โ† All CBSE Flashcard Decks

Blockchain Incident Response and Forensics Flashcards

6 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Blockchain Incident Response and Forensics flashcards as text
  1. What does the term 'dusting attack' mean in blockchain security forensics?

    Answer: Sending tiny amounts of crypto to wallets to link them and de-anonymize their owners

    Dusting sends microscopic amounts to wallets; when recipients move funds, analytics tools can cluster addresses and deanonymize them.

  2. Which blockchain forensics indicator suggests a Sybil attack may be underway on a proof-of-stake network?

    Answer: A sudden spike in unique validator addresses with minimal stake each

    Many low-stake validators appearing simultaneously is a hallmark of Sybil attacks attempting to gain disproportionate network influence.

  3. A forensics investigator needs to prove a specific transaction occurred at a certain time on a public blockchain. What provides this proof?

    Answer: The transaction hash, block number, and block timestamp anchored to the immutable chain

    The combination of transaction hash, block number, and finalized block timestamp provides tamper-evident, court-admissible proof of occurrence.

  4. When responding to a private blockchain incident in an enterprise setting, what is a key difference from a public chain investigation?

    Answer: Permissioned access allows forensics teams to query nodes directly and pull private transaction details

    Permissioned blockchains grant authorized investigators direct node access, enabling richer data collection than public chains allow.

  5. What is the role of a blockchain security incident post-mortem report?

    Answer: To document root cause, attacker TTPs, losses, and remediation steps for future prevention

    A post-mortem systematically documents the incident to prevent recurrence and provides transparency to stakeholders and the community.

  6. A CBSE analyst discovers that an attacker used a mixer service to obscure stolen funds. Which regulatory framework do US-based exchanges use to flag mixer-related transactions?

    Answer: FinCEN BSA / AML suspicious activity reporting (SAR)

    Under the Bank Secrecy Act, US exchanges must file SARs with FinCEN when they detect transactions linked to mixers or other obfuscation services.