Network and Node Security Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network and Node Security flashcards as text
What is the security purpose of rate-limiting incoming RPC requests on a node?
Answer: Mitigate resource-exhaustion and abuse
Rate-limiting prevents a single client from overwhelming the node with excessive requests.
An attacker delays relaying blocks to a victim node to gain an advantage. What is this called?
Answer: Timejacking or block-withholding style delay attack
Delaying block or time information to a node manipulates its view and can enable double-spend or consensus manipulation.
Why is network segmentation recommended when hosting multiple nodes?
Answer: Limits lateral movement if one node is compromised
Segmentation contains a breach to one segment, preventing an attacker from pivoting across all nodes.
Which is a sign that a node may be under an eclipse attack?
Answer: All peers share suspiciously similar IPs or behavior
If a node's peers all appear attacker-controlled or homogeneous, it may be eclipsed from the honest network.
What is the main reason to disable unused JSON-RPC methods on a node?
Answer: Reduce exploitable functionality exposed to callers
Disabling unneeded RPC methods removes attack vectors that could be abused remotely.
Why should a node operator verify client binaries with checksums or signatures before running them?
Answer: To ensure the software was not tampered with
Verifying checksums or signatures confirms the binary is authentic and not a malicious modified build.
Which practice reduces the impact of a stolen hot wallet key on a node?
Answer: Keep only minimal funds in the hot wallet
Keeping minimal funds in a hot wallet limits losses if its key is compromised.