Blockchain Threat Modeling Flashcards
7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Blockchain Threat Modeling flashcards as text
Which threat modeling output artifact is MOST useful for communicating identified risks to executive stakeholders who are not technically proficient?
Answer: A risk register with likelihood, impact, and residual risk scores
A risk register summarizes threats in business terms with prioritized scores, making it accessible to non-technical executives for decision-making.
A threat model for a Layer-2 rollup identifies a threat where the sequencer withholds transactions indefinitely. Which property of the L2 design does this threaten?
Answer: Censorship resistance and liveness
A centralized sequencer that withholds transactions undermines censorship resistance and liveness, as affected users cannot force their transactions on-chain.
In blockchain threat modeling, a 'long-range attack' targets which specific consensus vulnerability?
Answer: Using old private keys from early validators to rewrite chain history from a past checkpoint
A long-range attack uses old but valid private keys to construct an alternative chain history from a distant block, threatening proof-of-stake chain integrity.
Which asset in a blockchain threat model would be classified as having the HIGHEST confidentiality requirement?
Answer: Validator private keys used for block signing
Validator private keys must remain strictly confidential because their compromise allows an attacker to sign blocks, double-vote, or trigger slashing of the validator's stake.
A threat model identifies that a blockchain explorer API lacks rate limiting. Which threat does this MOST directly enable?
Answer: Enumeration and harvesting of wallet address activity for targeted phishing or deanonymization
Without rate limiting, an attacker can mass-query the explorer API to enumerate transaction histories and link addresses to user identities at scale.
In a threat model review, a tester finds that a blockchain application trusts the msg.sender field without verifying it is not a contract. Which attack does this oversight enable?
Answer: A reentrancy attack via a malicious contract fallback function
If msg.sender is a contract with a malicious fallback, it can re-enter the calling contract during an ETH transfer, exploiting state that has not yet been updated.
When documenting mitigations in a blockchain threat model, what distinguishes a 'compensating control' from a 'primary control'?
Answer: A compensating control reduces risk when the primary control cannot be fully implemented, without eliminating the vulnerability
A compensating control is a secondary measure that reduces residual risk when the ideal primary control is technically infeasible or too costly to implement fully.