โ† All Blockchain Technology Flashcard Decks

Network & Node Security Flashcards

7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network & Node Security flashcards as text
  1. A light client trusts a single remote full node for blockchain data. What is the main security weakness?

    Answer: The remote node can feed false data without verification

    Relying on one server without proofs lets that server present a false chain view to the light client.

  2. Which technique lets a light client verify data without trusting a single provider?

    Answer: Merkle proofs against block headers from multiple sources

    Merkle proofs verified against independently obtained headers let a light client confirm data authenticity.

  3. What is the security purpose of checkpoint/weak-subjectivity sync for a node joining the network?

    Answer: Anchor to a trusted recent state to resist long-range attacks

    A trusted checkpoint prevents an attacker from convincing a fresh node to follow a fake long-range history.

  4. An operator runs a node container with default Docker settings exposing the daemon socket. What is the risk?

    Answer: Container escape and full host compromise

    An exposed Docker socket can let an attacker break out of the container and control the host.

  5. Why is regular backup of a validator's slashing-protection database important?

    Answer: To safely restore without risking a double-sign

    A current anti-slash database lets the validator recover without signing conflicting messages.

  6. What does network segmentation between a node's signer and its public-facing peer process achieve?

    Answer: Limits lateral movement if the public process is breached

    Segmentation contains a compromise of the exposed component so it cannot directly reach the signer.

  7. An operator wants assurance that downloaded node software is authentic. What should they verify?

    Answer: Cryptographic signatures and checksums from the official source

    Verifying signatures and hashes confirms the binary was not tampered with in transit.