Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilBlockchain Developer Certification

Domain 7Objective 1

Attack Surfaces in Blockchain Ecosystems BDC Practice Questions (Page 9)

Part of the Blockchain Security and DeFi Development domain, which makes up ~11% of our current practice bank.

47questions here
10free pages
7concepts

Questions 41–45

  1. 41expert · hard

    A DeFi protocol uses a price oracle that reads from a single DEX pool. An attacker uses a flash loan to manipulate the pool's price, causing the protocol to allow undercollateralized loans. The attacker then borrows a large amount of another asset and repays the flash loan, leaving the protocol with bad debt. Which combination of mitigations would be MOST effective?

    Select an answer first
  2. 42expert · hard

    A blockchain project's core developers are targeted by a social engineering campaign. An attacker poses as a contributor and sends a malicious link to a developer, claiming it contains a proposal document. The developer clicks the link, which installs malware that steals their private key for the project's GitHub account. The attacker then pushes a malicious code change to the smart contract repository. Which combination of attacks is being used?

    Select an answer first
  3. 43application · medium

    A user's hardware wallet is lost. The user had written down the recovery seed phrase on a piece of paper and stored it in a safe. However, the user also took a photo of the seed phrase and stored it in their cloud drive. What is the most significant risk?

    Select an answer first
  4. 44application · medium

    A smart contract uses a variable to track the total supply of a token. The contract allows users to mint tokens by calling a function that increments the total supply. An attacker discovers that by calling the mint function with a very large value, the total supply wraps around to a small number, allowing them to mint an excessive amount. Which vulnerability is this, and what is the MOST direct fix?

    Select an answer first
  5. 45application · medium

    A user receives an email that appears to be from a popular wallet provider, warning of a 'suspicious login' and asking the user to click a link to 'verify their recovery phrase'. The link leads to a fake website that looks identical to the real wallet site. The user enters their recovery phrase and later finds their funds stolen. Which attack vector was used, and what is the MOST effective prevention?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “BDC” is a trademark of its owner, used for identification only.