
EC-CouncilBlockchain Fintech Certification
Domain 8Objective 3
Mitigating Blockchain Attacks and Security Practices BFC Practice Questions (Page 5)
Part of the Governance, Compliance, and Risk Management domain, which makes up ~12% of our current practice bank.
48questions here
10free pages
8concepts
Questions 21–25
- 21
A financial institution uses a blockchain to record transactions and must comply with anti-money laundering (AML) regulations that require transaction monitoring. They want to ensure that transaction data is tamper-evident while allowing authorized auditors to read the data. Which combination of practices best meets these needs?
Select an answer first - 22
A security audit of a smart contract reveals that a function uses `msg.sender` to authorize administrative actions. The auditor recommends changing to a multi-signature wallet. What vulnerability is the auditor most likely trying to mitigate?
Select an answer first - 23
In a blockchain network, an attacker creates numerous fake nodes to gain disproportionate influence in peer-to-peer communication. Which attack vector is this?
Select an answer first - 24
A blockchain-based payment startup must comply with GDPR when storing customer transaction data. The CTO wants to use a public blockchain for immutability but needs to ensure personal data can be erased upon request. Which approach best satisfies both requirements?
Select an answer first - 25
A financial institution is deploying a blockchain-based settlement system. Regulatory auditors require that private keys be protected against both internal theft and external compromise, and that all key-related activities be logged for audit. Which solution best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “BFC” is a trademark of its owner, used for identification only.