Certified Cryptocurrency Auditor™ (CCA) — Questions and Answers
Question 1: For a crypto mining company, how should newly mined cryptocurrency rewards be initially recognized on the income statement?
- As a capital contribution since no cash changed hands
- As revenue at fair value on the date each block reward is received (Correct answer)
- As inventory at production cost (electricity + hardware depreciation)
- Deferred until the mined crypto is sold for fiat currency
Correct answer: As revenue at fair value on the date each block reward is received
Mined cryptocurrency rewards should be recognized as revenue at their fair value on the date received, as the mining company has provided a service (transaction validation) and earned the reward.
Question 2: When a crypto compliance officer discovers a potential OFAC sanctions violation, the first action should be to:
- Wait 30 days to see if OFAC issues a public notice
- Notify the counterparty that they are sanctioned
- Delete transaction records to limit liability
- Block the transaction and report to OFAC via the designated reporting mechanism (Correct answer)
Correct answer: Block the transaction and report to OFAC via the designated reporting mechanism
Upon identifying a potential OFAC violation, the correct response is to immediately block the transaction and self-report to OFAC, as voluntary disclosure can reduce penalties.
Question 3: During a cryptocurrency audit, an auditor finds that a exchange stores user seed phrases encrypted with a single master key. What is the primary risk identified?
- Insufficient transaction monitoring
- Regulatory non-compliance with AML requirements
- Single point of failure — compromise of the master key exposes all user seeds (Correct answer)
- Lack of multi-signature for withdrawals
Correct answer: Single point of failure — compromise of the master key exposes all user seeds
A single master key is a critical single point of failure; if it is compromised, all encrypted seed phrases become accessible, jeopardizing every user's funds.
Question 4: A company converts $1M of Bitcoin (held for 18 months) into USD to pay operating expenses. For U.S. tax purposes, how is this gain classified?
- Short-term capital gain regardless of holding period
- Long-term capital gain taxed at preferential rates since the holding period exceeds 12 months (Correct answer)
- Tax-exempt since it was used to pay business expenses
- Ordinary income since it was used for business operations
Correct answer: Long-term capital gain taxed at preferential rates since the holding period exceeds 12 months
Under IRS rules, Bitcoin held for more than 12 months qualifies for long-term capital gain treatment when sold or exchanged, regardless of what the proceeds are used for.
Question 5: A cryptocurrency exchange's audit reveals a discrepancy between the on-chain wallet balance and the internal customer ledger. What is the auditor's immediate next step?
- Suspend the audit pending management explanation
- Issue an immediate qualified opinion
- Trace all deposits and withdrawals on-chain against ledger entries to identify the source of the discrepancy (Correct answer)
- Report the exchange to FinCEN
Correct answer: Trace all deposits and withdrawals on-chain against ledger entries to identify the source of the discrepancy
The auditor should perform a detailed on-chain trace to reconcile every transaction against the internal ledger to identify whether the discrepancy is a recording error, theft, or fraud.
Question 6: What type of income is recognized when cryptocurrency is received as payment for goods or services?
- Capital gain income
- Passive income
- Tax-exempt income
- Ordinary income (Correct answer)
Correct answer: Ordinary income
Cryptocurrency received as payment for goods or services is treated as ordinary income equal to its fair market value at the time of receipt.
Question 7: What distinguishes a 'soft fork' from a 'hard fork' in blockchain protocol upgrades?
- Soft forks require majority miner support while hard forks do not
- Soft forks split the network permanently while hard forks merge it
- Hard forks only affect transaction fees while soft forks affect block size
- Soft forks are backward-compatible; hard forks are not (Correct answer)
Correct answer: Soft forks are backward-compatible; hard forks are not
A soft fork tightens validation rules so old nodes still accept new blocks, whereas a hard fork introduces rules that make new blocks invalid under the old protocol, requiring all participants to upgrade.
Question 8: What is the primary valuation challenge when accounting for cryptocurrency on financial statements?
- All cryptocurrencies trade at par value on regulated exchanges
- Valuation is simple because prices are always publicly available
- Price volatility and the lack of a single standardized pricing source (Correct answer)
- Cryptocurrencies have a fixed value set by central banks
Correct answer: Price volatility and the lack of a single standardized pricing source
The primary valuation challenge is significant price volatility combined with the absence of a single standardized pricing source, requiring entities to establish clear, consistent pricing policies.
Question 9: An auditor is reviewing a smart contract's token distribution function, which iterates through a large, externally-provided array of recipient addresses to execute transfers. As the number of recipients grows, transactions calling this function begin to fail consistently. What is the most likely vulnerability?
- Denial of Service (DoS) due to block gas limit (Correct answer)
- Reentrancy attack
- Integer underflow
- Timestamp dependence
Correct answer: Denial of Service (DoS) due to block gas limit
This design is vulnerable to a Denial of Service (DoS) attack. Each operation within the loop consumes gas. If the array of recipients becomes too large, the total gas required to complete the loop will exceed the block's gas limit, causing any transaction that calls this function to fail. An attacker could potentially exploit this by adding many addresses to the distribution list to render the function unusable, trapping the funds.
Question 10: When auditing a cryptocurrency exchange, which control is most critical for verifying that customer assets are properly segregated from exchange operating funds?
- Proof-of-reserves attestation (Correct answer)
- Multi-signature wallet policy review
- KYC documentation review
- Trading volume reconciliation
Correct answer: Proof-of-reserves attestation
Proof-of-reserves attestation cryptographically proves that an exchange holds sufficient assets to cover all customer balances, directly verifying proper asset segregation.
Question 11: What is the role of regulatory audits in cryptocurrency firms?
- To create new tokens
- To automate smart contracts
- To calculate mining rewards
- To review compliance and internal processes (Correct answer)
Correct answer: To review compliance and internal processes
Audits ensure compliance with laws and regulations, and assess internal controls for risk and fraud prevention.
Question 12: Under the Bank Secrecy Act (BSA), U.S. cryptocurrency exchanges registered as Money Services Businesses (MSBs) are required to file a Currency Transaction Report (CTR) for cash transactions exceeding what threshold?
- $25,000
- $5,000
- $3,000
- $10,000 (Correct answer)
Correct answer: $10,000
The BSA CTR threshold is $10,000 for cash transactions, and FinCEN has confirmed this applies to MSBs including cryptocurrency exchanges that handle cash equivalent transactions.
Question 13: Which standard framework do U.S. federal agencies typically reference when conducting cryptocurrency tracing investigations and preparing court-admissible reports?
- GDPR Article 17 data minimization guidelines
- NIST SP 800-101 (Guidelines on Mobile Device Forensics)
- FinCEN's BSA/AML examination manual supplemented by agency-specific SOPs (Correct answer)
- ISO 27001
Correct answer: FinCEN's BSA/AML examination manual supplemented by agency-specific SOPs
U.S. agencies rely on FinCEN's BSA/AML framework and agency-specific standard operating procedures to ensure findings meet evidentiary standards in federal proceedings.
Question 14: What is the primary AML concern with peer-to-peer (P2P) cryptocurrency trading platforms that operate without KYC requirements?
- They are only used for tax evasion, not money laundering
- They can be used to exchange illicit cryptocurrency for cash without identity verification, effectively acting as unregistered money transmitters (Correct answer)
- They are technically illegal under all U.S. state laws
- P2P platforms cannot handle large transaction volumes
Correct answer: They can be used to exchange illicit cryptocurrency for cash without identity verification, effectively acting as unregistered money transmitters
KYC-free P2P platforms allow users to convert illicit cryptocurrency to cash with no identity records created, functioning as unregistered money transmission services and providing a critical off-ramp for money launderers.
Question 15: A cryptocurrency transaction shows funds moving through a chain of 15 intermediate wallets before reaching a final destination. This pattern is most consistent with which money laundering stage?
- Layering — obscuring the trail between illicit funds and their ultimate destination (Correct answer)
- Placement — introducing illicit funds into the financial system
- Integration — reintroducing cleaned funds into the legitimate economy
- Structuring — breaking transactions into small amounts to avoid reporting
Correct answer: Layering — obscuring the trail between illicit funds and their ultimate destination
Chaining transactions through many intermediate wallets is a classic layering technique designed to create distance between the source of illicit funds and their final destination, complicating blockchain tracing.
Question 16: Which type of oracle manipulation attack artificially moves the price reported to a DeFi protocol within a single block to exploit lending or liquidation logic?
- Sandwich attack
- Long-range attack
- Flash loan oracle attack (Correct answer)
- Wash trading attack
Correct answer: Flash loan oracle attack
Flash loan oracle attacks use uncollateralized loans within one transaction to manipulate spot price oracles and exploit protocols relying on them.
Question 17: In the context of blockchain auditing, what is a '51% attack'?
- A DDoS attack targeting over half the network's validator nodes
- An attack that steals private keys from more than half the network nodes
- A governance attack where 51% of token holders vote to drain a treasury
- An attack where an entity controls the majority of hashing power to rewrite recent history (Correct answer)
Correct answer: An attack where an entity controls the majority of hashing power to rewrite recent history
Controlling over 50% of a Proof-of-Work network's hash rate allows an attacker to out-mine honest nodes, enabling double-spends by replacing recently confirmed transactions.
Question 18: In cryptocurrency auditing, what is 'address reuse' primarily a risk to?
- Smart contract gas optimization
- Transaction throughput and network congestion
- Regulatory compliance under FATF travel rule
- User privacy and potentially key security through reduced entropy (Correct answer)
Correct answer: User privacy and potentially key security through reduced entropy
Address reuse links transactions together on the public ledger, degrading privacy and exposing spending patterns to blockchain analysis.
Question 19: What is the primary audit purpose of analyzing the 'change output' in a Bitcoin transaction?
- Measuring network congestion
- Identifying the likely wallet address controlled by the transaction sender (Correct answer)
- Verifying miner fee calculation
- Confirming transaction finality
Correct answer: Identifying the likely wallet address controlled by the transaction sender
The change output returns unspent funds to the sender's own wallet, and identifying it helps auditors separate recipient addresses from the sender's address cluster.
Question 20: What is a 'blockchain explorer' and how does it support cryptocurrency auditing?
- A forensic tool that decrypts private keys from public blockchain data
- A smart contract that automates audit report generation
- A web-based tool for querying on-chain data including addresses, transactions, and block details (Correct answer)
- A hardware wallet with a built-in display for reviewing transaction history
Correct answer: A web-based tool for querying on-chain data including addresses, transactions, and block details
Blockchain explorers provide transparent, queryable access to on-chain records, enabling auditors to independently verify transaction histories, balances, and block confirmations.
Question 21: A smart contract audit reveals a critical flaw. The contract's `withdraw` function first sends funds to an external address and then updates the user's internal balance afterward. An attacker could exploit this by creating a contract that calls the `withdraw` function repeatedly before the balance is updated. This vulnerability is known as a:
- Reentrancy Attack (Correct answer)
- Timestamp Dependency
- Denial of Service
- Integer Overflow
Correct answer: Reentrancy Attack
This scenario describes a classic Reentrancy Attack. The vulnerability occurs when a contract makes an external call to an untrusted contract before it resolves its own state changes (like updating a balance). The malicious contract can then "re-enter" the original function, calling it again to withdraw funds multiple times before the first call completes and the balance is updated.
Question 22: Which type of blockchain explorer data would a forensic analyst use to confirm that a specific smart contract was self-destructed after a rug pull?
- The contract's ERC-20 transfer events
- A SELFDESTRUCT opcode execution recorded in the contract's internal transaction trace (Correct answer)
- The contract's deployment transaction gas cost
- The number of token holders at the time of deployment
Correct answer: A SELFDESTRUCT opcode execution recorded in the contract's internal transaction trace
The SELFDESTRUCT opcode destroys a contract's bytecode and sends remaining ETH to a designated address; its execution is captured in internal transaction traces.
Question 23: In a Proof-of-Stake system, what is 'long-range attack' and why is it a unique concern?
- Using old private keys to rewrite blockchain history from a past point where an attacker had stake (Correct answer)
- Mining blocks for an extended period to accumulate enough hash power
- Gradually acquiring stake over a long timeframe to achieve 51%
- Attacking nodes over long geographic distances to increase latency
Correct answer: Using old private keys to rewrite blockchain history from a past point where an attacker had stake
Long-range attacks exploit the fact that old private keys, once spent, can be used to rewrite history from a past checkpoint in PoS systems without requiring current stake.
Question 24: Which FATF recommendation specifically requires cryptocurrency exchanges to collect and transmit originator and beneficiary information for virtual asset transfers?
- FATF Recommendation 16 (Travel Rule) (Correct answer)
- FATF Recommendation 6 (Targeted Financial Sanctions)
- FATF Recommendation 10 (Customer Due Diligence)
- FATF Recommendation 20 (Suspicious Transaction Reporting)
Correct answer: FATF Recommendation 16 (Travel Rule)
FATF Recommendation 16, the Travel Rule, requires VASPs to share sender and recipient information for crypto transfers above the threshold.
Question 25: When reviewing Ethereum internal transactions (traces), what scenario requires an auditor to examine traces rather than top-level transactions?
- Checking the gas limit
- Detecting ETH transfers triggered by smart contract logic, not direct EOA sends (Correct answer)
- Identifying the transaction sender
- Verifying block producer identity
Correct answer: Detecting ETH transfers triggered by smart contract logic, not direct EOA sends
Internal transactions are ETH or token movements initiated by smart contract execution and do not appear in the standard transaction list, only in execution traces.
Question 26: Under FinCEN's 2019 guidance, which activity requires a cryptocurrency exchange to register as a Money Services Business (MSB)?
- Holding private keys for personal use
- Mining cryptocurrency for block rewards
- Developing a blockchain protocol
- Exchanging virtual currency for fiat on behalf of customers (Correct answer)
Correct answer: Exchanging virtual currency for fiat on behalf of customers
FinCEN requires entities that exchange virtual currency for real currency, funds, or other virtual currency on behalf of others to register as MSBs.
Question 27: What is a blockchain?
- A centralized database
- A type of email system
- A distributed digital ledger (Correct answer)
- A private web browser
Correct answer: A distributed digital ledger
A blockchain is a distributed ledger that records transactions in a secure, transparent, and tamper-evident way.
Question 28: Which red flag is most indicative of potential structuring (smurfing) activity on a cryptocurrency exchange?
- Withdrawal of all funds after a single profitable trade
- Multiple deposits just below the $10,000 CTR threshold from the same customer across consecutive days (Correct answer)
- A single large deposit of $50,000 from a verified high-net-worth customer
- Frequent small purchases of fractional Bitcoin amounts by a retail customer
Correct answer: Multiple deposits just below the $10,000 CTR threshold from the same customer across consecutive days
Multiple deposits just below the CTR threshold from the same customer is the textbook definition of structuring, which is illegal under 31 U.S.C. § 5324 regardless of whether the underlying funds are licit.
Question 29: What was the key limitation of the indefinite-lived intangible asset treatment for cryptocurrency under old US GAAP?
- Assets had to be marked to market quarterly
- Impairment losses could be reversed if value recovered
- Impairment losses were permanent and could not be reversed (Correct answer)
- Gains were recognized before realization
Correct answer: Impairment losses were permanent and could not be reversed
Under the old indefinite-lived intangible asset treatment, impairment losses on cryptocurrency were permanent — even if fair value subsequently recovered, the write-down could not be reversed.
Question 30: An auditor finds that exchange withdrawal approval requires only a single authorized employee's digital signature. Which control framework principle does this violate?
- Segregation of duties (Correct answer)
- Data integrity
- Least privilege
- Defense in depth
Correct answer: Segregation of duties
Requiring only one approver for withdrawals violates segregation of duties, as a single actor can unilaterally move customer assets without independent oversight.
Question 31: Under FATF Recommendation 15 and its interpretive note for Virtual Assets, which type of entity is defined as a Virtual Asset Service Provider (VASP) subject to AML obligations?
- Only centralized cryptocurrency exchanges with more than 10,000 users
- Only DeFi protocols with more than $1B in total value locked
- Only entities that hold a state money transmitter license
- Any natural or legal person that conducts one or more of the specified VA activities (exchange, transfer, custody, etc.) as a business for another person (Correct answer)
Correct answer: Any natural or legal person that conducts one or more of the specified VA activities (exchange, transfer, custody, etc.) as a business for another person
FATF defines VASPs broadly as any entity conducting virtual asset activities (exchange, transfer, safekeeping, administration, or financial services for token offerings) as a business on behalf of others, regardless of size.
Certified Cryptocurrency Auditor™ (CCA)
The CCA certification validates expertise in auditing blockchain-based cryptocurrencies, covering audit methodology, technology security assessment, legal and tax compliance, and financial crime detection for digital assets.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds