Blockchain Threat Modeling Flashcards
7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Blockchain Threat Modeling flashcards as text
In STRIDE threat modeling applied to a blockchain node, which threat category specifically addresses a malicious node falsely claiming to be a trusted validator?
Answer: Spoofing
Spoofing in STRIDE covers identity impersonation, such as a node falsely presenting itself as a legitimate validator to gain trust.
Which attack vector does a threat model for a public blockchain's mempool primarily need to address regarding transaction ordering?
Answer: Miner Extractable Value (MEV) front-running
MEV front-running exploits the ability of miners/validators to reorder, insert, or censor pending transactions in the mempool for profit.
A threat model identifies that an attacker can intercept peer-to-peer gossip messages between blockchain nodes. Which control BEST mitigates this threat?
Answer: Implementing TLS/noise protocol encryption for P2P communication
Encrypting P2P communication with TLS or noise protocol prevents eavesdropping and man-in-the-middle attacks on gossip traffic.
In a DeFi protocol threat model, what does 'oracle manipulation' represent as an attack surface?
Answer: Feeding false external price data to influence on-chain contract logic
Oracle manipulation involves supplying tampered off-chain data (e.g., asset prices) to smart contracts, allowing attackers to exploit dependent logic.
Which threat modeling methodology uses an attacker-centric approach by enumerating attack trees rooted at a specific adversary goal against a blockchain system?
Answer: Attack Tree Analysis
Attack Tree Analysis models threats from the attacker's perspective by decomposing a top-level adversarial goal into sub-goals and leaf-node attack methods.
During threat modeling of a permissioned blockchain, which trust boundary is MOST critical to define between the ordering service and peer nodes?
Answer: The boundary where consensus messages are validated and authenticated
The ordering service-to-peer boundary is critical because unauthenticated consensus messages could allow a compromised orderer to inject invalid blocks.
A threat model rates a vulnerability with high likelihood but low impact. How should this be prioritized compared to a low-likelihood, high-impact threat?
Answer: Use risk scoring (likelihood × impact) to compare and prioritize objectively
Risk scoring multiplies likelihood and impact to produce a comparable risk value, enabling objective prioritization across asymmetric threat profiles.