Certified Blockchain Security Expert (CBSE) — Questions and Answers
Question 1: What is a 'front-running' attack in the context of decentralized exchanges (DEXs)?
- Submitting a higher-gas transaction to execute before a pending victim transaction and profit from the price change (Correct answer)
- Stealing private keys from mempool data
- Deploying a contract before the target contract is deployed
- Exploiting a reentrancy bug before the developer can patch it
Correct answer: Submitting a higher-gas transaction to execute before a pending victim transaction and profit from the price change
Front-running (a form of MEV) involves observing a pending transaction in the mempool and submitting a competing transaction with higher gas to be mined first.
Question 2: Which consensus-layer test verifies that a Byzantine node cannot force honest nodes to accept an invalid block?
- Byzantine fault tolerance (BFT) test (Correct answer)
- Sybil resistance test
- Peer discovery test
- Throughput benchmark
Correct answer: Byzantine fault tolerance (BFT) test
BFT testing injects nodes that send conflicting or invalid messages and checks whether honest nodes still reach correct consensus.
Question 3: A zero-knowledge proof allows a prover to convince a verifier of a statement's truth without revealing:
- The hash of the statement
- Any information beyond the validity of the statement itself (Correct answer)
- The public key used in the proof
- The identity of the verifier
Correct answer: Any information beyond the validity of the statement itself
Zero-knowledge proofs allow the prover to demonstrate knowledge of a secret (e.g., a private key) without disclosing any information about the secret itself.
Question 4: In Byzantine Fault Tolerant (BFT) consensus, what is the maximum fraction of faulty nodes the system can tolerate while still reaching agreement?
- Less than two-thirds of all nodes
- Less than one-half of all nodes
- Less than one-third of all nodes (Correct answer)
- Any fraction, as long as faulty nodes are identified
Correct answer: Less than one-third of all nodes
Classical BFT requires that fewer than one-third of nodes are Byzantine (malicious or faulty) to guarantee safety and liveness.
Question 5: In blockchain threat modeling, a 'long-range attack' targets which specific consensus vulnerability?
- Manipulating timestamps to artificially lower mining difficulty
- Exploiting weak randomness in block proposer selection
- Using old private keys from early validators to rewrite chain history from a past checkpoint (Correct answer)
- Flooding the network with forked blocks to exhaust peer connections
Correct answer: Using old private keys from early validators to rewrite chain history from a past checkpoint
A long-range attack uses old but valid private keys to construct an alternative chain history from a distant block, threatening proof-of-stake chain integrity.
Question 6: Which attack exploits predictable block timestamps or weak randomness beacons in PoS to manipulate validator selection?
- Selfish mining
- Eclipse attack
- Finney attack
- Grinding attack (Correct answer)
Correct answer: Grinding attack
A grinding attack lets a block proposer iterate through candidate block headers to find a value that biases the randomness function toward selecting themselves or allies as future proposers.
Question 7: A security architect wants to enable contract upgradability while preserving immutability guarantees. Which pattern achieves this?
- Use a proxy contract that delegates calls to a separate, swappable logic contract (Correct answer)
- Store all logic in contract storage slots to allow in-place editing
- Redeploy the contract with a new address each upgrade
- Use a self-destruct function and redeploy with the same address
Correct answer: Use a proxy contract that delegates calls to a separate, swappable logic contract
The proxy-delegate pattern keeps a stable address and storage while allowing the implementation logic contract to be replaced by the owner.
Question 8: Which of the following correctly describes the role of a verifiable random function (VRF) in blockchain protocols like Algorand?
- It enables threshold signatures where the random value is only revealed after f+1 nodes agree
- It produces a publicly verifiable pseudorandom output tied to a private key, used for unpredictable but provable leader election (Correct answer)
- It provides a commitment to future random values used in smart contract lotteries
- It generates entropy for mining nonces that cannot be predicted by any single node
Correct answer: It produces a publicly verifiable pseudorandom output tied to a private key, used for unpredictable but provable leader election
VRFs let a node produce a random output along with a proof that the output was correctly computed from their private key, enabling fair and verifiable leader selection without a trusted third party.
Question 9: What fundamentally distinguishes a non-custodial wallet from a custodial wallet?
- In a non-custodial wallet, the user alone controls and holds their private keys (Correct answer)
- Custodial wallets are always implemented as hardware devices
- Non-custodial wallets support a wider range of cryptocurrencies
- Non-custodial wallets always require identity verification
Correct answer: In a non-custodial wallet, the user alone controls and holds their private keys
Non-custodial wallets give users full ownership of their private keys, whereas custodial wallets have a third party (such as an exchange) holding keys on the user's behalf.
Question 10: A DeFi protocol loses $10M in an exploit. The team considers a 'white hat rescue' by front-running the attacker. What is the primary risk of this approach?
- It increases gas fees for normal users
- It may constitute unauthorized access and expose the team to legal liability (Correct answer)
- It triggers a consensus fork
- It permanently disables the protocol
Correct answer: It may constitute unauthorized access and expose the team to legal liability
Even well-intentioned front-running to rescue funds can be legally ambiguous and may violate the Computer Fraud and Abuse Act (CFAA).
Question 11: Which cryptographic primitive is used in Bitcoin's Proof-of-Work to create a target-meeting hash?
- RIPEMD-160
- SHA-256 applied twice (SHA-256d) (Correct answer)
- HMAC-SHA256
- Keccak-256
Correct answer: SHA-256 applied twice (SHA-256d)
Bitcoin's Proof-of-Work uses double SHA-256 (SHA-256 of SHA-256) on the block header to produce a hash that must be below the network difficulty target.
Question 12: During threat modeling of a permissioned blockchain, which trust boundary is MOST critical to define between the ordering service and peer nodes?
- The database replication boundary
- The block gas limit enforcement point
- The boundary between the user wallet and the UI
- The boundary where consensus messages are validated and authenticated (Correct answer)
Correct answer: The boundary where consensus messages are validated and authenticated
The ordering service-to-peer boundary is critical because unauthenticated consensus messages could allow a compromised orderer to inject invalid blocks.
Question 13: What is a 'finality reversion' attack in the context of PoS blockchains, and what condition makes it theoretically possible?
- An attacker bribes miners to orphan finalized blocks after the fact
- An attacker uses quantum computing to reverse cryptographic signatures on finalized blocks
- An attacker reverses a finalized block by accumulating more than 1/3 of stake to prevent supermajority agreement on the next checkpoint (Correct answer)
- An attacker replays old transactions to roll back account balances
Correct answer: An attacker reverses a finalized block by accumulating more than 1/3 of stake to prevent supermajority agreement on the next checkpoint
Reversing finality in Casper-style PoS requires the attacker to equivocate with enough stake to break the 2/3 supermajority, which is detectable and subject to severe slashing penalties.
Question 14: What does the 'binding' property of a cryptographic commitment scheme guarantee?
- The verifier cannot determine the committed value before it is revealed
- The commitment can only be opened by the original committer
- The committer cannot change the committed value after publishing the commitment (Correct answer)
- The committer cannot reveal the committed value to a third party
Correct answer: The committer cannot change the committed value after publishing the commitment
Binding ensures that once a commitment is published, the committer is bound to a specific value and cannot later open the commitment to a different value.
Question 15: In the context of blockchain node security, what does 'peer banning' accomplish?
- It permanently removes a transaction from the mempool
- It blacklists a misbehaving peer's IP address so the node will not reconnect to it (Correct answer)
- It prevents a peer from broadcasting blocks larger than 1 MB
- It revokes a node's mining license on permissioned chains
Correct answer: It blacklists a misbehaving peer's IP address so the node will not reconnect to it
Peer banning records an offending IP in a ban list and refuses future connections from that address for a configurable period, isolating misbehaving or malicious peers.
Question 16: A security auditor finds that a blockchain node's configuration file stores the RPC password in plaintext. What is the recommended remediation?
- Move the config file to a world-readable location for convenience
- Encrypt the config file with AES-256 and store the key in the same directory
- Use rpcauth with a salted HMAC-SHA256 hash instead of rpcpassword (Correct answer)
- Disable RPC entirely and use the P2P interface for all operations
Correct answer: Use rpcauth with a salted HMAC-SHA256 hash instead of rpcpassword
Bitcoin Core's rpcauth option stores a salted hash of the password so the plaintext credential never resides in the config file.
Question 17: Which of the following describes a Denial of Service (DoS) vulnerability caused by an unbounded loop in a smart contract function that distributes rewards to a list of users?
- An attacker repeatedly calls the function to drain its ether balance through reentrancy.
- A malicious user provides a malformed address that causes the external call to fail, reverting the entire transaction.
- The contract relies on a manipulatable timestamp, allowing an attacker to claim rewards indefinitely.
- The function's gas cost grows with the number of users, eventually exceeding the block gas limit and becoming impossible to execute. (Correct answer)
Correct answer: The function's gas cost grows with the number of users, eventually exceeding the block gas limit and becoming impossible to execute.
A common DoS vector in smart contracts occurs when a function iterates over an array that can grow indefinitely (unbounded). As more users are added, the gas required to execute the loop increases. Eventually, the total gas cost will exceed the block gas limit, making the function impossible to call successfully and effectively freezing that functionality. This can trap funds or render the contract unusable.
Question 18: A blockchain architect wants to ensure that even the infrastructure provider cannot read stored contract state. Which technique best achieves confidential smart contract execution?
- AES-256 encryption of transaction data before submission
- Trusted Execution Environments (TEE) such as Intel SGX for contract computation (Correct answer)
- Symmetric key sharing among all validator nodes
- Storing state in IPFS with access-controlled pinning
Correct answer: Trusted Execution Environments (TEE) such as Intel SGX for contract computation
TEEs provide hardware-enforced enclaves where code executes and state remains encrypted even from the host operating system and infrastructure provider.
Question 19: What is the primary security goal of encrypting communication channels between blockchain nodes using protocols like TLS?
- To prevent Sybil attacks by validating node identities.
- To maintain the confidentiality and integrity of peer-to-peer messages against eavesdropping and man-in-the-middle attacks. (Correct answer)
- To ensure the immutability of the blockchain ledger.
- To increase the speed of transaction propagation across the network.
Correct answer: To maintain the confidentiality and integrity of peer-to-peer messages against eavesdropping and man-in-the-middle attacks.
Transport Layer Security (TLS) is used to encrypt data in transit. In a blockchain network, it secures the communication channels between nodes. This prevents eavesdroppers from reading the messages (confidentiality) and protects against attackers altering messages while they are in transit (integrity), which constitutes a man-in-the-middle attack. While crucial for network security, it does not directly ensure ledger immutability or prevent Sybil attacks, which are handled by cryptographic hashing/consensus and consensus mechanism design, respectively.
Question 20: A threat model identifies that an attacker can intercept peer-to-peer gossip messages between blockchain nodes. Which control BEST mitigates this threat?
- Implementing TLS/noise protocol encryption for P2P communication (Correct answer)
- Enabling token-based access control
- Using a proof-of-work consensus
- Increasing block confirmation requirements
Correct answer: Implementing TLS/noise protocol encryption for P2P communication
Encrypting P2P communication with TLS or noise protocol prevents eavesdropping and man-in-the-middle attacks on gossip traffic.
Question 21: What is a 'tx.origin' attack in Ethereum smart contracts?
- Sending transactions with a forged origin address
- Manipulating the transaction fee to bypass checks
- Overflowing the call stack via recursive calls
- Using tx.origin instead of msg.sender for authorization, which can be exploited via phishing contracts (Correct answer)
Correct answer: Using tx.origin instead of msg.sender for authorization, which can be exploited via phishing contracts
tx.origin returns the original external account that initiated the call chain, so a malicious intermediate contract can trick a victim into authorizing an action unintentionally.
Question 22: What does a negative gas limit test in Ethereum smart contract testing verify?
- That the contract reverts when gas exceeds the block limit
- That miners can set arbitrary gas prices
- That gas estimation tools return accurate values
- That the EVM rejects transactions with an invalid or zero gas limit (Correct answer)
Correct answer: That the EVM rejects transactions with an invalid or zero gas limit
Testing with zero or invalid gas limits verifies that the EVM correctly rejects malformed transactions before execution.
Question 23: A public blockchain network is experiencing a volumetric Distributed Denial-of-Service (DDoS) attack where nodes are being flooded with an overwhelming amount of transaction and peer discovery requests, exhausting their bandwidth. Which technique would be most effective in mitigating this type of attack?
- Auditing smart contracts for reentrancy vulnerabilities.
- Mandating Know Your Customer (KYC) for all node operators.
- Implementing rate limiting on API endpoints and filtering traffic with a Web Application Firewall (WAF) or similar service. (Correct answer)
- Increasing the block size limit of the blockchain.
Correct answer: Implementing rate limiting on API endpoints and filtering traffic with a Web Application Firewall (WAF) or similar service.
Volumetric DDoS attacks aim to consume all available bandwidth. The most direct and effective mitigation is to filter the malicious traffic before it reaches the node. Implementing rate limiting restricts the number of requests a single IP can make in a period, and using a WAF or a DDoS scrubbing service can help distinguish and block malicious traffic from legitimate traffic.
Question 24: A threat model document lists 'gas griefing' as a threat. What does this attack involve?
- A caller passing insufficient gas to a sub-call so it fails while the outer call succeeds, corrupting contract state (Correct answer)
- Artificially inflating gas prices to price out competitors in a gas auction
- Mining empty blocks to waste validators' computational resources
- Deploying contracts that consume all available block gas on deployment
Correct answer: A caller passing insufficient gas to a sub-call so it fails while the outer call succeeds, corrupting contract state
Gas griefing exploits contracts that forward user-supplied gas to sub-calls; by providing too little gas, an attacker causes a sub-call revert without reverting the outer call.
Question 25: What cryptographic mechanism enables a node to prove it possesses a valid credential without revealing the credential itself during network authentication?
- Hash-based message authentication
- Symmetric key exchange
- Threshold signature
- Zero-knowledge proof (Correct answer)
Correct answer: Zero-knowledge proof
Zero-knowledge proofs let a prover convince a verifier of a statement's truth without disclosing the underlying secret.
Question 26: Which scenario represents a front-running attack on a blockchain, a topic assessed in the CBSE exam?
- A miner delays publishing a valid block to collect more transaction fees from the mempool
- An attacker sends duplicate transactions to cause a double-spend on a PoW network
- A node operator shuts down its node to reduce network participation during an election
- A validator observes a pending transaction in the mempool and submits a competing transaction with a higher gas fee to execute first (Correct answer)
Correct answer: A validator observes a pending transaction in the mempool and submits a competing transaction with a higher gas fee to execute first
Front-running exploits the transparency of the mempool: an attacker sees a profitable pending transaction and inserts their own with higher priority fees to execute ahead of it.
Question 27: A tester is evaluating a blockchain bridge contract and wants to confirm that a double-spend via replayed Merkle proofs is impossible. Which test is most appropriate?
- Submit the same valid Merkle proof twice and verify the second claim is rejected (Correct answer)
- Test that the bridge owner can pause the contract
- Verify that the bridge emits a Deposit event for each transfer
- Check that the bridge contract's Ether balance matches total deposits
Correct answer: Submit the same valid Merkle proof twice and verify the second claim is rejected
Replaying an already-processed Merkle proof tests whether the bridge contract tracks used proofs and correctly rejects duplicates.
Question 28: What is the primary security function of a blockchain oracle in a smart contract architecture?
- Providing authenticated real-world data to on-chain contracts (Correct answer)
- Generating randomness for consensus leader election
- Validating block headers across sidechains
- Encrypting private keys for external accounts
Correct answer: Providing authenticated real-world data to on-chain contracts
Oracles act as trusted data bridges, feeding external facts (prices, events) into smart contracts that cannot natively access off-chain information.
Question 29: A tester discovers that a DeFi protocol's oracle aggregator accepts a single data source. What vulnerability class does this represent?
- Integer overflow
- Denial of service
- Single point of failure / oracle manipulation (Correct answer)
- Access control bypass
Correct answer: Single point of failure / oracle manipulation
Relying on a single oracle source creates a single point of failure that attackers can manipulate to feed false price data.
Question 30: In a Proof-of-Work blockchain, what condition must an attacker satisfy to execute a 51% attack successfully?
- Own more than half of all circulating tokens
- Control more than half of the network's total hash rate (Correct answer)
- Possess private keys for more than half of all wallets
- Compromise more than half of all validator nodes
Correct answer: Control more than half of the network's total hash rate
A 51% attack requires the attacker to control the majority of the network's computational hash rate, enabling them to rewrite recent blocks and double-spend.
Question 31: What does the term 'dusting attack' mean in blockchain security forensics?
- Sending tiny amounts of crypto to wallets to link them and de-anonymize their owners (Correct answer)
- A 51% attack on a dust-token network
- A denial-of-service attack on validator nodes
- Sprinkling malicious opcodes in contract bytecode
Correct answer: Sending tiny amounts of crypto to wallets to link them and de-anonymize their owners
Dusting sends microscopic amounts to wallets; when recipients move funds, analytics tools can cluster addresses and deanonymize them.
Question 32: An attacker observes a large buy order for a specific token in the mempool of a decentralized exchange. They quickly submit their own buy order for the same token with a higher gas fee, followed immediately by a sell order. What is this type of attack called?
- Integer Overflow
- Timestamp Dependency
- Unchecked External Call
- Front-Running (Sandwich Attack) (Correct answer)
Correct answer: Front-Running (Sandwich Attack)
This is a classic example of a front-running attack, specifically a 'sandwich attack'. The attacker sees a pending transaction in the mempool and places a transaction before it (by paying a higher gas fee) and another one after it. This allows them to profit from the price slippage caused by the victim's large trade.
Certified Blockchain Security Expert (CBSE)
The CBSE certification by 101 Blockchains validates expertise in blockchain security across threat modeling, cryptography, consensus algorithm security, smart contract security, node/network security, and enterprise blockchain security. It is designed for security professionals seeking to identify and mitigate risks in blockchain ecosystems.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds