โ† All CBSE Flashcard Decks

Blockchain System Testing Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Blockchain System Testing flashcards as text
  1. A tester is evaluating a blockchain bridge contract and wants to confirm that a double-spend via replayed Merkle proofs is impossible. Which test is most appropriate?

    Answer: Submit the same valid Merkle proof twice and verify the second claim is rejected

    Replaying an already-processed Merkle proof tests whether the bridge contract tracks used proofs and correctly rejects duplicates.

  2. Which of the following best describes a 'griefing attack' test in the context of blockchain smart contracts?

    Answer: An attacker causes a victim's transaction to fail or become expensive without direct financial gain

    Griefing attack tests confirm that an adversary cannot force victims into costly failed transactions or endless loops without themselves profiting.

  3. During smart contract testing, a developer notices that arithmetic on uint8 values silently wraps at 255 in older Solidity versions. Which mitigation should the test verify is in place?

    Answer: Use of the SafeMath library or Solidity ^0.8.x built-in overflow checks

    SafeMath or Solidity 0.8.x automatic overflow/underflow reversion prevents silent wraparound that attackers can exploit to manipulate balances.

  4. What does a 'front-running' susceptibility test in a DEX smart contract attempt to do?

    Answer: Submit a high-gas transaction that copies a pending transaction's parameters before it is mined

    A front-running test simulates a malicious miner or bot that monitors the mempool and inserts a competing transaction with higher gas to execute first.

  5. In a blockchain node security test, what does testing for 'eclipse attack' resistance verify?

    Answer: That an attacker cannot monopolize all of a node's peer connections to isolate it from the honest network

    Eclipse attack testing attempts to fill a target node's peer table with attacker-controlled peers, verifying that peer diversity and eviction policies prevent full isolation.

  6. A security audit finds that a contract's constructor sets the owner to msg.sender but the contract is deployed via a factory. What test reveals the resulting ownership vulnerability?

    Answer: Deploy the contract via the factory and verify whether the factory contract or the intended user is recorded as owner

    When a factory deploys a contract, msg.sender is the factory address, not the end user, so the factory may unintentionally become the owner.

  7. Which regression test approach is recommended after patching a reentrancy vulnerability in a smart contract?

    Answer: Re-deploy the original unpatched contract to confirm the attack works, then deploy the patched version and confirm the same attack fails

    Confirming the exploit succeeds on the vulnerable version and fails on the patched version proves the fix is both necessary and sufficient.