Certified Blockchain Solution Architect (CBSA) — Questions and Answers
Question 1: A CBSA candidate is evaluating blockchain platforms for a solution requiring 10,000+ TPS with sub-second finality. Which platform architecture best fits this requirement?
- Bitcoin with Lightning Network
- Ethereum mainnet with EIP-1559
- Algorand or similar pure PoS with pipelined consensus (Correct answer)
- Hyperledger Fabric with optimized endorsement policy
Correct answer: Algorand or similar pure PoS with pipelined consensus
Pure Proof-of-Stake platforms with pipelined consensus (like Algorand) are designed to achieve thousands of TPS with near-instant finality without off-chain layer-2 solutions.
Question 2: What is the purpose of a bug bounty program in the context of blockchain security?
- Incentivizing external researchers to responsibly disclose vulnerabilities (Correct answer)
- Compensating auditors for completed smart contract reviews
- Paying node operators to report consensus failures
- Rewarding miners who find and report empty blocks
Correct answer: Incentivizing external researchers to responsibly disclose vulnerabilities
Bug bounty programs offer financial rewards to security researchers who discover and responsibly disclose vulnerabilities, leveraging the broader security community to find issues before malicious actors do.
Question 3: In Ethereum's Proof of Stake, what is the consequence of a validator performing a 'slashable offense' such as double voting?
- A portion of the validator's staked ETH is burned and they are ejected (Correct answer)
- The validator's rewards are withheld for 30 days
- The validator is temporarily suspended for one epoch
- The validator must re-stake with a larger minimum deposit
Correct answer: A portion of the validator's staked ETH is burned and they are ejected
Slashing penalizes validators for equivocation or surround voting by destroying part of their stake and forcibly removing them from the validator set to deter attacks.
Question 4: In smart contract security, what is a 'front-running' attack?
- A miner or bot observing a pending transaction and submitting a competing transaction with higher gas to execute first (Correct answer)
- Draining a contract by calling its fallback function repeatedly
- Deploying a malicious contract before the legitimate one to claim the same address
- Exploiting integer overflow to wrap token balances to the maximum value
Correct answer: A miner or bot observing a pending transaction and submitting a competing transaction with higher gas to execute first
Front-running exploits the public mempool by placing a higher-gas transaction ahead of a known pending one to profit from the anticipated outcome.
Question 5: In Hyperledger Fabric, what is chaincode equivalent to in Ethereum's smart contract ecosystem?
- Oracles
- Validators
- Smart contracts (Correct answer)
- Gas meters
Correct answer: Smart contracts
Chaincode in Hyperledger Fabric is the equivalent of smart contracts, defining business logic that runs on the permissioned ledger.
Question 6: Stellar's Federated Byzantine Agreement (FBA) differs from classical BFT because:
- It only works in permissioned blockchain networks
- It requires all nodes to agree on the same validator set
- Each node defines its own quorum slice, enabling decentralized trust (Correct answer)
- It uses Proof of Work as a fallback mechanism
Correct answer: Each node defines its own quorum slice, enabling decentralized trust
FBA allows each node to choose which nodes it trusts (quorum slices), enabling open membership while still achieving Byzantine fault tolerance without a globally fixed validator set.
Question 7: What role does a 'proposer' play in most BFT consensus protocols?
- It adjusts the mining difficulty target for the network
- It collects and orders transactions into a candidate block for validators to vote on (Correct answer)
- It distributes validator rewards at the end of each epoch
- It verifies the digital signatures of all transactions in a block
Correct answer: It collects and orders transactions into a candidate block for validators to vote on
In BFT protocols, the proposer (or leader) is responsible for collecting pending transactions, forming a candidate block, and broadcasting it to validators who then cast votes.
Question 8: Which consensus mechanism is best suited for a permissioned blockchain deployment where throughput is the primary concern and all participants are trusted?
- Delegated Byzantine Fault Tolerant (dBFT)
- Proof of Work (PoW)
- Crash Fault Tolerant (CFT) ordering like Raft (Correct answer)
- Proof of Stake (PoS)
Correct answer: Crash Fault Tolerant (CFT) ordering like Raft
CFT ordering services like Raft are optimized for high throughput in permissioned networks where Byzantine behavior (malicious nodes) is not a concern.
Question 9: A pharmaceutical company wants to prevent counterfeit drugs from entering the supply chain. Which blockchain capability is MOST critical for this use case?
- Immutable provenance tracking (Correct answer)
- Decentralized consensus voting
- Tokenization of assets
- Smart contract automation
Correct answer: Immutable provenance tracking
Immutable provenance tracking ensures each drug's origin and chain of custody is permanently recorded and tamper-proof, directly combating counterfeiting.
Question 10: Algorand's Pure Proof of Stake consensus uses cryptographic sortition to select committee members. What is the key advantage of this approach?
- It guarantees every token holder gets an equal number of committee slots
- It eliminates the need for validators to maintain online nodes
- It requires committee members to stake tokens for exactly 24 hours
- Selection is private and non-interactive, preventing targeted attacks on future committee members (Correct answer)
Correct answer: Selection is private and non-interactive, preventing targeted attacks on future committee members
Algorand's VRF-based sortition allows each user to privately and locally determine if they are selected, so potential committee members are unknown to attackers until they reveal their selection.
Question 11: Which consensus mechanism is generally considered most resistant to Sybil attacks due to its economic cost requirement?
- Proof of Stake (PoS)
- Proof of Work (PoW) (Correct answer)
- Proof of Authority (PoA)
- Delegated Proof of Stake (DPoS)
Correct answer: Proof of Work (PoW)
Proof of Work requires real computational resources and energy expenditure, making it economically prohibitive to create enough fake identities to compromise the network.
Question 12: A consortium is creating a blockchain-based platform for trading voluntary carbon credits. A key requirement is to prevent the 'double counting' of credits, where the same credit is sold or claimed multiple times. How does tokenizing carbon credits on a blockchain solve this specific problem?
- By making all transaction data permanently public and transparent.
- By assigning a unique digital token to each verified carbon credit, which can be tracked from issuance to retirement on an immutable ledger. (Correct answer)
- By increasing the liquidity of the carbon market, making it easier to buy and sell credits.
- By using smart contracts to automatically purchase credits when emissions are reported.
Correct answer: By assigning a unique digital token to each verified carbon credit, which can be tracked from issuance to retirement on an immutable ledger.
Tokenization creates a unique digital representation for each distinct carbon credit. This token can be tracked on the blockchain's immutable ledger throughout its lifecycle. When the credit is 'used' or retired to offset emissions, the transaction is recorded permanently, preventing that specific token (and its underlying credit) from ever being sold or used again, thus solving the double-counting problem.
Question 13: What security risk does an 'oracle problem' introduce to smart contract systems?
- Decentralized networks cannot maintain synchronized time references
- Smart contracts cannot process off-chain data natively, creating a trusted data feed dependency (Correct answer)
- Oracle databases are incompatible with blockchain storage formats
- External APIs expose smart contracts to denial-of-service attacks
Correct answer: Smart contracts cannot process off-chain data natively, creating a trusted data feed dependency
The oracle problem arises because smart contracts cannot securely access off-chain data themselves, requiring trusted intermediaries (oracles) that become potential single points of failure or manipulation.
Question 14: Which ERC standard defines a 'vault' interface standardizing how yield-bearing tokens represent shares of underlying assets?
- ERC-1967
- ERC-777
- ERC-3525
- ERC-4626 (Correct answer)
Correct answer: ERC-4626
ERC-4626 standardizes tokenized vault interfaces used by DeFi yield aggregators, making vaults composable across protocols.
Question 15: In a seafood supply chain use case, blockchain is used to trace fish from catch to consumer. Which data element is LEAST useful to record on-chain?
- The recipe used by the restaurant serving the fish (Correct answer)
- Cold chain temperature readings during transport
- Vessel license and certification numbers
- GPS coordinates at time of catch
Correct answer: The recipe used by the restaurant serving the fish
Restaurant recipes are not supply chain provenance data and have no impact on food safety, authenticity, or traceability — they belong in the restaurant's own systems, not on a shared ledger.
Question 16: What is the primary risk of storing sensitive data directly in a smart contract's storage on a public blockchain?
- The Ethereum VM does not support storing string data types
- On-chain storage is deleted after 256 blocks
- It significantly increases gas costs beyond practical limits
- All data stored on-chain is publicly visible, so no truly sensitive data should be stored in plain text (Correct answer)
Correct answer: All data stored on-chain is publicly visible, so no truly sensitive data should be stored in plain text
Blockchain storage is public and permanent, so storing sensitive plaintext data (e.g., private keys, PII) on-chain exposes it to anyone.
Question 17: A startup aims to tokenize high-value commercial real estate to enable fractional ownership. A primary challenge they face is convincing traditional real estate investors, who are unfamiliar with digital assets, to participate. This involves overcoming skepticism and demonstrating the legal and technical viability of the platform. Which of the following represents the MOST significant barrier to adoption for this use case?
- High energy consumption associated with Proof of Work.
- Regulatory uncertainty and the need for investor education. (Correct answer)
- Lack of high-speed consensus mechanisms.
- The inability of blockchain to store large property deed documents.
Correct answer: Regulatory uncertainty and the need for investor education.
The most significant hurdle for real estate tokenization is not purely technical but rooted in market and legal factors. Regulatory frameworks for tokenized property are still evolving, creating legal uncertainty. Furthermore, educating a traditional market about the complexities and benefits of blockchain, digital wallets, and smart contracts is a major challenge to building trust and driving adoption.
Question 18: A financial consortium is designing a private, permissioned blockchain for inter-bank settlements. The key requirements are high transaction throughput, low latency, and deterministic finality, as transactions cannot be reversed once confirmed. The number of participating banks (nodes) is known and will be less than 50. Which consensus mechanism is most suitable for this solution?
- Proof of Work (PoW)
- Practical Byzantine Fault Tolerance (PBFT) (Correct answer)
- Proof of Stake (PoS)
- Proof of Capacity (PoC)
Correct answer: Practical Byzantine Fault Tolerance (PBFT)
Practical Byzantine Fault Tolerance (PBFT) is ideal for permissioned or private blockchain networks where the participants are known. It provides high throughput and low latency because it does not require computationally intensive puzzle-solving like PoW. Most importantly, PBFT offers deterministic finality, meaning a transaction, once approved by the required number of nodes (typically 2/3), is final and cannot be reverted, which is a critical requirement for financial settlements. PoW and PoS only offer probabilistic finality. PoC is also not suitable as it is designed for permissionless networks and focuses on storage capacity rather than speed and finality.
Question 19: What is an 'Optimistic Rollup' in Layer 2 blockchain scaling?
- A Layer 2 solution that batches off-chain transactions and assumes their validity, relying on fraud proofs during a challenge window (Correct answer)
- A sharding approach that optimistically pre-assigns validators to shards
- A rollup that assumes all transactions are invalid until cryptographically proven otherwise
- A consensus mechanism designed for faster block production on Layer 1
Correct answer: A Layer 2 solution that batches off-chain transactions and assumes their validity, relying on fraud proofs during a challenge window
Optimistic Rollups assume transactions are valid by default and allow a challenge period during which verifiers can submit fraud proofs to dispute invalid state transitions.
Question 20: What is the main advantage of using a token curated registry (TCR) in a blockchain ecosystem?
- It replaces smart contract auditing with community voting
- It uses token-based incentives to crowdsource the curation of a trusted list (Correct answer)
- It provides a decentralized token exchange mechanism
- It automatically generates tokens for new users
Correct answer: It uses token-based incentives to crowdsource the curation of a trusted list
A TCR aligns financial incentives so that token holders who curate accurately are rewarded, creating a self-governing, spam-resistant list maintained by economic stakeholders.
Question 21: Which ERC standard extends ERC-20 to allow token approvals and transfers to be performed in a single transaction via off-chain signatures?
- ERC-2612 (Correct answer)
- ERC-777
- ERC-4626
- ERC-1155
Correct answer: ERC-2612
ERC-2612 adds a `permit` function that uses EIP-712 typed signatures to set allowances without a separate on-chain approval transaction.
Question 22: What is the primary purpose of a bug bounty program in blockchain security architecture?
- Rewarding users who hold tokens for longer periods
- Incentivizing external researchers to responsibly disclose vulnerabilities before exploitation (Correct answer)
- Compensating validators for honest block production
- Funding smart contract audits from the protocol treasury
Correct answer: Incentivizing external researchers to responsibly disclose vulnerabilities before exploitation
Bug bounty programs offer financial rewards to ethical hackers who discover and responsibly report security vulnerabilities, expanding the security testing surface beyond internal teams.
Question 23: What problem does the EIP-712 standard solve for smart contract interactions?
- It compresses ABI-encoded data to reduce transaction costs
- It introduces a new consensus mechanism for smart contract execution
- It defines a universal token transfer protocol replacing ERC-20
- It standardizes structured data hashing and signing so users can read what they're approving in wallet UIs (Correct answer)
Correct answer: It standardizes structured data hashing and signing so users can read what they're approving in wallet UIs
EIP-712 provides a structured, human-readable format for off-chain signatures, preventing users from blindly signing opaque hex data they cannot understand.
Question 24: When evaluating a blockchain use case for cross-border remittances, which factor most differentiates blockchain from traditional SWIFT transfers?
- Higher transaction throughput
- Elimination of currency conversion fees
- Near-instant settlement without correspondent banks (Correct answer)
- Stronger regulatory compliance tools
Correct answer: Near-instant settlement without correspondent banks
Blockchain enables direct settlement between parties without correspondent banks, dramatically reducing settlement time from days to minutes or seconds.
Question 25: A consortium of financial institutions is building a trade finance platform. A key requirement is that the details of a trade agreement (a 'state') should only be shared between the transacting parties and a designated notary service that validates the transaction's uniqueness. Other members of the consortium should not have access to this data. Which enterprise blockchain platform is architecturally designed around this 'need-to-know' data distribution model, avoiding a global broadcast of transaction data?
- Hyperledger Besu
- Hyperledger Fabric
- R3 Corda (Correct answer)
- ConsenSys Quorum
Correct answer: R3 Corda
R3 Corda is architected with a primary focus on privacy and does not broadcast ledger data globally. Instead, it shares transaction data only among the necessary participants (peers and a Notary). This peer-to-peer model, combined with a UTXO-style ledger where states are consumed and created, directly fits the requirement. Hyperledger Fabric uses channels and private data collections for privacy, but its fundamental model involves an ordering service that sees all transactions within a channel. Quorum and Besu are based on Ethereum and use private transaction managers to segregate data, but the default architecture is more broadcast-oriented than Corda's.
Question 26: What is the role of an oracle in a decentralized application ecosystem?
- To provide external real-world data to smart contracts that cannot access off-chain information natively (Correct answer)
- To store encrypted smart contract source code
- To validate block headers on behalf of light clients
- To aggregate user transactions into rollup batches
Correct answer: To provide external real-world data to smart contracts that cannot access off-chain information natively
Oracles bridge the gap between blockchains and the external world, feeding data like prices or weather into smart contracts.
Question 27: Which Hyperledger project focuses on supply chain use cases and provides asset tracking capabilities with event-driven architecture?
- Hyperledger Aries
- Hyperledger Caliper
- Hyperledger Cactus
- Hyperledger Grid (Correct answer)
Correct answer: Hyperledger Grid
Hyperledger Grid is a platform for building supply chain solutions, providing domain-specific data models and smart contract standards for tracking goods and assets.
Question 28: In Delegated Proof of Stake (DPoS), token holders participate in consensus by:
- Solving cryptographic puzzles proportional to their stake
- Voting for a fixed set of elected delegates who produce blocks (Correct answer)
- Locking tokens in a smart contract to earn rewards directly
- Running full mining nodes themselves
Correct answer: Voting for a fixed set of elected delegates who produce blocks
DPoS uses a democratic voting model where token holders elect delegates (witnesses/block producers) who are responsible for block production and validation.
Question 29: A blockchain architect needs to integrate a legacy ERP system with a Hyperledger Fabric network. Which integration pattern is most appropriate?
- Store all ERP data directly on-chain using a public Ethereum contract
- Use an off-chain oracle service to bridge data between the ERP and chaincode (Correct answer)
- Replace the ERP with a native blockchain application
- Disable the ERP and migrate all business logic to smart contracts
Correct answer: Use an off-chain oracle service to bridge data between the ERP and chaincode
An oracle service bridges off-chain legacy systems with on-chain chaincode, enabling data exchange without replacing existing infrastructure.
Question 30: What is the 'oracle problem' in the context of blockchain use cases involving real-world data?
- The difficulty of achieving consensus among blockchain nodes
- The problem of storing large files on-chain
- The inability of smart contracts to handle complex logic
- The challenge of securely and reliably bringing off-chain data onto the blockchain (Correct answer)
Correct answer: The challenge of securely and reliably bringing off-chain data onto the blockchain
The oracle problem refers to the trust challenge of feeding real-world data (prices, weather, events) into smart contracts without introducing a centralized point of failure.
Question 31: In designing token emission schedules, what is the trade-off between high early inflation and low long-term inflation?
- High early inflation increases token price; low long-term inflation decreases trading volume
- High early inflation improves network latency; low inflation worsens it
- High early inflation attracts validators but dilutes early investors; low long-term inflation ensures scarcity but may reduce validator incentives as fees must cover security costs (Correct answer)
- High early inflation reduces smart contract gas costs; low inflation increases them
Correct answer: High early inflation attracts validators but dilutes early investors; low long-term inflation ensures scarcity but may reduce validator incentives as fees must cover security costs
Front-loaded emission bootstraps network security and participation, but must transition to a fee-based security model as inflation drops, requiring sufficient organic transaction volume to maintain validator incentives.
Certified Blockchain Solution Architect (CBSA)
The CBSA certification validates a candidate's skills in designing and architecting blockchain-based solutions, covering blockchain fundamentals, architecture patterns, consensus mechanisms, smart contracts, and real-world use cases. It is offered by the Blockchain Training Alliance (BTA).
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds