Mixed Deck — All CBSE Topics Flashcards
100 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CBSE Topics flashcards as text
A developer deploys a contract that reads price data from a Chainlink oracle but does not check the 'updatedAt' timestamp. What vulnerability does this create?
Answer: The contract may use stale price data if the oracle has not updated recently, enabling price manipulation exploits
Without validating that the oracle's updatedAt timestamp is recent, the contract may act on stale prices during network outages or oracle failures, enabling attackers to profit from the discrepancy.
What does 'transaction malleability' allow an attacker to do at the network level before a transaction is confirmed?
Answer: Alter the transaction ID (txid) by modifying the scriptSig without changing its validity
Transaction malleability lets a third party tweak the scriptSig data, producing a different txid for the same economic transaction, which can confuse tracking systems.
In a blockchain security audit, which property is verified by 'liveness testing'?
Answer: That the network eventually processes valid transactions
Liveness testing confirms that the blockchain system continues to make progress and process valid transactions under normal and adverse conditions.
In a threshold signature scheme (t-of-n), what happens cryptographically if fewer than t key shares attempt to reconstruct the private key?
Answer: They obtain no information about the private key due to the information-theoretic security of secret sharing
In Shamir's Secret Sharing (the basis of most threshold schemes), fewer than t shares reveal zero information about the secret due to the polynomial construction used.
What is the primary security vulnerability associated with paper wallets?
Answer: Physical loss, theft, or destruction permanently destroys access to funds
Paper wallets exist only as physical objects; if lost, stolen, burned, or deteriorated, the private key is permanently irrecoverable with no backup mechanism.
An enterprise consortium is building a supply chain solution on Hyperledger Fabric. They need to ensure that transactions related to pricing negotiations between a supplier and a retailer are kept confidential and are not visible to other members of the consortium, like logistics providers. Which Hyperledger Fabric feature is specifically designed to address this requirement for data isolation?
Answer: Channels
Channels in Hyperledger Fabric create a private 'subnet' of communication between two or more specific network members. Each channel has its own separate ledger, meaning that only the members of that channel can see and transact on it, providing a powerful mechanism for confidentiality among subsets of participants.
What is the primary purpose of a blockchain node's mempool (memory pool) from a security perspective?
Answer: Holding unconfirmed transactions pending inclusion in a block
The mempool temporarily holds unconfirmed transactions; attackers can exploit it via transaction pinning or fee manipulation to delay or block legitimate transactions.
During a blockchain node stress test, which metric best indicates the onset of a memory exhaustion denial-of-service condition?
Answer: Mempool size growing unbounded while node RAM utilization spikes
An unbounded mempool combined with spiking RAM indicates the node cannot evict or process transactions fast enough, leading to memory exhaustion.
Which cryptographic concept is MOST central to understanding blockchain data integrity, as emphasized in the CBSE curriculum?
Answer: Cryptographic hash functions that link blocks and ensure tamper-evidence
Cryptographic hash functions are foundational to blockchain's tamper-evident chain structure, making them a core CBSE topic.
In the context of enterprise blockchain, what does 'chaincode lifecycle endorsement' in Hyperledger Fabric 2.x prevent?
Answer: Unauthorized chaincode deployment without sufficient organization approval
Fabric 2.x requires a configurable number of organizations to approve chaincode before it can be committed, preventing any single org from unilaterally deploying malicious code.
Which vulnerability type allows an attacker to repeatedly call a DeFi protocol's withdrawal function before the balance is updated?
Answer: Reentrancy
Reentrancy exploits occur when external contract calls are made before state changes, allowing recursive withdrawals that drain funds.
A smart contract platform node is exhibiting 'chain bloat' where adversarial contracts fill state storage to degrade node performance. Which mitigation strategy directly addresses this at the protocol level?
Answer: Introducing state rent or storage fees that charge for persistent on-chain storage over time
State rent mechanisms impose ongoing costs for occupying blockchain state, making it economically prohibitive for attackers to permanently bloat node storage with dust contracts.
What is a 'nothing-at-stake' problem in Proof-of-Stake consensus?
Answer: Validators can vote on multiple competing forks at no additional cost
Nothing-at-stake means validators can simultaneously vote on all fork candidates without penalty, undermining finality and enabling double-spend attacks.
What is a typical recommended prerequisite for candidates pursuing the CBSE certification?
Answer: Familiarity with blockchain fundamentals and cybersecurity concepts
Candidates are encouraged to have baseline knowledge of both blockchain technology and cybersecurity principles before attempting the CBSE.
Which of the following best describes the primary focus of the CBSE credential?
Answer: Security vulnerabilities and risk management within blockchain ecosystems
The CBSE credential centers on identifying, analyzing, and mitigating security threats and vulnerabilities specific to blockchain systems.
A blockchain application must comply with GDPR's right to erasure. Which architectural approach best satisfies this requirement without breaking chain immutability?
Answer: Store only a hash on-chain while keeping personal data in an erasable off-chain store
Hashing a pointer on-chain while storing erasable personal data off-chain allows deletion of the actual data while preserving audit trail integrity.
Which attack exploits the fact that a smart contract reads its own balance during execution and that balance can be manipulated before the call completes?
Answer: Reentrancy
Reentrancy allows an external malicious contract to repeatedly call back into the victim contract before its state is updated, draining funds.
What is the minimum passing score typically required to earn the CBSE credential?
Answer: 70%
EC-Council generally requires a 70% passing score on its certification examinations, including the CBSE.
What is the most common format of the CBSE certification exam?
Answer: Multiple-choice questions (MCQs)
Most professional certification exams, especially in technical fields like cybersecurity, utilize Multiple-Choice Questions (MCQs) as the standard format. This allows for efficient and objective assessment of a broad range of knowledge and understanding of concepts. MCQs are a common and effective way to test theoretical understanding across various topics covered in the CBSE curriculum.
In the context of consensus security, what is a 'DAG-based' consensus approach's primary security advantage over linear chain consensus?
Answer: DAG structures allow multiple blocks to be confirmed concurrently, reducing the window during which a double-spend can be introduced
DAG-based protocols (like IOTA, Phantom, or Conflux) confirm many transactions in parallel, increasing throughput and reducing the time an attacker has to build a competing chain.