← All CCA Flashcard Decks

Security & Risk Analysis Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Risk Analysis flashcards as text
  1. During a cryptocurrency custody audit, an auditor finds that signing keys are generated on an internet-connected machine before being moved to a hardware security module (HSM). What risk does this introduce?

    Answer: The private key may have been exposed or exfiltrated during internet-connected generation

    Generating keys on an internet-connected machine before HSM import exposes the key to malware or network exfiltration during the most vulnerable phase.

  2. What is a 'dusting attack' in the context of cryptocurrency security?

    Answer: Sending minimal amounts of crypto to wallets to trace ownership through subsequent transaction analysis

    Dusting attacks send tiny 'dust' amounts to target addresses, then track when victims consolidate funds to de-anonymize wallet clusters.

  3. Which risk specifically arises from using a deterministic wallet (BIP-32 HD wallet) where the master seed is compromised?

    Answer: All child private keys derived from that seed are compromised simultaneously

    In HD wallets, all child keys are mathematically derived from the master seed, so seed compromise exposes every derived key across all accounts.

  4. An exchange's risk assessment identifies that a key withdrawal approval system has no rate limiting. Which control weakness category does this best represent?

    Answer: Insufficient access control — missing transaction velocity controls

    Absence of rate limiting on withdrawals is an access control weakness that enables automated draining of funds if an account is compromised.

  5. What does 'time-of-check to time-of-use' (TOCTOU) represent as a smart contract vulnerability?

    Answer: A race condition where blockchain state changes between validation and execution steps

    TOCTOU vulnerabilities occur when a contract checks a condition and then acts on it, but blockchain state changes between those two operations.

  6. In evaluating an exchange's risk exposure, which scenario best exemplifies 'counterparty risk' specific to cryptocurrency markets?

    Answer: An exchange holding user funds becoming insolvent and unable to fulfill withdrawals

    Counterparty risk is the risk that the exchange itself fails to fulfill its obligations, such as FTX's inability to process customer withdrawals due to insolvency.

  7. Which FATF recommendation specifically requires cryptocurrency exchanges to collect and transmit originator and beneficiary information for virtual asset transfers?

    Answer: FATF Recommendation 16 (Travel Rule)

    FATF Recommendation 16, the Travel Rule, requires VASPs to share sender and recipient information for crypto transfers above the threshold.