Security & Risk Analysis Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Risk Analysis flashcards as text
A CCA auditor reviewing a DeFi lending protocol finds that liquidation thresholds are calculated using a single on-chain DEX price. What is the primary risk this creates?
Answer: Price oracle manipulation enabling unfair liquidations or under-collateralization
Single-source on-chain price oracles can be manipulated with large trades or flash loans, triggering artificial liquidations or masking undercollateralized positions.
What is the key difference between a 'hot wallet' and a 'warm wallet' in cryptocurrency exchange security architecture?
Answer: Hot wallets are fully online with automated signing; warm wallets require manual human approval but remain partially connected
Warm wallets occupy a middle tier — keys are semi-offline and withdrawals require human authorization, unlike fully automated hot wallets.
Which on-chain indicator would most clearly signal potential wash trading activity on a centralized exchange during an audit?
Answer: Simultaneous buy and sell orders between addresses linked to the same entity
Wash trading is evidenced by the same entity simultaneously buying and selling to create artificial volume, identifiable through blockchain address clustering.
When assessing smart contract risk, what does 'unbounded loop' refer to and why is it a security concern?
Answer: A loop iterating over a dynamic array that can grow large enough to exceed the block gas limit
Unbounded loops over user-controlled arrays can hit block gas limits, permanently bricking contract functions that must process all elements.
In cryptocurrency risk management, what does 'regulatory risk' encompass that distinguishes it from other operational risks?
Answer: Risk that changes in laws or enforcement actions render current business practices non-compliant or illegal
Regulatory risk includes jurisdictional changes, new licensing requirements, or enforcement actions that can restrict or shut down cryptocurrency operations.
An auditor examines a multisig wallet requiring 2-of-3 signatures where all three keys are held by employees in the same office. Which residual risk remains despite the multisig arrangement?
Answer: Physical co-location risk — a single physical incident or insider collusion can compromise all keys simultaneously
Geographic co-location of all key holders means a fire, raid, or collusion by office-based insiders defeats the multisig's intended protection.
What is the purpose of a 'cryptographic time-lock' in smart contract security, particularly in DeFi governance?
Answer: To enforce a mandatory delay between passing a governance proposal and executing it, allowing users to exit before changes take effect
Timelocks give users advance notice of approved protocol changes, allowing them to withdraw funds before potentially harmful upgrades are enacted.