Security Principles Flashcards
7 cards from real Blockchain Technology practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Principles flashcards as text
What is the purpose of a security audit before deploying a smart contract to mainnet?
Answer: Independent review to find vulnerabilities before funds are at risk
Audits provide independent expert review to catch vulnerabilities while changes are still cheap and safe.
A proxy upgrade pattern introduces which key security concern?
Answer: A compromised admin can swap in malicious implementation logic
Upgradeable proxies let the admin replace logic, so a compromised admin key can deploy malicious code.
Storage collision in upgradeable proxy contracts occurs when what happens?
Answer: New implementation variables overlap existing storage slots
If a new implementation rearranges variables, its slots can collide with existing data and corrupt state.
Why is a time lock often added to admin functions in DeFi protocols?
Answer: It delays sensitive changes so users can react to malicious actions
A timelock enforces a delay before privileged changes execute, giving users time to exit if the change is harmful.
Denial-of-service via unbounded loops can be triggered when a contract does what?
Answer: Iterates over an array that any user can grow without limit
If users can grow an array, iterating it may exceed the block gas limit and permanently block the function.
What is the recommended response when a critical vulnerability is found in a live contract?
Answer: Pause the contract if possible and execute an incident response plan
A pause mechanism plus a prepared incident response limits damage while a fix or migration is arranged.
A bug bounty program improves security primarily by doing what?
Answer: Incentivizing white-hat researchers to responsibly disclose vulnerabilities
Bounties reward ethical hackers for reporting flaws privately rather than exploiting or selling them.