Certified Blockchain Expert (CBE) — Questions and Answers
Question 1: As the block subsidy in a cryptocurrency like Bitcoin diminishes over time due to halvings, what is expected to become the primary source of revenue for miners to incentivize them to continue securing the network?
- Donations from the user community.
- Increased cryptocurrency value alone.
- Revenue from selling mining hardware.
- Transaction fees paid by users. (Correct answer)
Correct answer: Transaction fees paid by users.
The block subsidy is designed to decrease over time, eventually reaching zero. The long-term security model relies on transaction fees becoming the primary incentive for miners. As users compete for limited space in each block, they include fees to have their transactions processed. Miners collect these fees as part of the block reward, and this revenue is intended to replace the diminishing subsidy.
Question 2: A developer is writing a Solidity smart contract that handles user withdrawals. They write the code to send the Ether to the user's address *before* updating the user's balance in the contract's state. This sequence of operations makes the contract vulnerable to which specific type of attack?
- Integer Overflow
- Denial of Service (DoS)
- Timestamp Dependence
- Reentrancy (Correct answer)
Correct answer: Reentrancy
A reentrancy attack occurs when an external call is made to another contract before the original function has finished its execution, particularly before updating its state. A malicious contract can exploit this by repeatedly calling the withdraw function, re-entering the code before the balance is updated, and draining funds.
Question 3: Which blockchain platform is widely known for supporting smart contracts?
- Ripple
- Bitcoin
- Ethereum (Correct answer)
- Dogecoin
Correct answer: Ethereum
Ethereum is renowned for pioneering and widely supporting smart contract functionality. Unlike Bitcoin, which primarily focuses on peer-to-peer digital cash, Ethereum was designed as a platform for building decentralized applications (dApps) and executing complex, self-executing agreements through its smart contracts.
Question 4: A decentralized governance protocol allows token holders to vote on proposals. An attacker attempts to gain disproportionate influence by creating thousands of new, low-balance addresses and using them to vote for a malicious proposal. This attack is best described as a:
- Replay Attack
- 51% Attack
- Sybil Attack (Correct answer)
- Dusting Attack
Correct answer: Sybil Attack
A Sybil attack is a security threat where a single entity creates a large number of pseudonymous identities (e.g., wallet addresses or nodes) to subvert a reputation or voting system. In decentralized governance, this allows one actor to appear as many, illegitimately amplifying their voting power to manipulate outcomes.
Question 5: Which US regulatory body primarily oversees cryptocurrency exchanges and classifies many tokens as securities?
- SEC (Correct answer)
- CFTC
- OCC
- FinCEN
Correct answer: SEC
The SEC (Securities and Exchange Commission) applies the Howey Test to determine if tokens are securities and regulates exchanges accordingly.
Question 6: What is 'token burning' in blockchain tokenomics?
- Permanently removing tokens from circulation by sending them to an unspendable address (Correct answer)
- Transferring tokens to a locked staking contract for rewards
- Converting tokens into stablecoins to preserve value
- The process of creating new tokens through mining
Correct answer: Permanently removing tokens from circulation by sending them to an unspendable address
Token burning permanently removes tokens from circulation by sending them to an unspendable 'burn address,' reducing total supply and creating potential deflationary pressure.
Question 7: What is yield farming in decentralized finance?
- Generating returns by strategically providing liquidity or staking assets across multiple DeFi protocols (Correct answer)
- A method for validators to earn block rewards in proof-of-stake networks
- The process of mining new tokens through proof-of-work computational effort
- Creating NFTs to represent agricultural land and commodity ownership
Correct answer: Generating returns by strategically providing liquidity or staking assets across multiple DeFi protocols
Yield farming involves strategically deploying crypto assets across DeFi protocols—liquidity pools, lending markets, and staking contracts—to earn compounded returns through fees, interest, and token incentives.
Question 8: What is Ethereum's EIP-4844 (Proto-Danksharding) designed to improve?
- Reducing the cost of posting rollup data to Ethereum by introducing temporary 'blob' data storage (Correct answer)
- Adding native cross-chain messaging to the Ethereum protocol
- Enabling Ethereum to process 100,000 TPS natively without Layer 2 solutions
- Implementing full sharding with 64 shards for parallel transaction processing
Correct answer: Reducing the cost of posting rollup data to Ethereum by introducing temporary 'blob' data storage
EIP-4844 introduces blob-carrying transactions that provide cheap, temporary data storage specifically for rollups, dramatically reducing L2 transaction costs.
Question 9: What regulatory challenge is unique to decentralized finance (DeFi) compared to centralized exchanges?
- Excessive KYC requirements that slow transactions
- Lack of a central intermediary that can be held legally responsible (Correct answer)
- Mandatory government audits on all smart contracts
- Requirement to hold 100% reserves
Correct answer: Lack of a central intermediary that can be held legally responsible
DeFi protocols operate via autonomous smart contracts with no central party, making it difficult for regulators to enforce compliance obligations.
Question 10: What should you do when troubleshooting a system architecture issue?
- Follow a systematic approach: identify, research, test, implement, verify (Correct answer)
- Immediately restart all systems
- Escalate everything without investigation
- Make random changes until the problem goes away
Correct answer: Follow a systematic approach: identify, research, test, implement, verify
A systematic troubleshooting approach ensures the root cause is identified and the fix is verified without creating new issues.
Question 11: Which blockchain consensus mechanism is designed for scalability and speed?
- Proof of Work
- Delegated Proof of Stake (Correct answer)
- Proof of Elapsed Time
- Proof of Authority
Correct answer: Delegated Proof of Stake
Delegated Proof of Stake (DPoS) enhances scalability and speed by allowing token holders to elect a limited number of delegates to validate transactions and create blocks. This streamlined process, with fewer participants involved in consensus, significantly reduces block confirmation times and increases transaction throughput compared to other mechanisms like Proof of Work.
Question 12: What is the primary function of a cryptographic hash function in a blockchain?
- To generate public and private keys for user wallets.
- To execute the terms of a smart contract automatically.
- To reach an agreement among network participants on the validity of transactions.
- To provide a unique, fixed-size digital fingerprint for data, ensuring its integrity and linking blocks together. (Correct answer)
Correct answer: To provide a unique, fixed-size digital fingerprint for data, ensuring its integrity and linking blocks together.
Cryptographic hash functions are fundamental to blockchain's security and immutability. They take an input of any size and produce a unique, fixed-length output (the hash). Any change to the input data results in a completely different hash, which is how data integrity is ensured. Hashes are also used to chain blocks together, creating a tamper-evident ledger.
Question 13: What distinguishes a security token from a utility token under US securities regulations?
- Security tokens are always built on Ethereum while utility tokens are not
- Security tokens represent an investment with an expectation of profit derived from others' efforts, making them subject to SEC regulations (Correct answer)
- Utility tokens must be registered with the SEC while security tokens do not
- Security tokens can only be used for peer-to-peer transactions between accredited investors
Correct answer: Security tokens represent an investment with an expectation of profit derived from others' efforts, making them subject to SEC regulations
Security tokens pass the Howey Test by representing an investment of money in a common enterprise with an expectation of profits from others' efforts, triggering full SEC regulatory oversight.
Question 14: What is the Lightning Network's approach to scaling Bitcoin transactions?
- Moving Bitcoin transactions to a Proof of Stake sidechain
- Using ZK-proofs to batch Bitcoin transactions
- Payment channels that allow off-chain bilateral transactions settled on-chain only when channels close (Correct answer)
- Increasing Bitcoin's block size to 4MB
Correct answer: Payment channels that allow off-chain bilateral transactions settled on-chain only when channels close
The Lightning Network creates peer-to-peer payment channels where parties transact off-chain; only the opening and closing transactions are recorded on the Bitcoin blockchain.
Question 15: What defines a decentralized application (dApp)?
- Runs on centralized cloud
- Owned by a single company
- Runs on a blockchain and uses smart contracts (Correct answer)
- Only accessible via mobile
Correct answer: Runs on a blockchain and uses smart contracts
A decentralized application (dApp) is an application that runs on a decentralized peer-to-peer network, typically a blockchain, rather than a single centralized server. Its backend code is executed via smart contracts, ensuring transparency, immutability, and censorship resistance without a central authority.
Question 16: Which consensus algorithm is used by Bitcoin?
- Proof of Work (Correct answer)
- Proof of Stake
- Delegated Proof of Stake
- Proof of Authority
Correct answer: Proof of Work
Bitcoin, the first and most well-known cryptocurrency, utilizes the Proof of Work (PoW) consensus algorithm. In PoW, miners compete to solve a complex computational puzzle to validate transactions and add new blocks to the blockchain. The first miner to find the solution earns the right to add the block and receive a reward.
Question 17: What is the role of consensus in blockchain networks?
- To backup the chain
- To encrypt transactions
- To reach agreement among nodes (Correct answer)
- To build smart contracts
Correct answer: To reach agreement among nodes
Consensus mechanisms are fundamental to blockchain networks, serving to enable all participating nodes to agree on the single, true state of the distributed ledger. In a decentralized system without a central authority, consensus protocols ensure that transactions are validated and added to the blockchain in a consistent and trustworthy manner.
Question 18: In the context of a Bitcoin block, what is the primary purpose of a Merkle Tree?
- To efficiently and securely verify the integrity of a large set of transactions. (Correct answer)
- To encrypt the transaction data for confidentiality.
- To reach consensus among network nodes.
- To generate new private keys for each transaction.
Correct answer: To efficiently and securely verify the integrity of a large set of transactions.
A Merkle Tree, or hash tree, summarizes all the transactions in a block by repeatedly hashing pairs of transaction hashes until a single hash, the Merkle Root, is left. This structure allows for efficient verification of transactions; a user can check if a transaction is included in a block by only needing the Merkle Root and a small number of hashes (the Merkle proof), rather than downloading and checking every single transaction.
Question 19: An enterprise choosing to implement a private blockchain instead of a public one gains enhanced performance and data confidentiality at the expense of which key blockchain principle?
- Scalability
- Decentralization (Correct answer)
- Usability
- Interoperability
Correct answer: Decentralization
Private blockchains are controlled by a single entity, making them centralized. This centralization allows for higher performance and privacy controls but sacrifices the core benefit of decentralization, which provides the trustlessness and censorship resistance found in public networks.
Question 20: Elliptic Curve Cryptography (ECC) is widely used in blockchains like Bitcoin and Ethereum. What is its primary advantage over older algorithms like RSA?
- It uses symmetric keys for faster encryption.
- It is a simpler algorithm to implement.
- It is resistant to quantum computing attacks.
- It provides the same level of security with smaller key sizes. (Correct answer)
Correct answer: It provides the same level of security with smaller key sizes.
The main advantage of Elliptic Curve Cryptography (ECC) is that it can provide the same level of security as algorithms like RSA but with significantly smaller key sizes. This leads to lower computational overhead, faster operations, and reduced storage and bandwidth requirements, which are crucial for the efficiency and scalability of a blockchain network.
Question 21: A developer is building a new blockchain protocol and needs to select a hashing algorithm. Which of the following is a critical property for the chosen algorithm to prevent attackers from finding two different inputs that produce the same hash output?
- Pre-image resistance
- Fixed output size
- Collision resistance (Correct answer)
- Deterministic nature
Correct answer: Collision resistance
Collision resistance is a crucial property of a cryptographic hash function, meaning it should be computationally infeasible to find two different inputs that produce the exact same hash output. If a hash function is not collision-resistant, an attacker could create a fraudulent transaction that has the same hash as a legitimate one, compromising the integrity of the blockchain.
Question 22: What is a token airdrop in blockchain projects?
- The bridge process for transferring tokens from one blockchain to another
- An emergency smart contract function to freeze all token transfers during a security incident
- The free distribution of tokens to existing holders or target users as a promotional or reward strategy (Correct answer)
- A mechanism for permanently burning excess token supply to reduce inflation
Correct answer: The free distribution of tokens to existing holders or target users as a promotional or reward strategy
A token airdrop is the free distribution of tokens to wallet addresses, used to reward existing community members, incentivize new users, or bootstrap adoption of a newly launched protocol.
Question 23: Which of the following is a primary characteristic that distinguishes a smart contract from a traditional legal contract?
- Its terms are self-executing and enforced by code on a blockchain. (Correct answer)
- It can be easily amended by any party after it has been agreed upon.
- It relies on a central authority or legal system for enforcement.
- It is written in a natural, human-readable language.
Correct answer: Its terms are self-executing and enforced by code on a blockchain.
The core difference is that a smart contract is a self-executing agreement with the terms of the agreement directly written into lines of code. It automatically enforces the rules and obligations defined within it when predetermined conditions are met, without the need for a traditional intermediary or legal system.
Question 24: Which programming language is primarily used to write Ethereum smart contracts?
- Solidity (Correct answer)
- Go
- Rust
- Python
Correct answer: Solidity
Solidity is the primary high-level, contract-oriented programming language specifically developed for writing smart contracts on the Ethereum blockchain. It is syntactically similar to JavaScript and is the most widely used language for creating decentralized applications (dApps) and their underlying logic within the Ethereum ecosystem.
Question 25: A financial consortium wants to create a blockchain for inter-bank transfers. They require high transaction speeds, control over who can participate, and data privacy. Which type of blockchain would be most suitable for this scenario?
- Consortium Blockchain (Correct answer)
- Private Blockchain
- Hybrid Blockchain
- Public Blockchain
Correct answer: Consortium Blockchain
A consortium blockchain is a semi-decentralized type of blockchain that is governed by a group of organizations rather than a single entity. It is ideal for business collaborations where trust, privacy, and control are essential among a known group of participants, fitting the needs of a financial consortium perfectly. While a private blockchain is controlled by one entity, a consortium model shares control among members.
Question 26: In the context of blockchain platforms, the term 'permissionless' primarily implies that:
- all transactions are anonymous and cannot be traced.
- the network is controlled by a single entity that grants permissions.
- developers do not need permission from a central body to build applications on the platform.
- anyone can join the network, participate in consensus, and view the ledger without needing approval. (Correct answer)
Correct answer: anyone can join the network, participate in consensus, and view the ledger without needing approval.
'Permissionless' directly refers to the lack of a gatekeeper for participating in the network's core functions. On a public, permissionless blockchain, any individual can connect a node, view the public ledger, submit transactions, and attempt to participate in the consensus mechanism without seeking approval from a central authority.
Question 27: The Bank Secrecy Act (BSA) requires US crypto businesses to implement which compliance program?
- AML/KYC (Correct answer)
- PCI-DSS
- GDPR
- HIPAA
Correct answer: AML/KYC
The BSA mandates Anti-Money Laundering (AML) and Know Your Customer (KYC) programs for money services businesses, including many crypto firms.
Question 28: When deploying a smart contract to the Ethereum network, what is the primary purpose of 'gas'?
- To pay for the computational effort required to execute operations and record transactions on the blockchain. (Correct answer)
- A token used for governance votes within the DApp.
- A fixed fee paid to the developers of the Solidity language.
- A unit of data storage for the smart contract's variables.
Correct answer: To pay for the computational effort required to execute operations and record transactions on the blockchain.
Gas is the unit used to measure the computational work required to perform operations on the Ethereum network. Users pay gas fees in Ether (ETH) to compensate miners or validators for the resources consumed to execute transactions and smart contract interactions, preventing spam and allocating resources on the decentralized network.
Question 29: In a public-key cryptography system as used in blockchain, what is the relationship between the private key and the public key?
- The private key is derived from the public key.
- The public key is used to encrypt data, and the private key is used to decrypt it.
- Both keys are identical and shared between the sender and receiver for secure communication.
- The public key is mathematically derived from the private key, but it is computationally infeasible to reverse the process. (Correct answer)
Correct answer: The public key is mathematically derived from the private key, but it is computationally infeasible to reverse the process.
In asymmetric cryptography (public-key cryptography), the public key is generated from the private key through a one-way mathematical function, typically using elliptic curve multiplication in blockchains. While it is easy to generate the public key from the private key, it is computationally infeasible to derive the private key from the public key, which is fundamental to the security of the system.
Question 30: What is the primary characteristic that distinguishes a consortium blockchain from a private blockchain?
- Transaction speeds are significantly slower.
- It is the only type that can execute smart contracts.
- It is completely open for anyone to join and validate.
- Governance is shared among multiple organizations. (Correct answer)
Correct answer: Governance is shared among multiple organizations.
The defining difference is governance. A private blockchain is controlled and operated by a single organization. A consortium blockchain is governed by a pre-selected group of organizations that share control and decision-making, making it semi-decentralized.
Certified Blockchain Expert (CBE)
The Certified Blockchain Expert (CBE) is a vendor-neutral certification by Blockchain Council that validates expertise in blockchain technology, covering distributed ledger concepts, consensus mechanisms, smart contracts, blockchain platforms, mining, and security for enterprise applications.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds