Security & Risk Analysis Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Risk Analysis flashcards as text
During a cryptocurrency custody audit, an auditor finds that signing keys are generated on an internet-connected machine before being moved to a hardware security module (HSM). What risk does this introduce?
Answer: The private key may have been exposed or exfiltrated during internet-connected generation
Generating keys on an internet-connected machine before HSM import exposes the key to malware or network exfiltration during the most vulnerable phase.
What is a 'dusting attack' in the context of cryptocurrency security?
Answer: Sending minimal amounts of crypto to wallets to trace ownership through subsequent transaction analysis
Dusting attacks send tiny 'dust' amounts to target addresses, then track when victims consolidate funds to de-anonymize wallet clusters.
Which risk specifically arises from using a deterministic wallet (BIP-32 HD wallet) where the master seed is compromised?
Answer: All child private keys derived from that seed are compromised simultaneously
In HD wallets, all child keys are mathematically derived from the master seed, so seed compromise exposes every derived key across all accounts.
An exchange's risk assessment identifies that a key withdrawal approval system has no rate limiting. Which control weakness category does this best represent?
Answer: Insufficient access control — missing transaction velocity controls
Absence of rate limiting on withdrawals is an access control weakness that enables automated draining of funds if an account is compromised.
What does 'time-of-check to time-of-use' (TOCTOU) represent as a smart contract vulnerability?
Answer: A race condition where blockchain state changes between validation and execution steps
TOCTOU vulnerabilities occur when a contract checks a condition and then acts on it, but blockchain state changes between those two operations.
In evaluating an exchange's risk exposure, which scenario best exemplifies 'counterparty risk' specific to cryptocurrency markets?
Answer: An exchange holding user funds becoming insolvent and unable to fulfill withdrawals
Counterparty risk is the risk that the exchange itself fails to fulfill its obligations, such as FTX's inability to process customer withdrawals due to insolvency.
Which FATF recommendation specifically requires cryptocurrency exchanges to collect and transmit originator and beneficiary information for virtual asset transfers?
Answer: FATF Recommendation 16 (Travel Rule)
FATF Recommendation 16, the Travel Rule, requires VASPs to share sender and recipient information for crypto transfers above the threshold.