attacker controls everything it sees.
Which practice best protects a validator node's signing keys?
Answer: Store keys in a hardware security module or remote signer
Isolating signing keys in an HSM or remote signer keeps them off the internet-facing node and limits exposure.
What is the primary purpose of running a node behind a firewall that only exposes the P2P port?
Answer: Reduce attack surface by blocking unneeded ports
Limiting open ports to only what the node needs shrinks the attack surface available to remote adversaries.
A node operator notices the RPC interface is reachable from the public internet. What is the main risk?
Answer: Unauthorized access to node management and wallet functions
Exposed RPC endpoints can let attackers query or control the node and potentially drain hot wallets.
Which DNS-related weakness can mislead a new node during initial peer discovery?
Answer: Poisoned DNS seed returning attacker-controlled peers
If DNS seeds are poisoned, a bootstrapping node may connect only to malicious peers, enabling eclipse-style isolation.
Why is keeping node client software updated a security priority?
Answer: Patches fix known consensus and network vulnerabilities
Updates close disclosed vulnerabilities that attackers could otherwise exploit against the network or node.
What does a Sybil attack rely on to influence a peer-to-peer network?
Answer: Creating many fake identities or nodes
A Sybil attack floods the network with many fake nodes to gain disproportionate influence over routing or consensus.