Certified Blockchain Expert (CBE) — Questions and Answers
Question 1: A malicious actor gains control of 52% of the total hashing power on a Proof of Work (PoW) network. Which of the following actions can this actor successfully perform?
- Prevent specific new transactions from being confirmed and potentially reverse their own recent transactions. (Correct answer)
- Change the fundamental consensus rules of the blockchain, such as the block reward amount.
- Create new coins out of thin air, exceeding the protocol's supply limit.
- Steal cryptocurrency directly from another user's wallet.
Correct answer: Prevent specific new transactions from being confirmed and potentially reverse their own recent transactions.
A 51% attack on a PoW network gives the attacker control over the block creation process. This allows them to censor transactions by refusing to include them in their blocks and to perform a 'double-spend' by creating a secret longer chain where they reverse their own transactions and then broadcasting it to the network. However, they cannot steal funds from addresses they don't own the private keys to, change the core protocol rules, or create coins outside of the established block reward system.
Question 2: A consortium of private companies wants to establish a blockchain for supply chain management. They require high transaction throughput, low latency, and a mechanism where block producers are known and trusted entities. Which consensus mechanism is most suitable for this scenario?
- Proof of Authority (PoA) (Correct answer)
- Proof of Work (PoW)
- Proof of Stake (PoS)
- Proof of Burn (PoB)
Correct answer: Proof of Authority (PoA)
Proof of Authority (PoA) is ideal for private or consortium blockchains where participants are known and trusted. In PoA, validators are pre-approved entities who stake their reputation, not computational power or coins. This results in high throughput and efficiency, which is perfect for enterprise use cases like supply chain management where performance and accountability are key.
Question 3: A supply chain consortium wants to build a blockchain solution to track goods from manufacturer to retailer. They need to ensure that only authorized participants can view and add transactions. Which type of blockchain would be most suitable for this scenario?
- Permissioned (Private) Blockchain (Correct answer)
- Hybrid Blockchain
- Sidechain
- Public Blockchain
Correct answer: Permissioned (Private) Blockchain
A permissioned or private blockchain is the most suitable choice because it restricts access to a specific group of authorized participants. This allows the consortium to maintain confidentiality and control over who can interact with the supply chain data, which is a common requirement for enterprise-level applications.
Question 4: What is a 'multisig wallet' smart contract, and what problem does it solve?
- A contract that splits ETH equally among multiple recipients atomically
- A wallet that batches transactions to save gas by combining many senders
- A contract requiring M-of-N key holders to approve a transaction before execution (Correct answer)
- A wallet that automatically signs transactions using zero-knowledge proofs
Correct answer: A contract requiring M-of-N key holders to approve a transaction before execution
A multisig wallet requires a threshold number of predefined signatories to co-sign transactions, eliminating single-point-of-failure risk for high-value funds.
Question 5: What is a 'time lock' contract, and why do DeFi protocols use them?
- A contract that batches hourly transactions to save gas
- A contract that enforces a mandatory delay between proposing and executing governance changes (Correct answer)
- A contract that locks tokens based on the current ETH price
- A contract that pays staking rewards only at fixed calendar dates
Correct answer: A contract that enforces a mandatory delay between proposing and executing governance changes
Time locks impose a waiting period (e.g., 48 hours) on admin actions, giving users time to react and exit before potentially harmful changes take effect.
Question 6: In blockchain security, what is an 'eclipse attack'?
- Hiding malicious code inside smart contract bytecode
- Intercepting a node's network connections so it only communicates with attacker-controlled peers (Correct answer)
- Overwhelming a network with encrypted garbage data
- Blocking light from reaching solar-powered mining farms
Correct answer: Intercepting a node's network connections so it only communicates with attacker-controlled peers
An eclipse attack isolates a node by controlling all its peer connections, feeding it false information about the blockchain state.
Question 7: What does 'APY' represent in DeFi yield products?
- Automated Payment Yield from staking rewards
- Annual Percentage Yield, which includes the effect of compounding interest (Correct answer)
- Average Protocol Yield
- Asset Price Yield, the token price appreciation over a year
Correct answer: Annual Percentage Yield, which includes the effect of compounding interest
APY (Annual Percentage Yield) represents the real rate of return on an investment over one year, including the compounding of interest or rewards.
Question 8: What does ERC-721 define, and how does it differ from ERC-20?
- ERC-721 defines Layer 2 bridging; ERC-20 defines Layer 1 token wrapping
- ERC-721 defines governance voting tokens; ERC-20 defines stablecoins only
- ERC-721 defines non-fungible tokens where each token has a unique ID; ERC-20 defines fungible tokens (Correct answer)
- ERC-721 defines multi-token batches; ERC-20 defines single-token standards
Correct answer: ERC-721 defines non-fungible tokens where each token has a unique ID; ERC-20 defines fungible tokens
ERC-721 tokens are non-fungible — each has a unique tokenId and is not interchangeable — whereas ERC-20 tokens are identical and interchangeable units.
Question 9: In DeFi, what is an 'AMM' (Automated Market Maker)?
- A DAO governance module that manages token supply
- A protocol that prices assets using liquidity pool formulas instead of order books (Correct answer)
- A centralized order book managed by a smart contract
- A hardware oracle that feeds real-world prices on-chain
Correct answer: A protocol that prices assets using liquidity pool formulas instead of order books
AMMs like Uniswap use mathematical formulas (e.g., x*y=k) with liquidity pools to determine asset prices and enable permissionless token swaps.
Question 10: In the context of decentralized storage, how does blockchain enhance data resilience compared to centralized cloud storage?
- By storing all files on a single high-performance server
- By compressing files to zero bytes on-chain
- By distributing encrypted file shards across many nodes so no single point of failure exists (Correct answer)
- By requiring government approval for file uploads
Correct answer: By distributing encrypted file shards across many nodes so no single point of failure exists
Networks like Filecoin or Storj split and distribute encrypted data shards so the network remains functional even if many nodes go offline.
Question 11: What problem does the Lightning Network solve for Bitcoin?
- It adds smart contract functionality to Bitcoin
- It enables fast, low-cost off-chain payments through bidirectional payment channels (Correct answer)
- It reduces Bitcoin's mining difficulty
- It increases Bitcoin's block size to 10MB
Correct answer: It enables fast, low-cost off-chain payments through bidirectional payment channels
The Lightning Network creates bidirectional payment channels between users so that multiple transactions can occur off-chain, settling only the final balance on Bitcoin's blockchain.
Question 12: What is 'wash trading' in the context of NFT marketplaces and why is it harmful?
- Duplicating NFT metadata across multiple platforms to claim royalties multiple times
- Minting identical NFTs on competing chains to confuse buyers about authenticity
- Using bots to flood NFT listings with fake offers that are withdrawn before settlement
- Buying and selling NFTs to oneself or colluders to artificially inflate perceived trading volume and prices (Correct answer)
Correct answer: Buying and selling NFTs to oneself or colluders to artificially inflate perceived trading volume and prices
Wash trading creates false price discovery and misleads buyers about an NFT's value, potentially constituting market manipulation and defrauding investors.
Question 13: What is the role of an 'event' in a Solidity smart contract?
- To call external contracts asynchronously
- To enforce access control on functions
- To log data cheaply that off-chain clients can subscribe to (Correct answer)
- To trigger automatic token mints
Correct answer: To log data cheaply that off-chain clients can subscribe to
Events write data to transaction logs, which are cheaper than storage and can be monitored by off-chain applications via Web3 subscriptions.
Question 14: Which blockchain network type is most vulnerable to a 51% attack?
- Small public proof-of-work blockchain with low hash rate (Correct answer)
- Permissioned blockchain with PoA consensus
- Private blockchain with a trusted administrator
- Consortium blockchain with 10 members
Correct answer: Small public proof-of-work blockchain with low hash rate
Small public PoW blockchains with low hash rates are most vulnerable because an attacker can more easily acquire majority hash power.
Question 15: What is 'cross-chain atomic swap' technology?
- A method to merge two separate blockchains into one
- A trustless exchange of cryptocurrencies between different blockchains without a centralized intermediary (Correct answer)
- A smart contract upgrade mechanism that works across EVM chains
- A consensus mechanism shared across multiple chains
Correct answer: A trustless exchange of cryptocurrencies between different blockchains without a centralized intermediary
Atomic swaps use Hashed Timelock Contracts (HTLCs) to ensure that a cross-chain trade either fully completes on both chains or is entirely refunded, eliminating counterparty risk.
Question 16: When a node on a blockchain network receives a new transaction, it uses the sender's public key to perform a critical cryptographic operation. What is the purpose of this operation?
- To verify the digital signature attached to the transaction. (Correct answer)
- To encrypt the transaction so no one else can see the details.
- To generate a new private key for the sender for future transactions.
- To determine the sender's remaining account balance.
Correct answer: To verify the digital signature attached to the transaction.
The sender signs a transaction with their private key, creating a digital signature. When other nodes receive the transaction, they use the sender's publicly available key to verify that the signature is valid. This process confirms the authenticity and integrity of the transaction, proving it was authorized by the rightful owner and has not been altered.
Question 17: Which property of a cryptographic hash function ensures that two different inputs cannot produce the same output?
- Avalanche effect
- Determinism
- Collision resistance (Correct answer)
- Pre-image resistance
Correct answer: Collision resistance
Collision resistance means it is computationally infeasible to find two distinct inputs that hash to the same digest.
Question 18: What is a 'selfish mining' attack in blockchain networks?
- A miner submits fraudulent transactions to steal fees
- A miner refuses to validate transactions from competitors
- A miner hoards discovered blocks and releases them strategically to waste honest miners' work (Correct answer)
- A miner creates fake identities to claim multiple block rewards
Correct answer: A miner hoards discovered blocks and releases them strategically to waste honest miners' work
Selfish mining withholds blocks to make honest miners waste effort on orphaned chains, giving the attacker a disproportionate share of rewards.
Question 19: The Practical Byzantine Fault Tolerance (PBFT) consensus mechanism is known for providing high performance and low-latency transaction finality. What is its primary limitation, making it less suitable for large, open, permissionless blockchains?
- Its performance degrades significantly as the number of nodes increases due to high communication overhead. (Correct answer)
- High energy consumption due to complex computations.
- The requirement for all nodes to stake a large amount of cryptocurrency.
- Slow block confirmation times, often taking several minutes.
Correct answer: Its performance degrades significantly as the number of nodes increases due to high communication overhead.
Practical Byzantine Fault Tolerance (PBFT) requires a high volume of messages to be sent between nodes to reach consensus. The communication complexity is O(n^2), meaning the number of messages grows exponentially with the number of nodes (n). This makes it inefficient and unscalable for large, public networks like Bitcoin or Ethereum but very effective for smaller, permissioned systems where the number of validators is known and limited.
Question 20: Which Ethereum upgrade mechanism is exploited in an 'upgrade proxy attack'?
- Attackers exploit the beacon chain upgrade path to double-spend ETH
- Attackers exploit the EIP upgrade process to insert backdoors in the base protocol
- Attackers compromise the admin key of an upgradeable proxy contract to replace the logic contract with malicious code (Correct answer)
- Attackers submit fake governance votes to trigger unauthorized protocol upgrades
Correct answer: Attackers compromise the admin key of an upgradeable proxy contract to replace the logic contract with malicious code
Upgradeable proxy contracts delegate calls to a logic contract; if the admin key is compromised, attackers can swap in a malicious implementation.
Question 21: Which of the following is a primary characteristic of the Delegated Proof of Stake (DPoS) consensus mechanism?
- Validators are chosen based on the age of their staked coins.
- Miners compete to solve complex computational puzzles.
- All token holders directly participate in validating blocks.
- Token holders vote to elect a limited number of block producers. (Correct answer)
Correct answer: Token holders vote to elect a limited number of block producers.
In Delegated Proof of Stake (DPoS), token holders use their stake to vote for a limited number of 'delegates' or 'witnesses'. These elected officials are then responsible for validating transactions and producing blocks. This system is designed to be more efficient and faster than traditional Proof of Stake.
Question 22: What is the main distinction between a blockchain and a blockless solution?
- Transactions are not verified by the entire network in a blockless environment (Correct answer)
- Blockless solutions are slower
- Blockless solutions are less reliable
- Blockless solutions do not work on mobile devices
Correct answer: Transactions are not verified by the entire network in a blockless environment
The correct answer: <br> Transactions are not verified by the entire network in a blockless environment
Question 23: What distinguishes a consortium blockchain from a private blockchain?
- Consortium blockchains are governed by multiple organizations (Correct answer)
- Consortium blockchains are open to the public
- Private blockchains are faster
- Private blockchains use more nodes
Correct answer: Consortium blockchains are governed by multiple organizations
A consortium blockchain is governed by a group of organizations, while a private blockchain is controlled by a single entity.
Question 24: In the context of blockchain, what does 'finality' mean?
- The point at which a confirmed transaction cannot be reversed (Correct answer)
- The maximum number of transactions per block
- The process of retiring old blockchain addresses
- The time required to generate a new block
Correct answer: The point at which a confirmed transaction cannot be reversed
Finality refers to the guarantee that a committed transaction is irreversible and permanently settled on the blockchain.
Question 25: What is a 'shard' in the context of blockchain scalability?
- A partition of the network that processes transactions in parallel (Correct answer)
- A smart contract storage unit
- A hardware wallet component
- A type of cryptographic key
Correct answer: A partition of the network that processes transactions in parallel
Sharding divides the blockchain network into smaller partitions called shards, each capable of processing transactions independently to improve throughput.
Question 26: What does the ERC-20 standard primarily define?
- The Ethereum consensus mechanism specification
- A common interface for fungible tokens on Ethereum (Correct answer)
- A standard for cross-chain atomic swaps
- Rules for non-fungible tokens on Ethereum
Correct answer: A common interface for fungible tokens on Ethereum
ERC-20 defines a standard interface (functions like transfer, approve, allowance) for fungible tokens so wallets and exchanges can interact with any compliant token uniformly.
Question 27: Which cryptographic weakness made early Bitcoin brain wallets (password-derived keys) vulnerable to theft?
- Bitcoin's elliptic curve allowed recovery of the private key from two signed messages with the same nonce
- Low-entropy passwords could be brute-forced offline since the public address alone revealed which hash function to attack (Correct answer)
- Brain wallets leaked passwords through timing side-channels in the key derivation function
- SHA-256 collisions allowed attackers to find alternative passwords producing the same private key
Correct answer: Low-entropy passwords could be brute-forced offline since the public address alone revealed which hash function to attack
Brain wallets hash a password to derive a private key; weak passwords are trivially brute-forced against all known Bitcoin addresses using GPU clusters.
Question 28: What happens if two blocks are confirmed simultaneously?
- The blocks are broken up into two chains. Each chain is then extended by adding blocks until it reaches its maximum length. The Blockchain is therefore defined as the longest chain.
- Both chains are removed from the pool, and the unconfirmed transactions are re-added.
- The Orderer Block verifies which block has the most transactions confirmed.
- Which block is added to the Blockchain is decided by the nodes. (Correct answer)
Correct answer: Which block is added to the Blockchain is decided by the nodes.
Explanation: <br> The chain will split if more than one block is validated at the same time. In other words, each node in a blockchain keeps a copy of the database. Let's pretend that two blocks, A and B, were certified at the same moment. After both blocks have been validated, some nodes will receive A first, while others will receive B first.
Question 29: Which Solidity keyword prevents a function from modifying contract state?
- view (Correct answer)
- payable
- pure
- internal
Correct answer: view
'view' functions can read state but cannot modify it, while 'pure' functions cannot read or modify state at all.
Question 30: User identity on a blockchain can be unique and safe in its most basic form:
- Through cryptographic hashing (Correct answer)
- User identity cannot yet be protected on blockchain systems
- By users utilizing permissioned blockchains
- By users utilizing public blockchains
Correct answer: Through cryptographic hashing
Explanation: <br> A cryptographic hash function (CHF) is a mathematical procedure that converts data of any size (commonly referred to as the "message") into a fixed-size bit array (the "hash value", "hash", or "message digest"). It's a one-way function, which means it's almost impossible to invert.
Question 31: Which characteristic makes consortium blockchains particularly attractive for trade finance applications?
- They offer unlimited transaction throughput
- They eliminate the need for KYC compliance
- They allow anonymous transactions for privacy
- They enable multiple competing banks to share a trusted ledger without a central intermediary (Correct answer)
Correct answer: They enable multiple competing banks to share a trusted ledger without a central intermediary
Consortium blockchains let competing financial institutions collaborate on a shared ledger while sharing governance and eliminating single-point intermediaries.
Question 32: In Solidity, what is the difference between 'memory' and 'storage' data locations?
- storage is only readable; memory is only writable
- storage is persistent on-chain; memory is temporary and cleared after each call (Correct answer)
- memory holds contract ETH balance; storage holds token balances
- memory is persistent across transactions; storage is temporary
Correct answer: storage is persistent on-chain; memory is temporary and cleared after each call
storage variables persist permanently on the blockchain while memory variables exist only for the duration of a function call and are discarded afterward.
Question 33: What is 'front-running' in the context of blockchain transaction ordering?
- Adding transactions to a block before verifying their signatures
- Observing a pending transaction in the mempool and submitting a competing one with higher gas to be processed first (Correct answer)
- Mining empty blocks to delay competitors' transactions
- Broadcasting a transaction on multiple chains simultaneously
Correct answer: Observing a pending transaction in the mempool and submitting a competing one with higher gas to be processed first
Front-running exploits the public mempool by inserting a transaction with higher gas fees ahead of a target transaction to capture arbitrage or MEV profits.
Question 34: A developer is creating a decentralized autonomous organization (DAO) where token holders can vote on proposals. The smart contract automatically tallies votes and executes the winning proposal if a quorum is met. What fundamental property of smart contracts ensures this process will execute exactly as programmed without manual intervention?
- Self-Execution (Correct answer)
- Interoperability
- Scalability
- Anonymity
Correct answer: Self-Execution
Self-execution is the core principle that smart contracts are programs that automatically run when predetermined conditions are met. The terms of the agreement (the DAO's voting rules) are written directly into code, and the contract will enforce those rules (tallying votes, executing proposals) without the need for a traditional intermediary.
Question 35: What is 'slippage' in DeFi trading?
- The gas fee reduction for large trades
- The penalty for withdrawing from a liquidity pool early
- The difference between the expected price and the actual execution price of a trade (Correct answer)
- The delay between submitting and confirming a transaction
Correct answer: The difference between the expected price and the actual execution price of a trade
Slippage is the difference between the expected price of a trade and the actual price at execution, often caused by low liquidity or large trade sizes moving the pool's price.
Question 36: Which technique do attackers use in a 'sandwich attack' on decentralized exchanges?
- Intercept messages between two nodes and alter transaction data
- Insert malicious code between two legitimate smart contract calls
- Place a buy order before and a sell order after a victim's large trade to profit from price impact (Correct answer)
- Create two fraudulent blocks surrounding a valid block to trigger a reorg
Correct answer: Place a buy order before and a sell order after a victim's large trade to profit from price impact
A sandwich attack front-runs a victim's trade to push the price up, then back-runs it to sell at a profit, exploiting the victim's price slippage.
Question 37: How does a 'BGP hijacking' attack threaten Bitcoin mining pools?
- Exploiting the Bitcoin Gossip Protocol to inject false peer announcements
- Rerouting internet traffic to intercept pool communications, allowing attackers to steal hashrate or delay block propagation (Correct answer)
- Using BGP routing to prioritize attacker blocks over honest miner blocks
- Poisoning DNS cache entries for mining pool hostnames via BGP communities
Correct answer: Rerouting internet traffic to intercept pool communications, allowing attackers to steal hashrate or delay block propagation
BGP hijacking can redirect mining pool traffic through attacker-controlled routers, enabling hashrate theft, block withholding, or network partitioning.
Question 38: How do SPV (Simplified Payment Verification) clients verify transactions without downloading the full blockchain?
- By downloading only block headers and using Merkle proofs to verify inclusion (Correct answer)
- By trusting a central server's transaction records
- By requesting full blocks only when sending transactions
- By storing only the UTXO set without transaction history
Correct answer: By downloading only block headers and using Merkle proofs to verify inclusion
SPV clients download block headers and verify that a transaction is included in a block using its Merkle proof path.
Question 39: In blockchain networks, what is the purpose of a mempool (memory pool)?
- A database storing all finalized blocks permanently
- A caching layer that stores frequently accessed wallet balances
- A pool of staked tokens used for validator selection
- A temporary holding area where unconfirmed transactions wait to be selected by miners into a block (Correct answer)
Correct answer: A temporary holding area where unconfirmed transactions wait to be selected by miners into a block
The mempool is each node's local queue of broadcast but unconfirmed transactions awaiting inclusion in the next block.
Question 40: What is the purpose of a Merkle tree in blockchain architecture?
- To efficiently and securely verify the inclusion of transactions within a block (Correct answer)
- To manage smart contract state variables
- To encrypt private keys for wallet security
- To calculate mining difficulty adjustments
Correct answer: To efficiently and securely verify the inclusion of transactions within a block
A Merkle tree hashes transactions pairwise up to a root hash (Merkle root), stored in the block header, enabling efficient proof that a specific transaction is included without downloading all data.
Question 41: A key difference between Proof of Work (PoW) and Proof of Stake (PoS) lies in how they achieve Sybil resistance. How does PoS primarily prevent a Sybil attack?
- By making it economically irrational for an attacker to acquire a majority of the network's staked assets. (Correct answer)
- By requiring validators to stake their real-world identity and reputation.
- By electing a small, trusted group of validators to secure the network.
- By making computational power prohibitively expensive for an attacker.
Correct answer: By making it economically irrational for an attacker to acquire a majority of the network's staked assets.
In Proof of Stake (PoS), validators must lock up a significant amount of the network's native cryptocurrency as collateral. To launch a successful 51% attack, an attacker would need to acquire and stake more than half of the total value of all staked coins. This would be incredibly expensive, and any malicious action could lead to the loss of their staked funds ('slashing'), making such an attack economically unfeasible and irrational.
Question 42: A smart contract is designed to trigger an insurance payout for a flight delay. To function correctly, it needs to know the official landing time of a specific flight. How does a smart contract on a deterministic blockchain typically obtain this type of real-world information?
- Through a trusted external data feed service known as a blockchain oracle. (Correct answer)
- By allowing users to vote on the landing time after the fact.
- By directly querying a public flight tracking API from within the contract code.
- By using a built-in time function within the EVM to access real-world clocks.
Correct answer: Through a trusted external data feed service known as a blockchain oracle.
Blockchains and smart contracts cannot directly access off-chain data because it would break the deterministic nature required for consensus. A blockchain oracle is a necessary third-party service that acts as a bridge, fetching and verifying real-world data (like flight times or asset prices) and relaying it to the smart contract in a secure and reliable way.
Question 43: In a Directed Acyclic Graph (DAG) based blockchain architecture like IOTA, how are transactions confirmed?
- By smart contracts running consensus algorithms automatically
- By each new transaction validating two previous transactions, creating a web-like structure instead of a chain (Correct answer)
- By a single committee of elected validators per epoch
- By miners competing to solve hash puzzles in linear blocks
Correct answer: By each new transaction validating two previous transactions, creating a web-like structure instead of a chain
In DAG architectures like IOTA's Tangle, users must validate two prior transactions when submitting their own, creating a mesh of confirmations rather than a linear chain of blocks.
Question 44: What is 'block propagation' and why does its speed matter in blockchain networks?
- The method by which nodes archive old blocks
- The time it takes for a newly mined block to reach all nodes, affecting orphan block rates (Correct answer)
- The validation process for block headers
- The process of encrypting a block before broadcasting
Correct answer: The time it takes for a newly mined block to reach all nodes, affecting orphan block rates
Slow block propagation increases the chance of competing miners producing orphan blocks simultaneously, wasting computational resources.
Question 45: An attacker wants to isolate a single, specific node from the rest of the blockchain network. They do this by monopolizing all of the target node's incoming and outgoing peer connections with nodes they control. This allows the attacker to feed the victim false transaction data and a counterfeit view of the blockchain. Which network-level attack is being described?
- Denial-of-Service Attack
- Forking Attack
- Sybil Attack
- Eclipse Attack (Correct answer)
Correct answer: Eclipse Attack
An eclipse attack is a targeted network-level attack where a malicious actor takes control of all of a victim node's peer connections, effectively isolating it from the honest network. This 'eclipses' the node's view of the real blockchain, making it vulnerable to deception, such as accepting double-spent transactions.
Question 46: In Hyperledger Fabric, what is the role of the 'orderer' node?
- To validate node permissions on the network
- To establish consensus by ordering transactions into blocks (Correct answer)
- To store user identity certificates
- To execute chaincode (smart contracts)
Correct answer: To establish consensus by ordering transactions into blocks
The orderer service in Hyperledger Fabric is responsible for collecting transactions, ordering them, and packaging them into blocks for distribution.
Question 47: Which dApp architecture pattern uses IPFS or Arweave for storing large data off-chain?
- On-chain maximalist
- Oracle bridge pattern
- Hybrid storage pattern (Correct answer)
- Layer-2 rollup pattern
Correct answer: Hybrid storage pattern
The hybrid storage pattern stores large or mutable data on decentralized file systems (IPFS/Arweave) while anchoring only content hashes on-chain.
Question 48: What is the 'long-range attack' threat specific to Proof-of-Stake blockchains?
- An attacker gradually increases network latency to isolate validators
- An attacker sustains a 51% attack for an extended period
- An attacker mines blocks over long distances using satellite relays
- An attacker uses old private keys from past validators to rewrite blockchain history from a distant point (Correct answer)
Correct answer: An attacker uses old private keys from past validators to rewrite blockchain history from a distant point
Long-range attacks use old validator keys (when stake was cheaper) to create an alternative chain from far in the past, which PoS systems mitigate with checkpointing.
Question 49: A smart contract has a `withdraw` function where the code first sends Ether to the user's address and then updates the user's balance in the contract's storage. Which classic smart contract vulnerability does this specific order of operations create?
- Denial of Service (DoS)
- Timestamp Dependence
- Integer Overflow
- Reentrancy Attack (Correct answer)
Correct answer: Reentrancy Attack
This sequence creates a reentrancy vulnerability. A malicious contract can exploit this by implementing a fallback function that recursively calls the `withdraw` function *after* receiving the Ether but *before* the original call updates the balance. This allows the attacker to drain the contract's funds. The secure pattern is Checks-Effects-Interactions: update the balance first, then send the Ether.
Question 50: Which hash function does Bitcoin use to produce a 256-bit block hash in Proof of Work?
- SHA-256 applied twice (SHA-256d) (Correct answer)
- SHA-3
- Keccak-512
- RIPEMD-160
Correct answer: SHA-256 applied twice (SHA-256d)
Bitcoin applies SHA-256 twice to block headers (SHA-256d) to produce the block hash used in Proof of Work difficulty comparison.
Question 51: In DeFi, what is a 'flash loan' and what makes it unique compared to traditional loans?
- A micro-loan capped at $1,000 disbursed instantly via Layer 2
- A loan secured by NFTs that settles in under one minute on-chain
- A loan with a fixed 0% APR offered by central banks to DeFi protocols
- An uncollateralized loan that must be borrowed and repaid within a single transaction (Correct answer)
Correct answer: An uncollateralized loan that must be borrowed and repaid within a single transaction
Flash loans are uncollateralized because the smart contract enforces that the borrowed funds plus fee must be returned before the transaction finalizes, reverting everything if not.
Question 52: In a digital signature scheme, what is verified using the signer's public key?
- The signature produced with the signer's private key (Correct answer)
- The hash of the recipient's address
- The symmetric key used to encrypt the message
- The encrypted plaintext of the message
Correct answer: The signature produced with the signer's private key
Anyone with the signer's public key can verify that the signature was created by the corresponding private key without revealing it.
Question 53: Which consensus mechanism requires participants to demonstrate their commitment to the network by permanently destroying a certain amount of cryptocurrency?
- Proof of Stake (PoS)
- Proof of Elapsed Time
- Proof of Capacity
- Proof of Burn (PoB) (Correct answer)
Correct answer: Proof of Burn (PoB)
Proof of Burn (PoB) is a consensus mechanism where participants, often called miners or validators, intentionally send cryptocurrency to a verifiably unspendable address. This act of 'burning' coins serves as an economic sacrifice, demonstrating a long-term commitment to the network and granting the right to validate transactions and mine new blocks.
Question 54: What is the role of a 'commitment scheme' in a blockchain smart contract auction?
- Allowing bidders to commit to a hidden bid, revealed only after the bidding phase ends (Correct answer)
- Encrypting bids with the auctioneer's public key
- Hashing the auction contract address to prevent front-running
- Signing bids with ECDSA to prove identity
Correct answer: Allowing bidders to commit to a hidden bid, revealed only after the bidding phase ends
A commit-reveal scheme lets bidders submit a hash of their bid first, then reveal the actual value later, preventing other bidders from seeing bids before committing.
Question 55: What problem does the 'checks-effects-interactions' pattern solve in smart contract development?
- Integer overflow errors
- Gas optimization for loops
- Timestamp dependency attacks
- Reentrancy vulnerabilities (Correct answer)
Correct answer: Reentrancy vulnerabilities
The checks-effects-interactions pattern prevents reentrancy by updating all state (effects) before calling external contracts (interactions).
Question 56: What does 'on-chain governance' mean in a blockchain protocol?
- Governance rules hardcoded at genesis and immutable
- A system where protocol changes are proposed and voted on directly via blockchain transactions (Correct answer)
- A government agency that regulates blockchain activity
- Smart contract auditing by node operators
Correct answer: A system where protocol changes are proposed and voted on directly via blockchain transactions
On-chain governance allows token holders to submit and vote on protocol upgrade proposals directly on the blockchain, with results automatically enforced by the code.
Question 57: What is 'miner extractable value' (MEV) and why is it a security concern?
- Fees extracted from smart contracts during automated liquidations
- The computational value miners extract from solving hash puzzles during PoW
- Profits miners capture by reordering, inserting, or censoring transactions, creating unfair advantages and potential instability (Correct answer)
- Revenue validators earn from staking rewards beyond the base issuance rate
Correct answer: Profits miners capture by reordering, inserting, or censoring transactions, creating unfair advantages and potential instability
MEV allows block producers to exploit their ordering power to profit at users' expense, leading to network congestion, unfairness, and potential consensus instability.
Question 58: A smart contract function is designed to transfer a user's remaining token balance. The code is written as `balances[user] -= amount;`. If a user with a balance of 100 tokens calls this function with an `amount` of 101, and the contract is running on an older, unprotected version of Solidity, the user's balance could wrap around to a very large number. This vulnerability is known as:
- Reentrancy
- Timestamp Dependence
- Oracle Manipulation
- Integer Underflow (Correct answer)
Correct answer: Integer Underflow
Integer underflow occurs when an arithmetic operation results in a value smaller than the minimum value the data type can hold, causing it to wrap around to the maximum possible value. In this case, subtracting 101 from 100 would result in -1, which for an unsigned integer wraps around to the largest possible value, potentially allowing the user to claim an enormous balance. Modern Solidity versions (0.8.0+) have built-in checks to prevent this.
Question 59: A user stores their cryptocurrency private key in a plain text file named `wallet_key.txt` in a public GitHub repository. What is the most immediate and severe consequence of this action?
- The user's funds can be immediately and irreversibly stolen by anyone who finds the key. (Correct answer)
- The network will automatically freeze the funds associated with the key for security reasons.
- The user will receive a warning from GitHub to remove the sensitive information.
- An attacker can view the transaction history but cannot initiate new transactions.
Correct answer: The user's funds can be immediately and irreversibly stolen by anyone who finds the key.
A private key is the sole credential that proves ownership and grants the authority to spend cryptocurrency from an address. Exposing it publicly gives anyone who finds it complete and total control over the associated funds. The decentralized nature of blockchain means there is no central authority to reverse transactions or freeze funds once they have been stolen.
Question 60: A consortium of international banks plans to create a private blockchain for interbank settlements. They require high transaction throughput, low latency, and the ability to function even if some participating nodes become malicious or faulty. The participants are all known and permissioned entities. Which consensus mechanism would be most suitable for this scenario?
- Proof of Work (PoW)
- Proof of Stake (PoS)
- Delegated Proof of Stake (DPoS)
- Practical Byzantine Fault Tolerance (pBFT) (Correct answer)
Correct answer: Practical Byzantine Fault Tolerance (pBFT)
Practical Byzantine Fault Tolerance (pBFT) is well-suited for private or consortium blockchains where participants are known. It provides high throughput, low-latency finality, and is designed to tolerate a certain number of malicious (Byzantine) nodes (up to one-third). Since the banking consortium consists of permissioned entities, pBFT's efficiency and fault tolerance make it an ideal choice.
Question 61: How can blockchain improve the management of intellectual property (IP) licensing in the entertainment industry?
- By replacing copyright law with token ownership
- By recording license grants and usage rights on-chain so violations can be detected automatically (Correct answer)
- By storing entire films as NFTs on-chain
- By making all content freely available to the public
Correct answer: By recording license grants and usage rights on-chain so violations can be detected automatically
On-chain IP registries record who holds what license, and smart contracts can enforce usage terms and trigger royalty payments when conditions are met.
Question 62: A blockchain network aims to be highly energy-efficient and reduce the hardware barrier to entry for participation. However, a major criticism is that it could lead to a 'rich get richer' scenario where the wealthiest participants have the most influence. Which consensus mechanism does this describe?
- Proof of Stake (PoS) (Correct answer)
- Proof of Work (PoW)
- Proof of Burn (PoB)
- Practical Byzantine Fault Tolerance (PBFT)
Correct answer: Proof of Stake (PoS)
Proof of Stake (PoS) selects validators based on the number of tokens they hold and are willing to 'stake'. This is highly energy-efficient compared to PoW. However, a common criticism is that individuals with more tokens (the 'richest') have a higher chance of being selected to validate blocks and earn rewards, potentially leading to wealth concentration and centralization of power.
Question 63: A company wants to use blockchain for its loyalty rewards program. What key problem does this solve over traditional points systems?
- It gives unlimited points to all customers automatically
- It eliminates the need for customer purchases
- It enables points to be interoperable, tradable, or redeemable across multiple merchant partners (Correct answer)
- It removes expiration dates by law
Correct answer: It enables points to be interoperable, tradable, or redeemable across multiple merchant partners
Tokenized loyalty points on a shared blockchain can be exchanged or redeemed across partner merchants without each company maintaining separate reconciliation systems.
Question 64: In a Proof of Stake (PoS) consensus mechanism, what is the primary role of a 'validator'?
- To propose and verify new blocks of transactions after being selected based on their economic stake. (Correct answer)
- To provide storage space on their hard drives to secure the network.
- To solve complex mathematical puzzles faster than other participants.
- To vote for delegates who will then be responsible for securing the network.
Correct answer: To propose and verify new blocks of transactions after being selected based on their economic stake.
In a PoS system, validators are responsible for the core functions of maintaining the blockchain. They are chosen to create new blocks and validate transactions based on the amount of cryptocurrency they have staked as collateral. Unlike PoW miners, they do not compete by solving puzzles. Their stake acts as an incentive to act honestly, as malicious behavior can result in the loss of their staked funds (a process known as 'slashing').
Question 65: Why is Elliptic Curve Cryptography (ECC) widely preferred over RSA for generating key pairs in most modern blockchain protocols like Bitcoin and Ethereum?
- RSA is a symmetric algorithm, whereas blockchain requires asymmetric cryptography.
- ECC allows for the recovery of lost private keys, while RSA does not.
- ECC keys are easier for humans to remember and transcribe.
- ECC provides a greater level of security with significantly smaller key sizes, leading to better efficiency. (Correct answer)
Correct answer: ECC provides a greater level of security with significantly smaller key sizes, leading to better efficiency.
The primary advantage of Elliptic Curve Cryptography (ECC) is that it offers the same level of security as older algorithms like RSA but with much smaller key sizes. For example, a 256-bit ECC key provides comparable security to a 3072-bit RSA key. This efficiency is crucial for blockchain, as it reduces storage and bandwidth requirements, making the system faster and more scalable.
Question 66: Which consensus attack requires controlling more than one-third of stake in a Proof-of-Stake system?
- Finality delay or safety failure attacks requiring ≥1/3 of stake to prevent or break consensus (Correct answer)
- Double-spend attacks requiring exactly 34% of the network stake
- Sybil attacks requiring 33 separate validator identities
- Long-range attacks requiring 33% historical validator keys
Correct answer: Finality delay or safety failure attacks requiring ≥1/3 of stake to prevent or break consensus
In BFT-based PoS systems like Ethereum's Casper, controlling ≥1/3 of stake lets an attacker prevent finality or, with ≥2/3, revert finalized blocks.
Question 67: How does a 'vampire attack' work in the DeFi ecosystem?
- A bot continuously removes and re-adds liquidity to harvest yield while avoiding impermanent loss
- A smart contract siphons a percentage of all swap fees from liquidity pools without LPs noticing
- An attacker drains liquidity pools by exploiting price imbalances across multiple AMMs simultaneously
- A new protocol forks a competitor and offers superior incentives to migrate liquidity providers, draining the original protocol (Correct answer)
Correct answer: A new protocol forks a competitor and offers superior incentives to migrate liquidity providers, draining the original protocol
Vampire attacks offer outsized token rewards to poach liquidity providers from established protocols, rapidly shifting TVL and user base to the new entrant.
Question 68: In trade finance, what document is most commonly digitized on blockchain to reduce fraud?
- Employee payroll slip
- Letter of credit (Correct answer)
- Consumer credit score
- Marketing invoice
Correct answer: Letter of credit
Letters of credit are high-value documents prone to fraud; blockchain digitization creates a single, tamper-evident version visible to all parties.
Question 69: What is the primary purpose of a Key Derivation Function (KDF) like PBKDF2 in blockchain wallets?
- Validating transaction signatures
- Hashing block headers for Proof of Work
- Strengthening a user password before using it as cryptographic key material (Correct answer)
- Generating public keys from private keys
Correct answer: Strengthening a user password before using it as cryptographic key material
KDFs add computational cost (iterations, salting) to slow brute-force attacks when deriving encryption keys from user passwords.
Question 70: What is the purpose of transaction fees in a blockchain network?
- To fund the blockchain foundation's development
- To incentivize miners/validators to include transactions in blocks and prevent spam (Correct answer)
- To replace the block reward after all coins are mined
- To pay for the electricity used in verification
Correct answer: To incentivize miners/validators to include transactions in blocks and prevent spam
Transaction fees reward miners or validators for processing transactions and also deter spam by making mass frivolous transactions costly.
Question 71: A developer deploys a smart contract but soon discovers a critical bug. Due to the immutability of the blockchain, the contract code cannot be changed. Which design pattern allows developers to update contract logic while preserving the contract's address and state?
- The Singleton Pattern
- The Proxy Pattern (Correct answer)
- The Factory Pattern
- The Observer Pattern
Correct answer: The Proxy Pattern
The Proxy Pattern is the most common method for creating upgradeable smart contracts. It works by separating the contract's logic and its data storage into two separate contracts: an implementation contract (logic) and a proxy contract (storage). Users interact with the proxy contract, which delegates calls to the implementation contract. To upgrade, the proxy is simply pointed to a new implementation contract, allowing the logic to be updated while the state and address remain unchanged.
Question 72: What is 'signature malleability' and which Bitcoin transaction issue did it enable?
- Altering a signature's encoding without invalidating it, allowing third parties to change transaction IDs before confirmation (Correct answer)
- Forging digital signatures by exploiting weak elliptic curve parameters
- Extending signature length to exceed block size limits and cause transaction rejection
- Reusing the same signature across different transactions on separate chains
Correct answer: Altering a signature's encoding without invalidating it, allowing third parties to change transaction IDs before confirmation
Signature malleability let attackers tweak ECDSA signatures to produce valid but different transaction IDs (txids), complicating transaction tracking and was central to the MtGox issues.
Question 73: In Ethereum, which hashing function is used to compute the Keccak hash of transactions and state roots?
- Keccak-256 (SHA-3 variant) (Correct answer)
- BLAKE2b
- SHA-256
- RIPEMD-160
Correct answer: Keccak-256 (SHA-3 variant)
Ethereum uses Keccak-256, a variant of SHA-3, for hashing transactions, addresses, and state trie nodes.
Question 74: Which of the following describes a key difference between Proof of Stake (PoS) and Delegated Proof of Stake (DPoS)?
- In DPoS, token holders vote for a limited number of delegates to validate blocks, whereas in PoS, any user meeting the stake requirement can potentially be a validator. (Correct answer)
- PoS relies on computational puzzles, while DPoS relies on staking.
- PoS networks are immune to 51% attacks, while DPoS networks are not.
- DPoS is significantly less energy-efficient than PoS.
Correct answer: In DPoS, token holders vote for a limited number of delegates to validate blocks, whereas in PoS, any user meeting the stake requirement can potentially be a validator.
The primary distinction between PoS and DPoS is the selection process for block validators. In a typical PoS system, any participant who stakes the required amount of cryptocurrency has a chance to be selected to create a new block. In DPoS, token holders use their stake to vote for a smaller, fixed number of 'delegates' or 'witnesses' who are then responsible for block production and validation. This system is often considered more efficient and scalable but can lead to a higher degree of centralization.
Question 75: What is 'contract upgradeability' and which pattern is most commonly used to achieve it?
- Using Ethereum's built-in upgrade opcode; UPGRADECONTRACT
- Redeploying a new contract and migrating all state; direct redeployment
- Delegating calls to a swappable logic contract via a persistent proxy; the proxy pattern (Correct answer)
- Storing code on IPFS and updating the hash; content-addressed storage
Correct answer: Delegating calls to a swappable logic contract via a persistent proxy; the proxy pattern
The proxy pattern keeps a stable address and storage while delegating logic calls to an implementation contract that can be swapped, enabling upgrades without migrating state.
Question 76: What is a 'bridge exploit' and why are cross-chain bridges high-value targets?
- Compromising bridge validators by bribing them to approve fraudulent transfers
- Using bridge protocols to launder stolen funds across multiple blockchains
- Exploiting latency between blockchains to double-spend assets in transit
- Attacking smart contracts that hold large reserves of locked assets to mint unbacked tokens on the destination chain (Correct answer)
Correct answer: Attacking smart contracts that hold large reserves of locked assets to mint unbacked tokens on the destination chain
Bridges lock assets on one chain and mint wrapped tokens on another; exploiting the lock contract allows attackers to mint tokens without depositing real assets, as seen in the Ronin and Wormhole hacks.
Question 77: A DeFi protocol's smart contract has a function that (1) checks a user's balance, (2) sends them their requested funds, and then (3) updates their balance. An attacker exploits this by creating a malicious contract that, upon receiving funds, immediately calls the withdrawal function again before the original call can update the balance. This vulnerability is known as a:
- Integer Overflow Attack
- Reentrancy Attack (Correct answer)
- Timestamp Dependence Attack
- Denial of Service Attack
Correct answer: Reentrancy Attack
A Reentrancy Attack occurs when an external call is made to an untrusted contract before the original function resolves its state changes. The malicious contract can then 're-enter' the original function, repeatedly executing a part of it (like a withdrawal) before the state (like the user's balance) is updated. The famous DAO hack of 2016 was a reentrancy attack.
Question 78: What problem does a blockchain oracle solve?
- It generates random numbers for consensus selection
- It validates transactions faster than standard nodes
- It provides smart contracts with real-world external data that the blockchain cannot access natively (Correct answer)
- It predicts the price of cryptocurrencies for traders
Correct answer: It provides smart contracts with real-world external data that the blockchain cannot access natively
Oracles bridge the gap between blockchains and the external world, feeding smart contracts data like prices, weather, or sports results.
Question 79: What property of a cryptographic hash function ensures that finding two different inputs with the same hash output is computationally infeasible?
- Pre-image resistance
- Second pre-image resistance
- Avalanche effect
- Collision resistance (Correct answer)
Correct answer: Collision resistance
Collision resistance means it is computationally infeasible to find two distinct inputs that produce the same hash output.
Question 80: What is the purpose of BIP-39 mnemonic seed phrases in blockchain wallets from a cryptographic standpoint?
- They encrypt private keys using AES-256
- They store public keys as readable text for sharing
- They encode a random entropy value as human-readable words, which deterministically derive wallet keys via PBKDF2 (Correct answer)
- They hash private keys into 12 or 24 shorter keys
Correct answer: They encode a random entropy value as human-readable words, which deterministically derive wallet keys via PBKDF2
BIP-39 converts a random entropy value into a word list and uses PBKDF2-HMAC-SHA512 with the words as input to derive a master seed for HD wallet key generation.
Question 81: Which of the following best describes a 'light client' in blockchain networks?
- A client that validates only its own transactions
- A node that downloads only block headers rather than full block data (Correct answer)
- A node that only processes lightweight tokens
- A mobile wallet with minimal features
Correct answer: A node that downloads only block headers rather than full block data
A light client downloads block headers and uses Merkle proofs to verify specific transactions without storing the entire blockchain, reducing hardware requirements.
Question 82: What is the role of 'events' in Solidity smart contracts?
- They emit indexed logs stored on-chain that off-chain apps can efficiently query (Correct answer)
- They schedule future function executions at specific block heights
- They trigger external smart contract calls automatically
- They replace return values for all external function calls
Correct answer: They emit indexed logs stored on-chain that off-chain apps can efficiently query
Solidity events write log entries to the blockchain that are cheaper than storage and can be efficiently filtered by off-chain services like The Graph or ethers.js.
Question 83: Which concept describes bundling multiple smart contract interactions into one atomic transaction?
- Multi-sig approval
- Multicall (Correct answer)
- Delegate call
- Batch minting
Correct answer: Multicall
Multicall allows a single transaction to execute multiple contract calls atomically, saving gas and ensuring all-or-nothing execution.
Question 84: In elliptic curve cryptography (ECC), what is the 'discrete logarithm problem' that provides security?
- Factoring large prime numbers
- Solving quadratic residues modulo a prime
- Finding integer k given points P and Q=kP on the curve (Correct answer)
- Computing modular exponentiation efficiently
Correct answer: Finding integer k given points P and Q=kP on the curve
ECC security relies on the difficulty of finding scalar k when given curve points P and Q=kP, known as the elliptic curve discrete logarithm problem.
Question 85: In the context of Proof of Work (PoW) blockchains, what does the term 'probabilistic finality' mean?
- There is a 50/50 chance that any given transaction will be reversed.
- A transaction is considered final as soon as it is included in a block.
- The certainty of a transaction being irreversible increases as more blocks are added after it, but never reaches 100%. (Correct answer)
- The network's validators vote to finalize each block, making it irreversible.
Correct answer: The certainty of a transaction being irreversible increases as more blocks are added after it, but never reaches 100%.
Probabilistic finality, a characteristic of Nakamoto consensus (used in PoW), means that the likelihood of a transaction being reversed decreases as more blocks are built on top of the block containing it. While the probability of a reversal becomes extremely low after several confirmations (e.g., 6 blocks in Bitcoin), it never becomes an absolute certainty. This is in contrast to mechanisms like pBFT which offer absolute or deterministic finality.
Question 86: What security risk does 'tx.origin' pose compared to 'msg.sender' in Solidity?
- tx.origin is deprecated and causes contract compilation failures
- tx.origin exposes validator addresses making them targets for slashing
- tx.origin reveals the original EOA, making phishing contracts able to pass authorization checks (Correct answer)
- tx.origin leaks private key data to other contracts in the call chain
Correct answer: tx.origin reveals the original EOA, making phishing contracts able to pass authorization checks
Using tx.origin for authentication allows malicious intermediary contracts to impersonate the original caller, bypassing security checks.
Question 87: Which type of blockchain would MOST likely be used to issue and track publicly traded securities to ensure transparency for all market participants?
- Public blockchain (Correct answer)
- Private blockchain
- Consortium blockchain between two banks
- Encrypted sidechain
Correct answer: Public blockchain
Public blockchains provide full transparency for all participants, which is critical for market integrity in publicly traded securities.
Question 88: In Solidity, what is the difference between 'storage' and 'memory' variable locations?
- Storage is for mappings only; memory is for arrays only
- Storage is temporary per call; memory persists across transactions
- Storage is cheaper to read; memory is cheaper to write
- Storage persists on-chain between calls; memory is temporary within a single call (Correct answer)
Correct answer: Storage persists on-chain between calls; memory is temporary within a single call
Storage variables are permanently written to the blockchain state, while memory variables exist only during a function execution and are discarded afterward.
Question 89: How do non-fungible tokens (NFTs) extend beyond digital art into gaming use cases?
- They replace game servers with blockchain nodes
- They give players verifiable ownership of in-game assets transferable across platforms (Correct answer)
- They prevent players from trading in-game items
- They make all games free to play permanently
Correct answer: They give players verifiable ownership of in-game assets transferable across platforms
NFTs represent unique in-game items on a blockchain, letting players truly own, sell, or transfer assets outside the game publisher's control.
Question 90: A major criticism of the Proof of Work (PoW) consensus mechanism is its high energy consumption. Which of the following consensus mechanisms was primarily designed as a more energy-efficient alternative by replacing computational work with an economic stake?
- Proof of Authority (PoA)
- Delegated Proof of Stake (DPoS)
- Proof of Stake (PoS) (Correct answer)
- Proof of Burn (PoB)
Correct answer: Proof of Stake (PoS)
Proof of Stake (PoS) was developed to address the high energy consumption of PoW. Instead of requiring miners to perform energy-intensive computations, PoS selects validators to create new blocks based on the number of coins they hold and are willing to 'stake' as collateral. This method is significantly more energy-efficient.
Question 91: What is a 'length extension attack' and which hash function family is vulnerable to it?
- An attack that extends private keys; affects ECDSA
- An attack where knowing H(m) lets an attacker compute H(m||extra) without knowing m; affects SHA-1 and SHA-2 (Merkle-Damgård) (Correct answer)
- An attack on Merkle trees using extra leaf nodes; affects SHA-3 only
- An attack on RSA using extended Euclidean algorithm; affects all hash functions
Correct answer: An attack where knowing H(m) lets an attacker compute H(m||extra) without knowing m; affects SHA-1 and SHA-2 (Merkle-Damgård)
Merkle-Damgård construction (SHA-1, SHA-256) is vulnerable to length extension because the internal state after hashing m is exposed in H(m) and can be continued.
Question 92: What is 'smart contract honeypot' and how does it trap attackers?
- A fake liquidity pool that simulates high returns to lure attackers into depositing funds
- A contract that appears to have an exploitable vulnerability but contains a hidden mechanism that prevents fund withdrawal (Correct answer)
- A contract that mimics a vulnerable DAO but triggers a governance lock when exploit code is detected
- A decoy node that records attacker IPs when they attempt to broadcast invalid blocks
Correct answer: A contract that appears to have an exploitable vulnerability but contains a hidden mechanism that prevents fund withdrawal
Honeypot contracts appear exploitable (e.g., seemingly exposed funds) but use hidden code to trap attackers' deposited ETH, turning the tables on would-be exploiters.
Question 93: In zk-SNARKs used by privacy blockchains like Zcash, what does 'succinct' mean?
- The proof size and verification time are small and constant regardless of computation size (Correct answer)
- The proof is generated in zero time
- The prover and verifier must be online simultaneously
- The proof requires no cryptographic assumptions
Correct answer: The proof size and verification time are small and constant regardless of computation size
Succinct means the proof is very short and verification is fast (often milliseconds), even if the underlying computation being proved is large.
Question 94: In Elliptic Curve Cryptography (ECC), the 'discrete logarithm problem' refers to the difficulty of:
- Solving linear equations over finite fields
- Factoring large prime numbers
- Finding the scalar k given the points k·G and G on the curve (Correct answer)
- Computing modular square roots
Correct answer: Finding the scalar k given the points k·G and G on the curve
Given the public point k·G and base point G, recovering the private scalar k is computationally infeasible, forming the security basis of ECC.
Question 95: Which consensus mechanism does Ethereum use after 'The Merge' in 2022?
- Proof of Stake (Correct answer)
- Proof of Work
- Proof of Authority
- Delegated Proof of Stake
Correct answer: Proof of Stake
After The Merge, Ethereum switched from Proof of Work to Proof of Stake, where validators stake 32 ETH to propose and attest blocks.
Question 96: In post-quantum cryptography, why are current blockchain signature schemes (ECDSA, BLS) considered at risk?
- Grover's algorithm reduces hash output size to zero
- Quantum computers can factor large primes faster, breaking SHA-256 directly
- Shor's algorithm on a sufficiently large quantum computer can solve the elliptic curve discrete logarithm problem, breaking ECDSA and BLS (Correct answer)
- Quantum computers eliminate the need for hashing entirely
Correct answer: Shor's algorithm on a sufficiently large quantum computer can solve the elliptic curve discrete logarithm problem, breaking ECDSA and BLS
Shor's algorithm efficiently solves the discrete logarithm problem, which underpins the security of both ECDSA and BLS signatures used in blockchain.
Question 97: Which of the following best describes the role of "gas" in the context of the Ethereum blockchain?
- A cryptographic token used exclusively for staking in Proof of Stake consensus.
- The physical hardware required to run an Ethereum node.
- A unit of measurement for the computational effort required to execute operations. (Correct answer)
- A fixed-fee paid to the developers of a smart contract upon deployment.
Correct answer: A unit of measurement for the computational effort required to execute operations.
Gas is the unit that measures the amount of computational work required to perform operations, such as transactions or smart contract executions, on the Ethereum network. Each operation has a fixed gas cost. The total transaction fee (paid in ETH) is the amount of gas used multiplied by the gas price (in Gwei), which prevents network spam and compensates validators for their computational resources.
Question 98: In Solidity, what does the 'modifier' keyword allow developers to do?
- Reuse pre- and post-condition checks across multiple functions (Correct answer)
- Define custom error types with parameters
- Override inherited functions from parent contracts
- Declare immutable state variables
Correct answer: Reuse pre- and post-condition checks across multiple functions
Modifiers wrap functions with reusable logic (e.g., access checks), using the '_' placeholder to indicate where the modified function's body executes.
Question 99: What is the 'nothing-at-stake' problem in naive Proof-of-Stake implementations?
- Stakers can withdraw all stake before a slashing event is processed
- Validators with no stake can still participate in block validation if their identity is unverified
- Validators can vote on multiple competing forks simultaneously at no cost, undermining consensus (Correct answer)
- Empty blocks can be added to the chain without validators risking any reward loss
Correct answer: Validators can vote on multiple competing forks simultaneously at no cost, undermining consensus
Without slashing, validators lose nothing by supporting every fork, making double-spending trivial; modern PoS systems use slashing to penalize equivocation.
Question 100: What is the primary risk of using weak random number generation in a blockchain smart contract?
- Predictable outcomes that attackers can exploit before transactions confirm (Correct answer)
- Slower block confirmation times
- Incompatibility with other smart contracts
- Higher gas costs for random operations
Correct answer: Predictable outcomes that attackers can exploit before transactions confirm
Weak randomness (e.g., using block hash or timestamp) is predictable by miners, allowing them to manipulate lottery or gambling contract outcomes.
Certified Blockchain Expert (CBE)
The Certified Blockchain Expert (CBE) certification by Blockchain Council validates comprehensive knowledge of blockchain technology including architecture, consensus mechanisms, cryptography, smart contracts, dApps, and security — targeting developers, architects, and professionals seeking to demonstrate blockchain expertise.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds