← All CBSE Flashcard Decks

Architectural and Design Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Architectural and Design Security flashcards as text
  1. A blockchain application must comply with GDPR's right to erasure. Which architectural approach best satisfies this requirement without breaking chain immutability?

    Answer: Store only a hash on-chain while keeping personal data in an erasable off-chain store

    Hashing a pointer on-chain while storing erasable personal data off-chain allows deletion of the actual data while preserving audit trail integrity.

  2. What is the primary security function of a blockchain oracle in a smart contract architecture?

    Answer: Providing authenticated real-world data to on-chain contracts

    Oracles act as trusted data bridges, feeding external facts (prices, events) into smart contracts that cannot natively access off-chain information.

  3. Which attack exploits the fact that a smart contract reads its own balance during execution and that balance can be manipulated before the call completes?

    Answer: Reentrancy

    Reentrancy allows an external malicious contract to repeatedly call back into the victim contract before its state is updated, draining funds.

  4. In a blockchain network, what does 'finality' mean from a security design perspective?

    Answer: A confirmed transaction cannot be reversed or altered by any subsequent event

    Finality guarantees that once a transaction achieves a sufficient confirmation depth or BFT commit, it is irreversible—critical for settlement security.

  5. A developer proposes storing AES-encrypted sensitive data on a public blockchain with the decryption key held by the user. What is the primary long-term architectural risk?

    Answer: Quantum computing advances could decrypt historically stored ciphertext

    Ciphertext stored permanently on-chain could be decrypted by future quantum computers, exposing sensitive data years after it was written.

  6. Which design pattern prevents a malicious contract from consuming all available gas in a loop when processing an unbounded array of user records?

    Answer: Batch processing with gas limit checks per iteration

    Checking remaining gas inside each loop iteration and halting gracefully prevents out-of-gas failures from unbounded on-chain iteration.

  7. In a consortium blockchain, which trust model assumption is most appropriate when selecting a Byzantine Fault Tolerant (BFT) consensus algorithm?

    Answer: Up to f = (n-1)/3 nodes may be malicious or faulty

    Classical BFT protocols like PBFT tolerate up to f Byzantine (arbitrarily malicious) nodes when n ≥ 3f+1, meaning fewer than one-third can be adversarial.