Security & Risk Analysis Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Risk Analysis flashcards as text
Which type of oracle manipulation attack artificially moves the price reported to a DeFi protocol within a single block to exploit lending or liquidation logic?
Answer: Flash loan oracle attack
Flash loan oracle attacks use uncollateralized loans within one transaction to manipulate spot price oracles and exploit protocols relying on them.
What cryptographic property ensures that a transaction signed with a private key cannot be repudiated by the signer in blockchain systems?
Answer: Non-repudiation
Non-repudiation via digital signatures means the key owner cannot deny authorizing a transaction because only they possess the private key.
When auditing a cryptocurrency exchange, which control is most effective at detecting unauthorized access to production systems?
Answer: Implementing privileged access management (PAM) with session recording
PAM with session recording provides granular logging and replay of all privileged actions, enabling detection and forensic investigation of unauthorized access.
A blockchain auditor discovers that a protocol's emergency pause function is controlled by a single externally owned account (EOA). What risk does this represent?
Answer: Single point of failure and key-person risk for critical safety functions
A single EOA controlling emergency functions creates a key-person dependency where compromise or loss of one key disables the protocol's safety mechanism.
What is the primary purpose of a Merkle proof in the context of cryptocurrency exchange audits and proof-of-reserves?
Answer: To cryptographically prove a specific account balance is included in the exchange's total reserve set
Merkle proofs allow a user to verify their balance is included in the exchange's liability tree without the exchange revealing all other customer balances.
In the CVSS scoring system used for vulnerability severity ratings, which metric group captures the ease of exploiting a vulnerability remotely without authentication?
Answer: Base metrics — Attack Vector and Privileges Required
CVSS base metrics including Attack Vector (Network) and Privileges Required (None) capture remote, unauthenticated exploitability.
Which smart contract upgrade pattern introduces the most significant centralization and proxy-admin key risk?
Answer: Transparent proxy with a single admin key
A transparent proxy with a single admin key allows one compromised key to silently upgrade contract logic and redirect all funds.