
EC-CouncilBlockchain Developer Certification
Domain 7Objective 1
Attack Surfaces in Blockchain Ecosystems BDC Practice Questions (Page 7)
Part of the Blockchain Security and DeFi Development domain, which makes up ~11% of our current practice bank.
47questions here
10free pages
7concepts
Questions 31–35
- 31
What is oracle manipulation in a DeFi protocol?
Select an answer first - 32
A smart contract allows users to deposit tokens and then call a withdraw function that sends tokens to the caller. The contract updates the user's balance only after the external transfer. An attacker creates a malicious contract that re-enters the withdraw function before the balance is updated. Which vulnerability is being exploited, and what is the MOST direct fix?
Select an answer first - 33
A smart contract allows users to set a `uint8` variable to any value they choose. An attacker sets the value to 255 and then adds 1 to it. The contract does not check for overflow. What is the result?
Select an answer first - 34
A small proof-of-work blockchain network has a hash rate of 100 TH/s. A mining pool controls 45% of the network's hash rate. The network's difficulty adjustment is slow, and the block reward is significant. The pool's operators are considering an attack to increase profits. Which attack is most feasible and profitable given these conditions?
Select an answer first - 35
A user stores their private keys in a plain text file on their computer. They also use the same computer to browse the internet and download software. One day, they notice unauthorized transactions from their wallet. Which threat is MOST likely the cause, and what is a better practice?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “BDC” is a trademark of its owner, used for identification only.