โ† All CBSE Flashcard Decks

Node and Network Security Flashcards

7 cards from real CBSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Node and Network Security flashcards as text
  1. What is the security implication of running a blockchain node with the '--rpcallowip=0.0.0.0/0' flag in Bitcoin Core?

    Answer: It exposes the RPC server to all IP addresses, allowing any host to send commands

    Setting rpcallowip to 0.0.0.0/0 removes IP-based access control on the RPC port, allowing any internet host to issue wallet and node-management commands.

  2. Which type of attack exploits the gossip protocol's rebroadcast mechanism to exhaust a target node's network bandwidth?

    Answer: Transaction flooding / spam attack

    Transaction flooding sends a high volume of low-fee or zero-fee transactions that propagate through the gossip network, consuming bandwidth and mempool memory on every node.

  3. A security auditor finds that a blockchain node's configuration file stores the RPC password in plaintext. What is the recommended remediation?

    Answer: Use rpcauth with a salted HMAC-SHA256 hash instead of rpcpassword

    Bitcoin Core's rpcauth option stores a salted hash of the password so the plaintext credential never resides in the config file.

  4. In Hyperledger Fabric, what component enforces which nodes are permitted to join the network and sign transactions?

    Answer: Membership Service Provider (MSP)

    The MSP manages digital identities (X.509 certificates) and defines policies that determine which identities can endorse, order, or submit transactions.

  5. What network-level threat does the 'MAX_BLOCK_SIZE' parameter help mitigate in Bitcoin nodes?

    Answer: Resource exhaustion via oversized block propagation

    Enforcing a maximum block size limits how much data a peer can force a node to download and validate, preventing disk/memory exhaustion via crafted large blocks.

  6. Which cryptographic primitive ensures that a node's peer discovery messages in Ethereum's discv5 protocol cannot be forged by a third party?

    Answer: ECDSA signatures over the packet payload using the node's private key

    discv5 packets are signed with ECDSA using the node's secp256k1 private key, binding each discovery message to a verifiable node identity.

  7. A DevSecOps engineer wants to detect if a blockchain node binary has been tampered with before deployment. What is the most reliable verification method?

    Answer: Verifying the cryptographic hash (SHA-256) against the official signed release hash

    A SHA-256 hash verified against a developer-signed checksum file ensures the binary is byte-for-byte identical to the official release, detecting any tampering or supply-chain substitution.