Certified Blockchain Professional (CBCP) Exam — Questions and Answers
Question 1: Which of the following describes a Decentralized Autonomous Organization (DAO)?
- A corporation that uses blockchain to track its physical assets and supply chain.
- A software company that develops dApps for a variety of blockchain platforms.
- An internet-native organization where rules are encoded as smart contracts and operational decisions are made by its members, typically through voting with governance tokens. (Correct answer)
- A government agency that uses smart contracts to automate regulatory compliance.
Correct answer: An internet-native organization where rules are encoded as smart contracts and operational decisions are made by its members, typically through voting with governance tokens.
A Decentralized Autonomous Organization (DAO) is an entity with no central leadership. It is collectively owned and managed by its members. Its rules are encoded in smart contracts on a blockchain, and decisions are made through proposals and voting by members, who typically hold governance tokens that represent voting power.
Question 2: What is a 'crypto dusting attack'?
- Generating fake blocks to temporarily fork the blockchain
- Overloading a node with invalid transaction requests
- Sending tiny amounts of cryptocurrency to wallets to de-anonymize owners by tracking subsequent transactions (Correct answer)
- Flooding the network with tiny transactions to cause congestion and raise fees
Correct answer: Sending tiny amounts of cryptocurrency to wallets to de-anonymize owners by tracking subsequent transactions
Dusting attacks send tiny 'dust' amounts to many wallets; if recipients move those funds, analysts can cluster and link addresses to reveal wallet ownership.
Question 3: In a decentralized exchange (DEX) using an Automated Market Maker (AMM), what determines the token swap price?
- A mathematical formula based on the ratio of token reserves in a liquidity pool (Correct answer)
- A governance vote held every 24 hours
- An order book matching buyers and sellers
- A price feed from a centralized oracle provider
Correct answer: A mathematical formula based on the ratio of token reserves in a liquidity pool
AMMs like Uniswap use the constant product formula (x * y = k) where the price is determined by the current ratio of two token reserves in the pool.
Question 4: What is a 'Layer 2' solution in the context of cryptocurrency scalability?
- A second cryptographic layer added to wallet security
- A regulatory framework for second-generation cryptocurrencies
- A second blockchain that replaces the main chain
- A protocol built on top of a base blockchain to increase throughput and reduce fees (Correct answer)
Correct answer: A protocol built on top of a base blockchain to increase throughput and reduce fees
Layer 2 solutions (e.g., Lightning Network, Optimism, Arbitrum) process transactions off the main chain while inheriting its security, dramatically improving scalability.
Question 5: What is the primary security assumption behind Nakamoto consensus used in Bitcoin?
- All nodes must be known and identified
- Transactions are confirmed only after 1 block
- An attacker controlling less than 50% of hash rate cannot consistently outpace the honest chain (Correct answer)
- At least 67% of validators must be honest
Correct answer: An attacker controlling less than 50% of hash rate cannot consistently outpace the honest chain
Nakamoto consensus assumes that as long as honest miners control the majority of hash rate, the longest chain produced by honest nodes will outpace any attacker's chain.
Question 6: What is 'impermanent loss' in DeFi liquidity provision?
- The penalty for withdrawing staked assets before the lock-up period ends
- The temporary reduction in value a liquidity provider experiences compared to simply holding the assets, caused by price divergence (Correct answer)
- Transaction fees lost when a trade fails to execute
- Funds permanently lost due to a smart contract exploit
Correct answer: The temporary reduction in value a liquidity provider experiences compared to simply holding the assets, caused by price divergence
Impermanent loss occurs when the price ratio of pooled assets changes from deposit time; the loss becomes permanent only if the LP withdraws before prices revert.
Question 7: In cryptocurrency regulation, what does 'KYC/AML' require exchanges to do?
- Ensure all listed tokens have passed a security audit
- Report all transactions above $100 to regulators
- Only verify corporate clients, not individual traders
- Verify user identities and monitor transactions for suspicious activity to prevent financial crimes (Correct answer)
Correct answer: Verify user identities and monitor transactions for suspicious activity to prevent financial crimes
KYC (Know Your Customer) and AML (Anti-Money Laundering) regulations require exchanges to verify user identities, maintain records, and report suspicious transactions to relevant authorities.
Question 8: A new stablecoin is being designed to maintain a 1:1 peg with the US dollar. The issuer holds an equivalent amount of actual US dollars and short-term government securities in a fully audited bank account as a reserve. What type of stablecoin collateralization model does this represent?
- Algorithmic
- Commodity-collateralized
- Crypto-collateralized
- Fiat-collateralized (Correct answer)
Correct answer: Fiat-collateralized
This model describes a fiat-collateralized stablecoin. The stability of the token's value is derived from being backed by a reserve of fiat currency (like USD) or highly liquid, safe assets like government bonds. Crypto-collateralized stablecoins are backed by other cryptocurrencies, while algorithmic stablecoins use smart contracts to manage supply and maintain the peg without direct collateral.
Question 9: Which enterprise blockchain platform was built by the Linux Foundation and supports multiple programming languages for smart contract development including Go, JavaScript, and Java?
- VeChain
- R3 Corda
- Hyperledger Fabric (Correct answer)
- Quorum
Correct answer: Hyperledger Fabric
Hyperledger Fabric, maintained under the Linux Foundation's Hyperledger umbrella, supports chaincode written in Go, JavaScript (Node.js), and Java.
Question 10: What distinguishes a 'utility token' from a 'security token'?
- Utility tokens are regulated by the SEC while security tokens are unregulated
- Utility tokens have unlimited supply while security tokens have capped supply
- Utility tokens grant access to a product or service while security tokens represent investment contracts in an enterprise (Correct answer)
- Utility tokens are always built on Ethereum while security tokens use other blockchains
Correct answer: Utility tokens grant access to a product or service while security tokens represent investment contracts in an enterprise
Utility tokens provide platform access or functionality, while security tokens represent ownership or profit-sharing rights and are subject to securities regulation.
Question 11: A development team is building a decentralized social media platform. They want to ensure the user interface is fast and responsive, similar to a traditional web app, while the core logic for content ownership and user interactions is handled by smart contracts. Which of the following BEST describes a typical architectural stack for such a dApp?
- The application logic is run on a centralized server which then batches transactions and submits them to the blockchain.
- The entire application, including the frontend UI and all data, is stored and executed directly on the blockchain.
- A traditional frontend (HTML/CSS/JS) interacts with smart contracts for backend logic, and may use decentralized storage (like IPFS) for media files. (Correct answer)
- Smart contracts are used to query a centralized database where all user data and application logic is stored.
Correct answer: A traditional frontend (HTML/CSS/JS) interacts with smart contracts for backend logic, and may use decentralized storage (like IPFS) for media files.
A standard dApp architecture involves a separation of concerns. The frontend (user interface) is typically built with standard web technologies (HTML, CSS, JavaScript) for a good user experience. This frontend then communicates with the backend, which consists of smart contracts deployed on a blockchain. For large files like images or videos, decentralized storage solutions like IPFS are often used instead of storing them directly on the blockchain due to cost and performance constraints.
Question 12: What is the primary security risk of reusing the same ECDSA nonce (k) for two different signatures with the same private key?
- The signature becomes invalid and is rejected by the network
- The private key can be mathematically extracted from the two signatures (Correct answer)
- The hash of the transaction becomes predictable to miners
- The public key is exposed in plaintext in the transaction
Correct answer: The private key can be mathematically extracted from the two signatures
If k is reused, an attacker with two signatures and the known nonce can solve for the private key algebraically using the ECDSA signature equations.
Question 13: What is a wrapped token such as Wrapped Bitcoin (WBTC)?
- A token that automatically rebalances its value against a basket of assets
- A tokenized 1:1 representation of another asset enabling it to be used on a different blockchain's ecosystem (Correct answer)
- A token simultaneously issued and recognized by multiple independent blockchain networks
- A token that has been encrypted with an additional cryptographic security layer
Correct answer: A tokenized 1:1 representation of another asset enabling it to be used on a different blockchain's ecosystem
A wrapped token is a tokenized 1:1 representation of another cryptocurrency, enabling it to be used on blockchains with different native standards (e.g., WBTC brings Bitcoin's value to Ethereum's DeFi ecosystem).
Question 14: What is 'flash loan' in DeFi smart contracts?
- A loan where repayment is enforced by a hardware security module
- A micro-loan protocol that uses off-chain credit scores
- An uncollateralized loan that must be borrowed and repaid within a single transaction (Correct answer)
- A long-term undercollateralized loan issued by a DAO
Correct answer: An uncollateralized loan that must be borrowed and repaid within a single transaction
Flash loans are atomic, uncollateralized loans where borrowing and repayment occur in one transaction; if repayment fails, the entire transaction reverts.
Question 15: What is the 'CAP theorem' and how does it apply to blockchain consensus design?
- Consistency, Availability, and Partition tolerance cannot all be simultaneously guaranteed; blockchains must choose two (Correct answer)
- The theorem states blockchains can achieve complete decentralization with sufficient compute
- Consensus, Atomicity, and Persistence are the three required properties of any blockchain
- Cost, Accuracy, and Performance are the primary metrics for evaluating consensus algorithms
Correct answer: Consistency, Availability, and Partition tolerance cannot all be simultaneously guaranteed; blockchains must choose two
CAP theorem states distributed systems can guarantee at most two of Consistency, Availability, and Partition tolerance; PoW chains sacrifice consistency (probabilistic finality) for availability and partition tolerance.
Question 16: What is a cryptographic accumulator and how is it used in blockchain scalability?
- A hardware module that accelerates hash computation for miners
- A data structure that proves set membership without revealing the full set, used in stateless clients and rollups (Correct answer)
- A method to accumulate mining rewards before payout
- A technique to batch multiple blocks into one using AES encryption
Correct answer: A data structure that proves set membership without revealing the full set, used in stateless clients and rollups
Cryptographic accumulators (e.g., RSA or Merkle-based) allow compact proofs of membership or non-membership, enabling stateless blockchain clients that don't store full state.
Question 17: What distinguishes a 'pure' function from a 'view' function in Solidity?
- Pure functions require on-chain verification; view functions do not
- Pure functions can modify state; view functions cannot
- Pure functions are payable; view functions are not
- Pure functions neither read nor modify state; view functions can read but not modify state (Correct answer)
Correct answer: Pure functions neither read nor modify state; view functions can read but not modify state
A pure function promises to neither read nor write contract state, while a view function may read state but not modify it.
Question 18: What is the 'ABI' (Application Binary Interface) in the context of Ethereum smart contracts?
- A JSON description of a contract's functions and events used to encode/decode interactions (Correct answer)
- A digital signature proving contract ownership
- The bytecode representation stored on the blockchain
- A cryptographic hash of the contract bytecode
Correct answer: A JSON description of a contract's functions and events used to encode/decode interactions
The ABI is a JSON specification that defines how to encode function calls and decode return values when interacting with a deployed smart contract.
Question 19: Which of the following best describes the primary characteristic of a fungible token?
- Each token has a unique identifier and metadata.
- It represents ownership of a specific, unique real-world asset.
- It cannot be divided into smaller fractional parts.
- Each unit of the token is interchangeable and has the same value as any other unit. (Correct answer)
Correct answer: Each unit of the token is interchangeable and has the same value as any other unit.
Fungibility is the property of an asset where individual units are interchangeable and indistinguishable from one another. For example, one US dollar is equal in value to any other US dollar. Fungible tokens, like those based on the ERC-20 standard, exhibit this property, making them suitable for use as currencies or utility tokens. Non-fungible tokens (NFTs), by contrast, are unique.
Question 20: What attack vector does the 'checks-effects-interactions' pattern in Solidity primarily defend against?
- Front-running
- Signature replay
- Integer overflow
- Reentrancy attacks (Correct answer)
Correct answer: Reentrancy attacks
By updating state before making external calls, the pattern prevents a malicious contract from re-entering a function in an inconsistent state.
Question 21: What is 'tokenomics' in the context of DApp design?
- The process of converting ERC-20 tokens to ERC-721 tokens
- A tax applied to token transactions on decentralized exchanges
- The cryptographic algorithm used to secure token transfers
- The economic model governing a token's supply, distribution, incentives, and utility within an ecosystem (Correct answer)
Correct answer: The economic model governing a token's supply, distribution, incentives, and utility within an ecosystem
Tokenomics describes the economic design of a token system including total supply, emission schedule, staking rewards, and incentive structures that drive participant behavior.
Question 22: What are DApps made to accomplish?
- Manage cryptocurrencies only, without any embedded voting system for governance of the blockchain
- Support applications that run on multiple public cloud providers avoiding any vendor lock-in and fraud
- Execute smart contracts with the business logic in the front-end of a standalone application
- Run applications on a peer-to-peer (P2P) network expanding smart contracts beyond simple value transfer (Correct answer)
Correct answer: Run applications on a peer-to-peer (P2P) network expanding smart contracts beyond simple value transfer
Decentralized Applications (DApps) are designed to run applications on a peer-to-peer (P2P) network, extending the capabilities of smart contracts beyond simple value transfer. They leverage blockchain technology to distribute their backend logic across multiple nodes, enhancing censorship resistance, transparency, and resilience. DApps enable complex functionalities like decentralized finance, gaming, and social media, operating without a central authority.
Question 23: What does TVL (Total Value Locked) measure in the DeFi ecosystem?
- The total number of active DeFi wallet addresses globally
- The total transaction fees collected by blockchain validators
- The total market capitalization of all cryptocurrencies combined
- The total monetary value of assets deposited in DeFi smart contracts (Correct answer)
Correct answer: The total monetary value of assets deposited in DeFi smart contracts
TVL represents the total monetary value of all assets deposited and locked in DeFi smart contracts, used as a key metric for measuring a protocol's adoption and liquidity.
Question 24: In the context of DApps, what is the purpose of the Web3.js or Ethers.js library?
- To provide a JavaScript interface for interacting with Ethereum nodes and smart contracts (Correct answer)
- To run a local Ethereum node in the browser
- To compile Solidity source code into EVM bytecode
- To generate cryptographic key pairs for wallets
Correct answer: To provide a JavaScript interface for interacting with Ethereum nodes and smart contracts
Web3.js and Ethers.js are JavaScript libraries that enable frontend DApp code to communicate with Ethereum nodes via JSON-RPC, call contract functions, and listen for events.
Question 25: A consortium of financial institutions is creating a private blockchain for inter-bank settlements. The network requires high transaction throughput and low latency. The members are all known and trusted entities, but there is a need to tolerate a few nodes acting maliciously or failing. Which consensus mechanism is most suitable for this scenario?
- Proof of Work (PoW)
- Practical Byzantine Fault Tolerance (PBFT) (Correct answer)
- Proof of Stake (PoS)
- Delegated Proof of Stake (DPoS)
Correct answer: Practical Byzantine Fault Tolerance (PBFT)
Practical Byzantine Fault Tolerance (PBFT) is designed for permissioned networks where participants are known. It provides high throughput and low latency by having nodes communicate to reach a consensus. It can tolerate a certain number of malicious or faulty nodes (specifically, up to f faulty nodes out of 3f + 1 total nodes) without compromising the network's integrity, making it ideal for consortiums of trusted entities.
Question 26: A smart contract is designed to release payments to a supplier only after a shipment's arrival is confirmed by an IoT sensor. The blockchain network itself cannot directly access data from the IoT sensor. Which of the following is required to securely and reliably feed the external data to the smart contract?
- Manual data entry by a network administrator
- A blockchain oracle (Correct answer)
- A direct API call from the smart contract to the IoT device
- A centralized server owned by the shipping company
Correct answer: A blockchain oracle
Blockchains are deterministic, isolated networks and cannot natively access external, off-chain data. A blockchain oracle is a service that connects smart contracts with off-chain data sources, acting as a bridge to provide the necessary external information in a trusted manner.
Question 27: Which property of Byzantine Fault Tolerance (BFT) consensus describes the guarantee that all honest nodes agree on the same value?
- Safety (Correct answer)
- Availability
- Finality
- Liveness
Correct answer: Safety
Safety in BFT consensus ensures that no two honest nodes decide on different values, preventing forks or conflicting chain states.
Question 28: In Ethereum's account abstraction roadmap, what does EIP-4337 enable without requiring consensus-layer changes?
- Native multi-call support for EOAs at the protocol level
- Elimination of the nonce requirement for smart contracts
- Smart contract wallets that can initiate transactions using a separate mempool and bundler infrastructure (Correct answer)
- Gasless transactions sponsored directly by miners
Correct answer: Smart contract wallets that can initiate transactions using a separate mempool and bundler infrastructure
EIP-4337 achieves account abstraction via UserOperations, a dedicated alt-mempool, and bundler nodes — no hard fork needed.
Question 29: Which tokenization model represents fractional ownership of a real-world asset such as real estate on a blockchain?
- Stablecoin
- Utility Token
- Security Token (STO) (Correct answer)
- Non-Fungible Token (NFT)
Correct answer: Security Token (STO)
Security Tokens represent ownership stakes or financial rights in real-world assets and are subject to securities regulations, making them the appropriate model for tokenized real estate or equity.
Question 30: What does 'finality' mean in the context of blockchain consensus?
- The guarantee that a confirmed transaction cannot be reversed (Correct answer)
- The maximum number of transactions a block can contain
- The moment a miner receives their block reward
- The process of archiving old blocks to reduce storage
Correct answer: The guarantee that a confirmed transaction cannot be reversed
Finality describes the point at which a transaction is considered irreversibly settled; different consensus mechanisms offer probabilistic or absolute finality.
Question 31: Which elliptic curve is used by Bitcoin for its digital signature scheme?
- secp256k1 (Correct answer)
- Curve25519
- P-384
- P-256
Correct answer: secp256k1
Bitcoin uses the secp256k1 elliptic curve defined in the SEC standard for its ECDSA signature scheme.
Question 32: Which type of node in a blockchain network stores a complete copy of the entire transaction history?
- Full node (Correct answer)
- Light node (SPV node)
- Mining node only
- Archival super-node
Correct answer: Full node
A full node independently downloads and validates every block and transaction from the genesis block, maintaining the complete chain history.
Question 33: In Hyperledger Fabric's transaction lifecycle, what is the specific role of an 'endorsing peer'?
- To execute a chaincode transaction proposal, sign the result, and return it to the client. (Correct answer)
- To manage the cryptographic identities and certificates for all network participants.
- To bundle transactions into blocks and send them to all peers.
- To validate the final block and write it to its local ledger.
Correct answer: To execute a chaincode transaction proposal, sign the result, and return it to the client.
The endorsing peer's primary role is to receive a transaction proposal from a client application, simulate the transaction by executing the specified chaincode, and then sign the read-write set (the results). This signed proposal response, or 'endorsement', is sent back to the client. It does not commit the transaction to the ledger at this stage. [8, 21]
Question 34: Due to the immutable nature of blockchains, fixing a bug in a deployed smart contract is a significant challenge. Which design pattern allows developers to update the application logic of a dApp without requiring users to migrate their data to a new contract address?
- The Factory Pattern
- The Singleton Pattern
- The Proxy Pattern (Correct answer)
- The Observer Pattern
Correct answer: The Proxy Pattern
The Proxy Pattern is a common method for enabling smart contract upgrades. It involves separating the contract's state and logic. Users interact with a proxy contract that holds the state (data), which then delegates calls to a separate logic contract. To upgrade, a new logic contract is deployed, and the proxy contract is simply updated to point to the new logic contract's address, preserving the original state and contract address for users.
Question 35: Which consensus mechanism does Ethereum currently use after 'The Merge' in 2022?
- Proof of Stake (Correct answer)
- Proof of Authority
- Proof of Work
- Delegated Proof of Stake
Correct answer: Proof of Stake
Ethereum transitioned from Proof of Work to Proof of Stake via 'The Merge' in September 2022, reducing energy consumption by ~99.95%.
Question 36: What is the main purpose of using cryptographic algorithms in the blockchain?
- Ensuring secure data transmission and storage (Correct answer)
- Generating new blocks
- Updating network protocols
- Validating transactions
Correct answer: Ensuring secure data transmission and storage
Cryptographic algorithms are the backbone of blockchain security and integrity. Their main purpose is to ensure secure data transmission and storage by encrypting information, creating unique hashes for blocks and transactions, and enabling digital signatures. This prevents unauthorized access, tampering, and ensures the immutability of the blockchain ledger.
Question 37: Which BIP standard defines the mnemonic seed phrase (12–24 words) used to back up HD wallets?
- BIP-44
- BIP-141
- BIP-39 (Correct answer)
- BIP-32
Correct answer: BIP-39
BIP-39 specifies converting entropy into a human-readable mnemonic word list and then deriving a binary seed from those words via PBKDF2.
Question 38: Which of the following best describes the core architectural difference between a traditional application and a Decentralized Application (DApp)?
- DApps store data on a centralized database for faster retrieval, unlike traditional apps which use distributed storage.
- DApps use HTML and CSS for the frontend, while traditional applications use proprietary languages.
- The backend logic of a DApp is executed on a peer-to-peer network via smart contracts, whereas a traditional app's backend runs on centralized servers. (Correct answer)
- Traditional applications are always open-source, while DApps are typically closed-source to protect the smart contract logic.
Correct answer: The backend logic of a DApp is executed on a peer-to-peer network via smart contracts, whereas a traditional app's backend runs on centralized servers.
The fundamental architectural shift in DApps is the replacement of a centralized backend server with smart contracts running on a decentralized, peer-to-peer blockchain network. The frontend can use standard web technologies, but the business logic is enforced by the smart contracts on the blockchain.
Question 39: What is a 'governance token' in the context of decentralized protocols?
- A token used to verify identity on-chain
- A token that grants holders voting rights over protocol changes and treasury decisions (Correct answer)
- A stablecoin used to fund protocol development
- A token required to pay transaction fees
Correct answer: A token that grants holders voting rights over protocol changes and treasury decisions
Governance tokens give holders the ability to propose and vote on protocol upgrades, parameter changes, and treasury allocations in a decentralized autonomous organization.
Question 40: Which blockchain claim is accurate?
- All of the above (Correct answer)
- Blockchain is a decentralized, distributed, and oftentimes public, digital ledge
- Blockchain database is managed autonomously using a peer-to-peer network
- Blockchain has been described as a value-exchange protocol
Correct answer: All of the above
All the listed claims accurately describe key aspects of blockchain technology. It functions as a decentralized, distributed, and often public digital ledger managed autonomously by a peer-to-peer network, eliminating the need for central authority. Furthermore, its ability to securely transfer and record assets makes it a powerful value-exchange protocol, enabling new forms of digital commerce and interaction.
Question 41: What is 'finality' in the context of blockchain consensus, and which type is typically provided by BFT protocols?
- Finality means blocks are mined faster; BFT provides economic finality
- Finality refers to fee settlement; BFT provides instant fee clearing
- Finality means transactions are irreversible; BFT provides absolute (deterministic) finality (Correct answer)
- Finality means transactions are irreversible; BFT provides probabilistic finality
Correct answer: Finality means transactions are irreversible; BFT provides absolute (deterministic) finality
BFT-based protocols provide deterministic (absolute) finality — once a block is committed, it cannot be reverted, unlike the probabilistic finality of PoW chains.
Question 42: What is the purpose of key stretching algorithms like PBKDF2, bcrypt, or scrypt in blockchain wallet security?
- To make brute-force attacks slower by deliberately increasing computational cost (Correct answer)
- To generate Merkle proofs faster
- To increase the key length for symmetric encryption
- To convert asymmetric keys into symmetric keys
Correct answer: To make brute-force attacks slower by deliberately increasing computational cost
Key stretching algorithms apply many iterations of hashing to slow down computation, making brute-force or dictionary attacks on passwords prohibitively expensive.
Question 43: Which governance concept describes a blockchain network where changes require agreement from a defined subset of network participants?
- Threshold governance (Correct answer)
- BFT-based governance
- Multisig governance
- Proof of Authority
Correct answer: Threshold governance
Threshold governance requires a predefined minimum number or percentage of participants to agree before a protocol change or transaction is approved.
Question 44: A Decentralized Autonomous Organization (DAO) is being established to manage a DeFi protocol. How are major decisions, such as updating smart contract parameters or allocating treasury funds, typically made in a DAO?
- By the lead development team without external input.
- Through a hierarchical management structure led by a CEO.
- Through proposals and voting by community members who hold governance tokens. (Correct answer)
- By a centralized board of directors appointed by the founders.
Correct answer: Through proposals and voting by community members who hold governance tokens.
A core principle of a DAO is decentralized governance. Decisions are not made by a central authority but are instead proposed by and voted on by the community of members. Typically, voting power is proportional to the number of governance tokens a member holds.
Question 45: What distinguishes a 'cold wallet' from a 'hot wallet' in cryptocurrency asset management?
- Cold wallets require multi-signature authorization while hot wallets require only a single key
- Cold wallets store only stablecoins while hot wallets hold volatile assets
- Cold wallets are kept offline and disconnected from the internet, while hot wallets remain connected online (Correct answer)
- Cold wallets use hardware encryption while hot wallets use software encryption
Correct answer: Cold wallets are kept offline and disconnected from the internet, while hot wallets remain connected online
Cold wallets (hardware or paper) store private keys offline, making them immune to remote hacking, while hot wallets maintain internet connectivity for convenience at the cost of greater attack surface.
Question 46: What does it mean for a cryptographic protocol to be 'computationally secure' versus 'information-theoretically secure'?
- Computationally secure requires hardware support; information-theoretically secure runs in software only
- Computationally secure protocols are safe assuming bounded adversary compute power; information-theoretically secure ones are safe against unlimited compute (Correct answer)
- Computationally secure means formally proven; information-theoretically secure means heuristically validated
- Computationally secure protocols use faster algorithms; information-theoretically secure protocols use slower ones
Correct answer: Computationally secure protocols are safe assuming bounded adversary compute power; information-theoretically secure ones are safe against unlimited compute
Information-theoretic security (like a one-time pad) is unbreakable regardless of compute power, while computational security assumes adversaries cannot solve hard mathematical problems within feasible time.
Question 47: What is the significance of 'block time' in a blockchain network?
- The average interval between successive block additions to the chain (Correct answer)
- The time required for a node to download the full ledger
- The maximum age a transaction can be before it is discarded
- The duration a validator is locked in a staking pool
Correct answer: The average interval between successive block additions to the chain
Block time determines how quickly transactions are finalized; shorter block times increase throughput but may raise the orphan rate.
Question 48: How long does it take to mine a block of Ethereum?
- 0 (Correct answer)
- 12
- 10
- 30
Correct answer: 0
After Ethereum's transition to Proof-of-Stake (known as 'The Merge'), the concept of 'mining' a block in the traditional Proof-of-Work sense no longer applies. Instead, blocks are created and attested by validators at fixed intervals (slots), meaning there is no competitive mining process with a variable 'mining time.' Thus, the time to 'mine' a block is effectively 0 in the old sense, as blocks are now scheduled.
Question 49: What is the primary purpose of a 'multi-signature' (multisig) wallet configuration such as 2-of-3?
- It encrypts wallet data with multiple layers of AES encryption keys
- It increases transaction throughput by parallelizing signature verification
- It enables gasless transactions by distributing fee payment across signers
- It requires M of N keyholders to authorize a transaction, reducing single-point-of-failure risk (Correct answer)
Correct answer: It requires M of N keyholders to authorize a transaction, reducing single-point-of-failure risk
A 2-of-3 multisig wallet requires any 2 of 3 designated private keys to sign a transaction, providing security redundancy — loss of one key doesn't lock funds, and theft of one key isn't sufficient to steal funds.
Question 50: What does the term 'gas limit' represent in an Ethereum transaction?
- The maximum Ether value that can be transferred
- The minimum fee required by miners
- The block's throughput capacity in transactions per second
- The maximum amount of computational work the sender is willing to pay for (Correct answer)
Correct answer: The maximum amount of computational work the sender is willing to pay for
Gas limit is the maximum units of gas a sender authorizes for a transaction; if execution requires more gas, it reverts but the gas is still consumed.
Question 51: Which Layer 2 scaling solution bundles many transactions off-chain and posts only a cryptographic proof to the main chain?
- State Channels
- Optimistic Rollup
- Plasma
- ZK-Rollup (Correct answer)
Correct answer: ZK-Rollup
ZK-Rollups execute transactions off-chain and submit a validity proof (ZK-SNARK/STARK) to the main chain, enabling high throughput while inheriting mainchain security without a challenge period.
Question 52: What attack does salting a password hash defend against?
- Brute-force attacks on the hash algorithm itself
- Pre-computed rainbow table attacks (Correct answer)
- Replay attacks using captured authentication tokens
- Side-channel timing attacks
Correct answer: Pre-computed rainbow table attacks
A salt is a random value appended to the password before hashing, ensuring identical passwords produce different hashes and invalidating pre-computed lookup tables.
Question 53: What is 'uncle rate' in pre-Merge Ethereum and why was it significant?
- The fraction of valid blocks not included in the main chain, indicating network latency and miner competition (Correct answer)
- The ratio of failed transactions to successful ones
- The percentage of ETH issuance going to staking validators
- The proportion of gas used by internal calls
Correct answer: The fraction of valid blocks not included in the main chain, indicating network latency and miner competition
High uncle rates indicated propagation delays; uncle blocks received partial rewards to reduce wasted PoW work.
Question 54: In Hyperledger Fabric's endorsement policy, what determines which peers must sign a transaction before it is considered valid?
- The orderer node selects endorsers based on current network load
- The chaincode-specific endorsement policy defining required organizational signatures (Correct answer)
- All peers in the channel must endorse every transaction by default
- The peer with the highest computational power automatically endorses all transactions
Correct answer: The chaincode-specific endorsement policy defining required organizational signatures
Hyperledger Fabric endorsement policies are defined per chaincode and specify which organizations' peers must simulate and sign a transaction proposal for it to be valid.
Question 55: What is the key risk of 'impermanent loss' in automated market maker (AMM) liquidity pools?
- Regulatory seizure of pooled assets
- Smart contract bugs that permanently destroy tokens
- Loss compared to simply holding assets when their prices diverge (Correct answer)
- Failure of the oracle feeding price data
Correct answer: Loss compared to simply holding assets when their prices diverge
Impermanent loss occurs when the price ratio of pooled assets changes after deposit, making the LP position less valuable than simply holding the tokens individually.
Question 56: A DeFi protocol's smart contract contains a function that sends funds to an external address. An attacker discovers that they can repeatedly call this function from their own malicious contract before the original function completes its state update, allowing them to withdraw more funds than they are entitled to. This vulnerability is known as a:
- Front-Running Attack
- Timestamp Dependence Vulnerability
- Integer Overflow Attack
- Reentrancy Attack (Correct answer)
Correct answer: Reentrancy Attack
A reentrancy attack occurs when an external call from a vulnerable contract allows the called contract to call back into the original contract before its state is updated. This can lead to the logic being executed multiple times, often to drain funds, as famously happened in the 2016 DAO hack.
Question 57: What is the primary security property provided by digital signatures in blockchain transactions?
- Availability — the transaction is always accessible on the network
- Non-repudiation — the sender cannot deny authorizing the transaction (Correct answer)
- Confidentiality — only the recipient can read the transaction
- Integrity — the transaction data is compressed for storage
Correct answer: Non-repudiation — the sender cannot deny authorizing the transaction
Digital signatures provide non-repudiation by cryptographically proving that only the private key holder could have authorized the transaction, preventing later denial.
Question 58: What situation provides the best opportunity for a smart contract to solve the issue?
- An energy company wants to automatically buy power when the price reaches a predetermined rate. (Correct answer)
- A bartender wants to force customers to pay for their drinks by transferring cryptocurrency to his wallet.
- A chief financial officer wants her smart watch to notify her when her partner enters their front door.
- An insurance company wants to pay out a farmer whenever the case manager feels it is best to do so.
Correct answer: An energy company wants to automatically buy power when the price reaches a predetermined rate.
A smart contract provides the best solution when an energy company wants to automatically buy power when the price reaches a predetermined rate. The contract can be programmed to monitor real-time energy prices from a trusted oracle. Once the specified price condition is met, the smart contract automatically executes the power purchase, ensuring efficient and timely transactions without manual intervention or intermediaries.
Question 59: In Delegated Proof of Stake (DPoS), what is the primary role of 'witnesses' or 'delegates'?
- To validate identity of new participants
- To produce blocks on behalf of token holders who voted for them (Correct answer)
- To audit smart contract code
- To hold reserve funds for network security
Correct answer: To produce blocks on behalf of token holders who voted for them
In DPoS, token holders vote for delegates/witnesses who are then responsible for block production, making the system more democratic yet efficient.
Question 60: What is the purpose of the 'require' statement in Solidity?
- To declare a variable that cannot be changed after deployment
- To import external libraries at compile time
- To validate conditions and revert the transaction with a message if the condition is false (Correct answer)
- To emit an event on the blockchain
Correct answer: To validate conditions and revert the transaction with a message if the condition is false
The require statement checks a condition at runtime; if it fails, it reverts the transaction and optionally provides an error message, refunding remaining gas.
Certified Blockchain Professional (CBCP) Exam
The Certified Blockchain Professional (CBCP) exam validates an individual's foundational knowledge of blockchain technology, including its concepts, principles, and applications.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds