Certified Blockchain Security Expert (CBSE) — Questions and Answers
Question 1: A QA engineer wants to test that a smart contract's time-lock mechanism cannot be bypassed using block timestamp manipulation. Which test setup is required?
- Deploy on mainnet and wait for the lock period to expire
- Use a local testnet where block timestamps can be manually set to future values (Correct answer)
- Run the contract through a gas estimator
- Audit the Solidity source code for block.timestamp usage
Correct answer: Use a local testnet where block timestamps can be manually set to future values
A local testnet with controllable timestamps lets testers simulate miner timestamp manipulation to verify that the time-lock cannot be bypassed.
Question 2: Which attack vector does a threat model for a public blockchain's mempool primarily need to address regarding transaction ordering?
- 51% attacks
- Sybil attacks
- Replay attacks
- Miner Extractable Value (MEV) front-running (Correct answer)
Correct answer: Miner Extractable Value (MEV) front-running
MEV front-running exploits the ability of miners/validators to reorder, insert, or censor pending transactions in the mempool for profit.
Question 3: How does blockchain security expertise contribute to the blockchain ecosystem?
- By making blockchain networks faster and more scalable
- By developing new blockchain platforms for decentralized finance
- By increasing the transparency of blockchain transactions
- By ensuring the safety and integrity of blockchain-based solutions (Correct answer)
Correct answer: By ensuring the safety and integrity of blockchain-based solutions
The core purpose of blockchain security expertise is to protect blockchain networks and applications from vulnerabilities and attacks. By ensuring the safety and integrity of these solutions, experts maintain trust, prevent data breaches, and enable the reliable and secure operation of the entire blockchain ecosystem, which is crucial for its widespread adoption.
Question 4: A tester discovers that a DeFi protocol's oracle aggregator accepts a single data source. What vulnerability class does this represent?
- Denial of service
- Integer overflow
- Access control bypass
- Single point of failure / oracle manipulation (Correct answer)
Correct answer: Single point of failure / oracle manipulation
Relying on a single oracle source creates a single point of failure that attackers can manipulate to feed false price data.
Question 5: Which blockchain-specific threat involves an attacker deliberately delaying block propagation to increase the chance that their competing block is accepted?
- Long-range attack
- Eclipse attack
- Grinding attack
- Selfish mining (Correct answer)
Correct answer: Selfish mining
Selfish mining withholds discovered blocks to gain a disproportionate share of block rewards by forcing honest miners to waste work on orphaned chains.
Question 6: Which architectural decision most directly reduces the blast radius of a compromised smart contract in a DeFi protocol?
- Using a monolithic contract to minimize inter-contract call overhead
- Storing all protocol funds in a single treasury contract
- Maximizing on-chain logic to reduce oracle dependency
- Implementing circuit breakers with emergency pause functionality per module (Correct answer)
Correct answer: Implementing circuit breakers with emergency pause functionality per module
Per-module circuit breakers allow operators to halt only the compromised component, preserving the rest of the protocol during an incident.
Question 7: In a blockchain network, what does 'finality' mean from a security design perspective?
- Transactions are encrypted after a set number of blocks
- Peer nodes have all downloaded the full chain history
- A confirmed transaction cannot be reversed or altered by any subsequent event (Correct answer)
- The smart contract bytecode is frozen after deployment
Correct answer: A confirmed transaction cannot be reversed or altered by any subsequent event
Finality guarantees that once a transaction achieves a sufficient confirmation depth or BFT commit, it is irreversible—critical for settlement security.
Question 8: What is the key advantage of using ECDSA over RSA for digital signatures in blockchain systems?
- ECDSA uses prime factorization for faster verification
- ECDSA provides equivalent security with significantly smaller key sizes (Correct answer)
- ECDSA supports symmetric encryption natively
- ECDSA does not require a random number generator
Correct answer: ECDSA provides equivalent security with significantly smaller key sizes
ECDSA achieves equivalent cryptographic security to RSA but with much smaller keys (e.g., 256-bit ECC ≈ 3072-bit RSA), reducing storage and bandwidth overhead.
Question 9: A developer is creating an ERC-20 token contract using Solidity version 0.7.0. The `transfer` function subtracts the amount from the sender's balance without using a safe math library. What vulnerability could a user with a balance of 100 tokens exploit if they try to transfer 110 tokens?
- Integer Underflow (Correct answer)
- Reentrancy
- Short Address Attack
- Denial of Service
Correct answer: Integer Underflow
Integer underflow happens when an arithmetic operation results in a value smaller than the minimum value for that data type, causing it to wrap around to the maximum value. In Solidity versions before 0.8.0, subtracting 110 from 100 would underflow the `uint` balance, resulting in a very large number instead of reverting the transaction. Modern Solidity versions (0.8.0+) have built-in protection against this.
Question 10: A blockchain network administrator is hardening a new full node to minimize its attack surface. Which of the following is the MOST critical first step to protect the node from known software vulnerabilities?
- Encrypting the blockchain data at rest using AES-256.
- Configuring strict role-based access control (RBAC) for administrative access.
- Implementing a host-based intrusion detection system (HIDS).
- Ensuring the blockchain client software and operating system are fully patched and up to date. (Correct answer)
Correct answer: Ensuring the blockchain client software and operating system are fully patched and up to date.
The most critical initial step in hardening any server, including a blockchain node, is to patch and update all software. Attackers frequently exploit known vulnerabilities in outdated software to gain access. While HIDS, RBAC, and encryption are all important security controls, they are secondary to ensuring the fundamental software components are not exposed to well-known exploits.
Question 11: Which CBSE curriculum topic covers the security implications of using oracles in decentralized applications?
- Key Management
- Network Layer Attacks
- Consensus Security
- DeFi and Oracle Security (Correct answer)
Correct answer: DeFi and Oracle Security
DeFi and Oracle Security is the CBSE domain that examines how oracles introduce off-chain data trust assumptions and can be manipulated to compromise on-chain logic.
Question 12: What is the primary security risk associated with upgradeable proxy contracts in DeFi?
- The proxy admin can silently replace the implementation with malicious logic without user consent (Correct answer)
- Higher deployment gas costs
- Reduced EVM compatibility
- Increased smart contract size limits
Correct answer: The proxy admin can silently replace the implementation with malicious logic without user consent
Upgradeable proxies introduce centralized control — a compromised or malicious admin can swap in exploit code, defeating the trustlessness of DeFi.
Question 13: In the Ethereum Merge's PoS design, what happens to a validator that goes offline for an extended period during non-emergency conditions?
- The validator incurs inactivity leak penalties that gradually reduce its effective balance (Correct answer)
- The validator is permanently banned from re-staking on the network
- The validator is immediately slashed and ejected from the validator set
- The validator's stake is redistributed to active validators as a reward
Correct answer: The validator incurs inactivity leak penalties that gradually reduce its effective balance
Inactivity leaks drain inactive validators' balances quadratically over time, incentivizing return to participation and enabling the network to recover finality if too many validators go offline.
Question 14: Which of the following describes a length extension attack and which hash construction is vulnerable to it?
- Forging a valid hash by appending data; SHA-2 Merkle-Damgård constructions are vulnerable (Correct answer)
- Finding two inputs with the same hash; SHA-3 is vulnerable
- Recovering the input from a hash; bcrypt is vulnerable
- Generating a pre-image from a hash; BLAKE2 is vulnerable
Correct answer: Forging a valid hash by appending data; SHA-2 Merkle-Damgård constructions are vulnerable
Length extension attacks exploit Merkle-Damgård construction internals (used by SHA-256) to compute H(key||message||extension) without knowing the key.
Question 15: In a blockchain transaction, what is the primary purpose of a digital signature?
- To reduce the size of the transaction data for faster processing.
- To provide proof of the sender's identity (authentication) and guarantee the message has not been altered (non-repudiation and integrity). (Correct answer)
- To encrypt the transaction data for confidentiality.
- To ensure the transaction can be reversed if incorrect.
Correct answer: To provide proof of the sender's identity (authentication) and guarantee the message has not been altered (non-repudiation and integrity).
A digital signature in a blockchain transaction cryptographically proves that the transaction was authorized by the holder of the private key (authentication), ensures the transaction data has not been tampered with (integrity), and prevents the sender from later denying they sent the transaction (non-repudiation).
Question 16: Which mitigation directly addresses the risk of a compromised or malicious contract being set as the logic implementation in an upgradeable proxy?
- Replacing delegatecall with staticcall for all implementation calls
- Compiling the proxy with optimizer runs set to zero
- Disabling selfdestruct in the implementation contract
- Using a timelocked upgrade process with a multi-signature governance requirement (Correct answer)
Correct answer: Using a timelocked upgrade process with a multi-signature governance requirement
A timelock combined with multi-sig governance ensures no single party can instantly swap in malicious logic; stakeholders have a window to detect and cancel a malicious upgrade.
Question 17: Which consensus mechanism is most vulnerable to a 'long-range attack' where an adversary rewrites blockchain history from genesis?
- Proof of Work
- Delegated Proof of Stake
- Proof of Authority
- Proof of Stake (Correct answer)
Correct answer: Proof of Stake
Pure Proof-of-Stake systems are susceptible to long-range attacks because old private keys can be used to rewrite history without requiring ongoing computational resources.
Question 18: A Proof-of-Stake blockchain is experiencing a chain fork. A validator decides to validate transactions and create blocks on both forked chains simultaneously to maximize their potential rewards, regardless of which chain ultimately becomes canonical. What specific security vulnerability does this action represent?
- Nothing-at-Stake Problem (Correct answer)
- Eclipse Attack
- 51% Attack
- Selfish Mining
Correct answer: Nothing-at-Stake Problem
The Nothing-at-Stake problem is unique to Proof-of-Stake consensus mechanisms. It describes a scenario where, because creating blocks has a low marginal cost, validators are incentivized to vote for multiple blockchain forks, as there is no financial penalty for doing so. This behavior can destabilize the consensus process and make the network more susceptible to double-spending attacks.
Question 19: What does 'signature replay' mean in smart contract security?
- Replaying past oracle price data to manipulate on-chain state
- Copying source code from a verified contract to disguise malicious logic
- Resending the same Ethereum transaction multiple times to drain gas
- Reusing a valid cryptographic signature from a past transaction to authorize a new, unintended one (Correct answer)
Correct answer: Reusing a valid cryptographic signature from a past transaction to authorize a new, unintended one
A replay attack re-submits a legitimately signed message on the same or a different chain/contract where no nonce or chainId prevents its reuse.
Question 20: Which network-layer defense is most effective at preventing IP-spoofing-based amplification attacks targeting blockchain gossip protocols?
- Using proof-of-stake consensus
- BCP 38 ingress filtering at the ISP or router level (Correct answer)
- Increasing block size limits
- Enabling verbose node logging
Correct answer: BCP 38 ingress filtering at the ISP or router level
BCP 38 (RFC 2827) ingress filtering drops packets with spoofed source IPs at the network perimeter, preventing spoofed-source amplification attacks.
Question 21: What security property does 'onion routing' (Tor) provide when used to connect blockchain nodes to the P2P network?
- End-to-end encryption stronger than standard TLS
- Faster transaction confirmation by routing through low-latency exit nodes
- IP address anonymization, preventing network-level deanonymization of node operators (Correct answer)
- Guaranteed delivery of transactions even under network congestion
Correct answer: IP address anonymization, preventing network-level deanonymization of node operators
Tor masks the node's real IP address by routing traffic through multiple encrypted relays, preventing adversaries from linking a transaction to a specific IP address.
Question 22: In the context of blockchain key management, a BIP-39 mnemonic phrase encodes entropy as:
- A sequence of random bytes stored in plain text
- An AES-encrypted version of the private key
- A base64-encoded representation of the public key
- A list of 12–24 words derived from a standardized wordlist that encodes the wallet seed (Correct answer)
Correct answer: A list of 12–24 words derived from a standardized wordlist that encodes the wallet seed
BIP-39 converts entropy (128–256 bits) into 12–24 human-readable words from a 2048-word list, making wallet backup more reliable and user-friendly.
Question 23: A team is in the final stages of testing their dApp. They require an environment that closely mimics the public mainnet, including unpredictable block times and potential network congestion, to conduct a final public test run without using real assets. Which environment best suits this need?
- A local development blockchain like Ganache
- A public testnet like Sepolia (Correct answer)
- A private consortium network
- A static analysis tool like Slither
Correct answer: A public testnet like Sepolia
Public testnets (like Sepolia for Ethereum) are designed to simulate the real mainnet environment as closely as possible. They are publicly accessible and use valueless test tokens, allowing developers and users to experience real-world network conditions (e.g., latency, congestion) before a mainnet deployment.
Question 24: A security architect wants to enable contract upgradability while preserving immutability guarantees. Which pattern achieves this?
- Use a self-destruct function and redeploy with the same address
- Redeploy the contract with a new address each upgrade
- Use a proxy contract that delegates calls to a separate, swappable logic contract (Correct answer)
- Store all logic in contract storage slots to allow in-place editing
Correct answer: Use a proxy contract that delegates calls to a separate, swappable logic contract
The proxy-delegate pattern keeps a stable address and storage while allowing the implementation logic contract to be replaced by the owner.
Question 25: Which best describes a Sybil attack in the context of blockchain networks, as covered in the CBSE curriculum?
- An attacker intercepts transactions between two nodes to alter their content
- An attacker floods the network with high-fee transactions to delay legitimate ones
- An attacker reverse-engineers a wallet's private key from its public key
- An attacker creates multiple fake identities to gain disproportionate influence over the network (Correct answer)
Correct answer: An attacker creates multiple fake identities to gain disproportionate influence over the network
In a Sybil attack, the adversary creates many pseudonymous nodes to subvert reputation systems or gain majority voting power in consensus.
Question 26: An enterprise is building a consortium blockchain and needs a secure architecture for managing the private keys of its member organizations. The primary goals are to prevent key compromise from a single point of failure and to allow for key recovery procedures. Which solution best meets these architectural requirements?
- Using a Hardware Security Module (HSM) combined with an M-of-N multi-signature scheme for access. (Correct answer)
- Distributing unencrypted keys to all system administrators.
- Requiring each member to store their key on a single, air-gapped laptop.
- Storing all private keys in an encrypted, cloud-hosted database.
Correct answer: Using a Hardware Security Module (HSM) combined with an M-of-N multi-signature scheme for access.
A Hardware Security Module (HSM) provides a physically secure environment for key generation and signing operations, while an M-of-N multi-signature scheme ensures that multiple authorized parties (M) out of a total group (N) must approve an action. This combination prevents a single point of failure, protects against theft, and enables secure, distributed recovery protocols, making it ideal for enterprise key management.
Question 27: A blockchain node operator notices abnormally high CPU usage caused by peers repeatedly requesting the same large block. Which denial-of-service technique is being used?
- Timejacking
- Replay attack
- Block withholding attack
- Bandwidth exhaustion via block re-request flooding (Correct answer)
Correct answer: Bandwidth exhaustion via block re-request flooding
Flooding a node with repeated large-block requests wastes CPU and bandwidth resources, constituting a bandwidth exhaustion DoS against that node.
Question 28: A blockchain validator node is targeted by an attacker who controls 51% of peers and delays block propagation to all other honest nodes. What is this strategy called?
- Selfish mining
- Fee sniping
- Network partitioning with block withholding (Correct answer)
- Long-range attack
Correct answer: Network partitioning with block withholding
By partitioning the honest network and withholding new blocks, the attacker can force honest miners onto a stale chain while the attacker's chain grows ahead.
Question 29: A security analyst is reviewing a new public blockchain protocol. The protocol uses a Proof-of-Stake consensus mechanism where validators are penalized for downtime but not for signing conflicting blocks. The analyst flags a major security risk. What is the MOST likely risk they identified?
- Long-Range Attack (Correct answer)
- Centralization of stake
- Resource Exhaustion Attack
- 51% Attack
Correct answer: Long-Range Attack
A Long-Range Attack is a significant vulnerability in some PoS systems. An attacker acquires old private keys from former validators and uses them to create a long alternative chain from a much earlier point in the blockchain's history. Without penalties (slashing) for signing conflicting blocks (equivocation), there is little to stop validators on this new fork. The lack of such penalties is a key enabler for this type of attack.
Question 30: When applying PASTA threat modeling to a blockchain application, which phase involves simulating realistic attack scenarios using threat intelligence?
- Phase 7 – Risk and Impact Analysis
- Phase 6 – Attack Enumeration and Modeling (Correct answer)
- Phase 2 – Define Technical Scope
- Phase 5 – Vulnerability and Weakness Analysis
Correct answer: Phase 6 – Attack Enumeration and Modeling
Phase 6 of PASTA focuses on enumerating and simulating attacker-centric scenarios using threat intelligence to model how identified weaknesses could be exploited.
Question 31: Which of the following describes a Denial of Service (DoS) vulnerability caused by an unbounded loop in a smart contract function that distributes rewards to a list of users?
- A malicious user provides a malformed address that causes the external call to fail, reverting the entire transaction.
- An attacker repeatedly calls the function to drain its ether balance through reentrancy.
- The function's gas cost grows with the number of users, eventually exceeding the block gas limit and becoming impossible to execute. (Correct answer)
- The contract relies on a manipulatable timestamp, allowing an attacker to claim rewards indefinitely.
Correct answer: The function's gas cost grows with the number of users, eventually exceeding the block gas limit and becoming impossible to execute.
A common DoS vector in smart contracts occurs when a function iterates over an array that can grow indefinitely (unbounded). As more users are added, the gas required to execute the loop increases. Eventually, the total gas cost will exceed the block gas limit, making the function impossible to call successfully and effectively freezing that functionality. This can trap funds or render the contract unusable.
Question 32: Which TLS/SSL configuration weakness most directly endangers communications between blockchain node peers over an encrypted channel?
- Enforcing mutual certificate authentication
- Allowing TLS 1.0 with RC4 cipher suites (Correct answer)
- Using TLS 1.3 with forward secrecy
- Using ECDHE key exchange
Correct answer: Allowing TLS 1.0 with RC4 cipher suites
TLS 1.0 with RC4 is cryptographically broken; RC4 has known biases that allow plaintext recovery, compromising the confidentiality of peer communications.
Question 33: A developer proposes storing AES-encrypted sensitive data on a public blockchain with the decryption key held by the user. What is the primary long-term architectural risk?
- Nodes will refuse to store non-native token data
- Quantum computing advances could decrypt historically stored ciphertext (Correct answer)
- Key rotation is impossible because data is immutable
- High gas costs for large encrypted payloads
Correct answer: Quantum computing advances could decrypt historically stored ciphertext
Ciphertext stored permanently on-chain could be decrypted by future quantum computers, exposing sensitive data years after it was written.
Question 34: Which domain of the CBSE curriculum specifically addresses vulnerabilities in Ethereum smart contract code?
- Blockchain Fundamentals
- Smart Contract Security (Correct answer)
- Cryptographic Protocols
- Consensus Mechanism Analysis
Correct answer: Smart Contract Security
Smart Contract Security is the CBSE domain dedicated to identifying and remediating vulnerabilities such as reentrancy, integer overflow, and access control flaws in smart contract code.
Question 35: What is a 'front-running' attack in the context of decentralized exchanges (DEXs)?
- Stealing private keys from mempool data
- Exploiting a reentrancy bug before the developer can patch it
- Submitting a higher-gas transaction to execute before a pending victim transaction and profit from the price change (Correct answer)
- Deploying a contract before the target contract is deployed
Correct answer: Submitting a higher-gas transaction to execute before a pending victim transaction and profit from the price change
Front-running (a form of MEV) involves observing a pending transaction in the mempool and submitting a competing transaction with higher gas to be mined first.
Question 36: In HD (Hierarchical Deterministic) wallets defined by BIP-32, child private keys are derived using HMAC-SHA512 applied to:
- The master seed and the block height
- The transaction hash and the derivation index
- The wallet password and a random salt
- The parent public key (or private key) and a chain code (Correct answer)
Correct answer: The parent public key (or private key) and a chain code
BIP-32 child key derivation uses HMAC-SHA512 with the parent key material and chain code as inputs, producing a deterministic child key and new chain code.
Question 37: What is a 'tx.origin' attack in Ethereum smart contracts?
- Sending transactions with a forged origin address
- Using tx.origin instead of msg.sender for authorization, which can be exploited via phishing contracts (Correct answer)
- Manipulating the transaction fee to bypass checks
- Overflowing the call stack via recursive calls
Correct answer: Using tx.origin instead of msg.sender for authorization, which can be exploited via phishing contracts
tx.origin returns the original external account that initiated the call chain, so a malicious intermediate contract can trick a victim into authorizing an action unintentionally.
Question 38: In Practical Byzantine Fault Tolerance (PBFT), the protocol phases are prepare, pre-prepare, and commit. Which phase ensures that all honest nodes agree on a single value before committing?
- View-change phase
- Prepare phase (Correct answer)
- Commit phase
- Pre-prepare phase
Correct answer: Prepare phase
The prepare phase collects 2f+1 matching prepare messages (where f is the fault threshold), ensuring quorum agreement on the proposed value before the commit phase finalizes it.
Question 39: What is the security implication of running a blockchain node with the '--rpcallowip=0.0.0.0/0' flag in Bitcoin Core?
- It enables faster block validation by allowing parallel RPC calls
- It disables transaction broadcast to external peers
- It forces all wallet operations through a hardware security module
- It exposes the RPC server to all IP addresses, allowing any host to send commands (Correct answer)
Correct answer: It exposes the RPC server to all IP addresses, allowing any host to send commands
Setting rpcallowip to 0.0.0.0/0 removes IP-based access control on the RPC port, allowing any internet host to issue wallet and node-management commands.
Question 40: Which statement accurately reflects the global recognition of the CBSE certification?
- It is recognized only within the United States due to regulatory restrictions
- It is recognized solely by Ethereum Foundation partners
- It is accepted exclusively by government agencies as a hiring requirement
- It is internationally recognized as a benchmark for blockchain security expertise (Correct answer)
Correct answer: It is internationally recognized as a benchmark for blockchain security expertise
The CBSE enjoys international recognition among blockchain and cybersecurity professionals, employers, and organizations worldwide.
Question 41: What is the role of 'checkpoint' blocks in Bitcoin's security model against certain network-level history-rewriting attacks?
- They prevent a node from accepting a chain that diverges before a known-good block hash, blocking deep reorg attacks (Correct answer)
- They speed up initial block download by skipping signature verification before the checkpoint
- They create mandatory hard forks at defined block heights
- They act as backup copies of the blockchain stored on developer servers
Correct answer: They prevent a node from accepting a chain that diverges before a known-good block hash, blocking deep reorg attacks
Hardcoded checkpoints make it computationally infeasible to feed a node a completely different chain history before those points, protecting against long-range reorg attacks.
Question 42: What distinguishes a 'bribery attack' from a traditional 51% attack on a PoS network?
- A bribery attack requires the attacker to already hold 51% of the stake
- A bribery attack exploits smart contract bugs to redirect staking rewards
- A bribery attack temporarily purchases votes from existing validators rather than acquiring majority stake outright (Correct answer)
- A bribery attack targets miners instead of validators
Correct answer: A bribery attack temporarily purchases votes from existing validators rather than acquiring majority stake outright
In a bribery attack, the adversary incentivizes existing validators to vote for a specific fork by paying them more than their honest staking reward, bypassing the need to own a majority of stake.
Question 43: A blockchain development team is choosing a public-key cryptography algorithm for their new platform. They require high security with smaller key sizes to optimize for speed and reduce storage demands. Which algorithm best meets these requirements?
- RSA (Rivest-Shamir-Adleman)
- SHA-256
- AES (Advanced Encryption Standard)
- ECC (Elliptic Curve Cryptography) (Correct answer)
Correct answer: ECC (Elliptic Curve Cryptography)
Elliptic Curve Cryptography (ECC) provides the same level of security as other algorithms like RSA but with significantly smaller key sizes. This efficiency reduces computational overhead and storage requirements, making it ideal for resource-constrained environments and blockchain applications where performance is critical.
Question 44: A blockchain uses SHA-256 to hash block headers. An attacker wants to find an input that hashes to a specific target value. Which property prevents this?
- Pre-image resistance (Correct answer)
- Determinism
- Collision resistance
- Second pre-image resistance
Correct answer: Pre-image resistance
Pre-image resistance ensures that given a hash output H(x), it is computationally infeasible to find any input x that produces that output.
Question 45: Which consensus property is sacrificed when a blockchain network prioritizes availability and partition tolerance according to the CAP theorem?
- Sybil resistance
- Safety (consistency) (Correct answer)
- Finality
- Liveness
Correct answer: Safety (consistency)
Per CAP theorem, choosing availability and partition tolerance means the system may return stale or conflicting state, sacrificing strong consistency (safety).
Question 46: In a blockchain node security test, what does testing for 'eclipse attack' resistance verify?
- That the node rejects blocks with invalid Merkle roots
- That RPC endpoints require authentication
- That an attacker cannot monopolize all of a node's peer connections to isolate it from the honest network (Correct answer)
- That the node correctly validates proof-of-work difficulty
Correct answer: That an attacker cannot monopolize all of a node's peer connections to isolate it from the honest network
Eclipse attack testing attempts to fill a target node's peer table with attacker-controlled peers, verifying that peer diversity and eviction policies prevent full isolation.
Question 47: An attacker compromises DNS servers used by a blockchain node to resolve seed node hostnames. What class of attack does this represent, and what is the best mitigation?
- A replay attack; mitigated by transaction nonces
- A DNS hijacking attack; mitigated by using hardcoded seed IP addresses or DNSSEC-validated lookups (Correct answer)
- A Finney attack; mitigated by waiting for multiple confirmations
- A nothing-at-stake attack; mitigated by slashing conditions
Correct answer: A DNS hijacking attack; mitigated by using hardcoded seed IP addresses or DNSSEC-validated lookups
DNS hijacking redirects seed node lookups to attacker-controlled IPs; hardcoded seed IPs or DNSSEC prevents reliance on a poisoned DNS response for initial peer discovery.
Question 48: What does a 'storage collision' test in upgradeable proxy contracts verify?
- That only the admin can trigger an upgrade
- That the proxy correctly delegates calls to the implementation
- That upgrade operations emit the correct events
- That the proxy and implementation contracts do not declare state variables at the same storage slots (Correct answer)
Correct answer: That the proxy and implementation contracts do not declare state variables at the same storage slots
Storage collision testing ensures that proxy and implementation storage layouts do not overlap, which would cause one contract to corrupt the other's state.
Question 49: A blockchain threat model categorizes a threat as affecting 'availability' of the network. Which specific attack does this BEST describe?
- A transaction flooding DoS attack that fills the mempool and blocks legitimate transactions (Correct answer)
- A front-running attack exploiting MEV
- A private key theft leading to asset loss
- A reentrancy attack draining contract funds
Correct answer: A transaction flooding DoS attack that fills the mempool and blocks legitimate transactions
Transaction flooding is a denial-of-service attack that exhausts mempool capacity, preventing legitimate transactions from being included in blocks.
Question 50: Which attack exploits predictable block timestamps or weak randomness beacons in PoS to manipulate validator selection?
- Selfish mining
- Eclipse attack
- Finney attack
- Grinding attack (Correct answer)
Correct answer: Grinding attack
A grinding attack lets a block proposer iterate through candidate block headers to find a value that biases the randomness function toward selecting themselves or allies as future proposers.
Question 51: Which audit technique is most effective for discovering integer overflow vulnerabilities in Solidity contracts older than version 0.8.0?
- Dynamic fuzz testing with maximum uint256 boundary values (Correct answer)
- Checking the Solidity pragma version alone is sufficient
- Running the contract through an ERC-20 linter
- Reviewing only the Natspec documentation for missing SafeMath references
Correct answer: Dynamic fuzz testing with maximum uint256 boundary values
Fuzz testing with extreme boundary values (e.g., type(uint256).max) automatically surfaces wrap-around behavior that manual review or linting may miss.
Question 52: Which type of attack exploits the gossip protocol's rebroadcast mechanism to exhaust a target node's network bandwidth?
- Vampire attack (resource exhaustion via repeated connection requests)
- Replay attack across forks
- Side-channel cache timing attack
- Transaction flooding / spam attack (Correct answer)
Correct answer: Transaction flooding / spam attack
Transaction flooding sends a high volume of low-fee or zero-fee transactions that propagate through the gossip network, consuming bandwidth and mempool memory on every node.
Question 53: Which threat does the 'nothing-at-stake' problem primarily affect in blockchain consensus design?
- Proof-of-Work mining centralization
- Byzantine fault tolerance threshold
- Proof-of-Stake validator equivocation (Correct answer)
- Sybil resistance in permissioned networks
Correct answer: Proof-of-Stake validator equivocation
In early Proof-of-Stake designs, validators faced no cost for signing multiple conflicting forks, enabling double-spend attacks without economic penalty.
Question 54: In a token-curated registry (TCR) implemented as a smart contract, which governance attack involves an adversary accumulating a majority of voting tokens to control list inclusion decisions?
- Plutocracy / token concentration attack (Correct answer)
- Flash loan governance attack
- Griefing attack via spam applications
- Time-lock bypass through delegate voting
Correct answer: Plutocracy / token concentration attack
Token concentration allows a wealthy adversary to dominate votes on which entries are included or excluded, centralizing control of a supposedly decentralized registry.
Question 55: In ECDSA signature generation, reusing the same nonce k for two different messages with the same private key results in:
- An invalid signature that the network rejects
- A stronger signature that is harder to forge
- Exposure of the private key to any observer (Correct answer)
- A collision in the hash of the signed message
Correct answer: Exposure of the private key to any observer
If the same nonce k is used to sign two different messages, an attacker can solve for the private key algebraically using the two signature equations.
Question 56: A security analyst is performing a threat modeling exercise on a new DeFi lending protocol. The protocol uses a decentralized price oracle to determine asset values for collateralization. A potential threat identified is that an attacker could manipulate the oracle's price feed to cause unfair liquidations. Using the DREAD model to rate this threat, which component would likely score the highest?
- Damage Potential (Correct answer)
- Discoverability
- Affected Users
- Reproducibility
Correct answer: Damage Potential
The Damage Potential of a successful price oracle manipulation attack on a DeFi lending protocol is extremely high, as it could lead to the mass liquidation of user positions and the theft of millions of dollars in collateral. While other DREAD components are relevant, the potential for catastrophic financial loss makes Damage Potential the most significant factor.
Question 57: Which of the following cryptographic primitives is primarily used in blockchain to ensure data integrity and create a unique, fixed-size fingerprint of transaction data?
- Symmetric Encryption
- Cryptographic Hash Functions (Correct answer)
- Asymmetric Encryption
- Digital Signatures
Correct answer: Cryptographic Hash Functions
Cryptographic hash functions are fundamental to blockchain technology for ensuring data integrity. They take an input of any size and produce a fixed-size output (a hash). Any change to the input data results in a completely different hash, making it easy to detect tampering. This property is crucial for linking blocks together in a chain and for creating Merkle trees.
Question 58: A tester is evaluating a blockchain bridge contract and wants to confirm that a double-spend via replayed Merkle proofs is impossible. Which test is most appropriate?
- Verify that the bridge emits a Deposit event for each transfer
- Check that the bridge contract's Ether balance matches total deposits
- Submit the same valid Merkle proof twice and verify the second claim is rejected (Correct answer)
- Test that the bridge owner can pause the contract
Correct answer: Submit the same valid Merkle proof twice and verify the second claim is rejected
Replaying an already-processed Merkle proof tests whether the bridge contract tracks used proofs and correctly rejects duplicates.
Question 59: Which testing approach is most appropriate for validating that a permissioned blockchain's access control policies are correctly enforced at the network layer?
- Network-level penetration testing with unauthorized node identities (Correct answer)
- Unit testing of smart contract modifiers
- Merkle root verification
- Gas profiling of transactions
Correct answer: Network-level penetration testing with unauthorized node identities
Network-level penetration testing using unauthorized node certificates or identities directly tests whether the permissioning layer rejects unauthorized participants.
Question 60: A threat model rates a vulnerability with high likelihood but low impact. How should this be prioritized compared to a low-likelihood, high-impact threat?
- Always prioritize the high-likelihood threat regardless of impact
- Defer both threats since neither scores maximum on both axes
- Use risk scoring (likelihood × impact) to compare and prioritize objectively (Correct answer)
- Always prioritize the high-impact threat regardless of likelihood
Correct answer: Use risk scoring (likelihood × impact) to compare and prioritize objectively
Risk scoring multiplies likelihood and impact to produce a comparable risk value, enabling objective prioritization across asymmetric threat profiles.
Question 61: When testing a blockchain application, which of the following presents a unique and fundamental challenge not typically encountered when testing traditional, centralized web applications?
- Verifying database read/write permissions for different user roles.
- Ensuring the application's user interface is responsive on mobile devices.
- Checking for cross-browser compatibility issues in the front-end code.
- The immutability of deployed on-chain code and the difficulty of patching bugs. (Correct answer)
Correct answer: The immutability of deployed on-chain code and the difficulty of patching bugs.
The immutability of the blockchain is a core principle that makes it fundamentally different from traditional systems. Once a smart contract is deployed, its code cannot be easily altered. This makes fixing bugs post-deployment exceptionally difficult and expensive, placing immense importance on thorough pre-deployment testing. Traditional applications, by contrast, can be patched and redeployed with relative ease.
Question 62: Which wallet type provides the strongest protection against remote network-based attacks?
- Cold wallet stored on an air-gapped hardware device (Correct answer)
- Mobile wallet with biometric authentication
- Browser-based web wallet
- Hot wallet connected to an exchange
Correct answer: Cold wallet stored on an air-gapped hardware device
Cold wallets store private keys offline on air-gapped devices, making them immune to remote or network-based attacks since keys never touch an internet-connected system.
Question 63: Which consensus security property ensures that if two honest nodes both finalize a block, those blocks must be the same block?
- Safety (agreement) (Correct answer)
- Termination
- Liveness
- Accountability
Correct answer: Safety (agreement)
Safety (also called agreement or consistency) guarantees that no two correct nodes ever commit different values at the same block height.
Question 64: Which best describes the relationship between the CBSE and the Certified Blockchain Expert (CBE) credential?
- The CBSE covers general blockchain topics while the CBE covers only security
- The CBE is a prerequisite for the CBSE, which focuses specifically on security (Correct answer)
- The CBE is a government-issued license, while the CBSE is vendor-specific
- They are identical certifications offered under different names
Correct answer: The CBE is a prerequisite for the CBSE, which focuses specifically on security
The CBE provides broad blockchain expertise that serves as a recommended foundation, while the CBSE builds on that with a security-focused specialization.
Question 65: Which LINDDUN privacy threat category is most relevant when a blockchain's transaction graph allows de-anonymization of user identities?
- Non-repudiation
- Detectability
- Linkability (Correct answer)
- Unawareness
Correct answer: Linkability
Linkability in LINDDUN describes the ability to correlate transactions or identities across a system, enabling de-anonymization in transparent blockchains.
Question 66: What is the key difference between cryptographic hashing and encryption in the context of blockchain security?
- Hashing is a one-way function primarily for data integrity, while encryption is a two-way function for data confidentiality. (Correct answer)
- Encryption is a one-way function, while hashing is a two-way function.
- Hashing is used for data confidentiality, while encryption is used for data integrity.
- Hashing is a reversible process, while encryption is irreversible.
Correct answer: Hashing is a one-way function primarily for data integrity, while encryption is a two-way function for data confidentiality.
The fundamental difference is reversibility and purpose. Hashing is a one-way, irreversible function that converts data into a unique digest to verify integrity. Encryption is a two-way, reversible process that converts plaintext to ciphertext and back again using a key, with the primary goal of ensuring data confidentiality.
Question 67: Which vulnerability exists when a proxy contract's 'implementation' storage slot overlaps with a variable in the implementation contract?
- Reentrancy through delegatecall
- Access control misconfiguration in the proxy admin
- Storage collision between proxy and implementation (Correct answer)
- Uninitialized proxy
Correct answer: Storage collision between proxy and implementation
If the proxy stores the implementation address in slot 0 and the implementation also writes to slot 0, the implementation address can be overwritten by normal operations.
Question 68: During smart contract testing, a developer notices that arithmetic on uint8 values silently wraps at 255 in older Solidity versions. Which mitigation should the test verify is in place?
- Casting all uint8 values to uint256 before display
- Adding a require statement only on subtraction operations
- Using unchecked blocks for all arithmetic
- Use of the SafeMath library or Solidity ^0.8.x built-in overflow checks (Correct answer)
Correct answer: Use of the SafeMath library or Solidity ^0.8.x built-in overflow checks
SafeMath or Solidity 0.8.x automatic overflow/underflow reversion prevents silent wraparound that attackers can exploit to manipulate balances.
Question 69: A security audit finds that a contract's constructor sets the owner to msg.sender but the contract is deployed via a factory. What test reveals the resulting ownership vulnerability?
- Test that the constructor can only be called once
- Call the transferOwnership function as a non-owner
- Deploy the contract via the factory and verify whether the factory contract or the intended user is recorded as owner (Correct answer)
- Deploy the contract directly and verify the owner is the deployer
Correct answer: Deploy the contract via the factory and verify whether the factory contract or the intended user is recorded as owner
When a factory deploys a contract, msg.sender is the factory address, not the end user, so the factory may unintentionally become the owner.
Question 70: A CBSE candidate is auditing a cross-chain bridge. Which vulnerability class has caused the largest losses in bridge hacks?
- Token decimal mismatch
- Event log indexing errors
- Gas optimization errors
- Improper validation of cross-chain message signatures allowing forged mint approvals (Correct answer)
Correct answer: Improper validation of cross-chain message signatures allowing forged mint approvals
The Ronin ($625M) and Wormhole ($320M) hacks both exploited insufficient signature validation on cross-chain messages, enabling unauthorized minting.
Question 71: Which Solidity visibility specifier should be avoided on sensitive functions to prevent unauthorized external access?
- private
- internal
- public (without an access modifier check) (Correct answer)
- view
Correct answer: public (without an access modifier check)
Marking a sensitive function public without a role-based guard exposes it to all external callers, enabling unauthorized state changes or fund extraction.
Question 72: Delegated Proof-of-Stake (DPoS) introduces which unique centralization-related security risk compared to standard PoS?
- An inability to fork the chain in response to protocol bugs
- Validators losing stake due to network latency rather than malicious behavior
- Block rewards being distributed unevenly among token holders
- Collusion among a small set of elected delegates to censor transactions or double-spend (Correct answer)
Correct answer: Collusion among a small set of elected delegates to censor transactions or double-spend
DPoS concentrates block-production power in a small elected group, making delegate collusion or cartel formation a realistic attack vector.
Question 73: What is a 'grinding attack' in the context of Proof-of-Stake consensus?
- A miner repeatedly re-mines the same block to earn double rewards
- An adversary degrades peer connections to force network partitions
- An adversary iterates over many block header values to bias the next validator selection (Correct answer)
- An attacker floods the network with low-fee transactions to stall consensus
Correct answer: An adversary iterates over many block header values to bias the next validator selection
In a grinding attack, a validator tries many candidate block values to manipulate the randomness source used for future leader selection.
Question 74: A blockchain architect wants to ensure that even the infrastructure provider cannot read stored contract state. Which technique best achieves confidential smart contract execution?
- Symmetric key sharing among all validator nodes
- Storing state in IPFS with access-controlled pinning
- AES-256 encryption of transaction data before submission
- Trusted Execution Environments (TEE) such as Intel SGX for contract computation (Correct answer)
Correct answer: Trusted Execution Environments (TEE) such as Intel SGX for contract computation
TEEs provide hardware-enforced enclaves where code executes and state remains encrypted even from the host operating system and infrastructure provider.
Question 75: When creating a comprehensive threat model for a decentralized application (dApp), why is it insufficient to only analyze the on-chain components like smart contracts?
- Because all dApp logic is contained within the smart contract.
- Because on-chain threat modeling is already handled by the blockchain's consensus mechanism.
- Because smart contracts are immutable and cannot be changed once deployed.
- Because dApps also include off-chain components like web front-ends and wallets which introduce their own attack surfaces. (Correct answer)
Correct answer: Because dApps also include off-chain components like web front-ends and wallets which introduce their own attack surfaces.
A complete dApp architecture includes not just the on-chain smart contracts but also off-chain elements like user interfaces (web front-ends), wallets, and backend services that interact with the blockchain. These components have their own vulnerabilities (e.g., XSS, insecure key storage) that must be included in a holistic threat model.
Question 76: A blockchain design uses a separate chain for high-frequency micropayments that periodically settles to the main chain. This pattern is best described as:
- State channel / payment channel
- Cross-chain atomic swap
- Sharding
- Sidechain (Correct answer)
Correct answer: Sidechain
A sidechain runs independently with its own consensus and periodically anchors or transfers assets back to the main chain.
Question 77: In threat modeling a blockchain's governance mechanism, which attack does vote delegation with no time-lock primarily enable?
- A Sybil attack using multiple validator identities
- A long-range attack rewriting governance history
- A flash loan governance attack where borrowed tokens manipulate a vote within a single block (Correct answer)
- An eclipse attack isolating governance nodes
Correct answer: A flash loan governance attack where borrowed tokens manipulate a vote within a single block
Without a time-lock between delegation and voting, an attacker can borrow a large token balance via flash loan, cast a decisive vote, then repay the loan—all in one transaction.
Question 78: In Solidity, which pattern best mitigates reentrancy attacks by updating state before making external calls?
- Pull-over-push pattern
- Factory pattern
- Oracle pattern
- Checks-Effects-Interactions pattern (Correct answer)
Correct answer: Checks-Effects-Interactions pattern
The Checks-Effects-Interactions pattern mandates updating all state variables before interacting with external contracts, preventing reentrancy.
Question 79: Which type of exam format does the CBSE certification primarily use?
- Oral interview with a panel of experts
- Portfolio submission and review
- Open-book essay format
- Multiple-choice questions administered in a proctored environment (Correct answer)
Correct answer: Multiple-choice questions administered in a proctored environment
The CBSE exam consists of multiple-choice questions delivered in a proctored, computer-based testing environment.
Question 80: A development team is building a decentralized application (dApp) for supply chain management. During the threat modeling process, they focus on ensuring that once a shipment's status is recorded on the blockchain, no party, including the originator, can deny having submitted that transaction. Which security principle is central to this requirement?
- Integrity
- Non-repudiation (Correct answer)
- Availability
- Confidentiality
Correct answer: Non-repudiation
Non-repudiation is the security principle that ensures a party cannot deny the authenticity of their signature on a document or the sending of a message that they originated. In blockchain, cryptographic signatures provide strong non-repudiation, as a valid transaction signature can only be created with the corresponding private key.
Certified Blockchain Security Expert (CBSE)
The CBSE certification by 101 Blockchains validates expertise in blockchain security across threat modeling, cryptography, consensus algorithm security, smart contract security, node/network security, and enterprise blockchain security. It is designed for security professionals seeking to identify and mitigate risks in blockchain ecosystems.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds