Mixed Deck — All CCE Topics Flashcards
100 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCE Topics flashcards as text
A DeFi protocol issues fractionalized NFTs (F-NFTs) representing ownership shares in a rare digital artwork. When the underlying NFT is locked in a vault and ERC-20 fractions are distributed, which mechanism allows the original NFT to be reconstituted?
Answer: A buyout auction where a single party acquires 100% of the fractional tokens and triggers vault release
In fractionalized NFT protocols (e.g., Fractional.art / Tessera), reconstitution typically occurs via a buyout auction mechanism: any party can initiate a buyout at or above the reserve price. If successful, they acquire 100% of the fractional tokens (either through purchase or by tendering all tokens they hold), which triggers the vault smart contract to release the underlying NFT to the buyer. Governance votes and admin overrides are not standard reconstitution paths in trustless F-NFT protocols.
What is a 'Merkle Patricia Trie' used for in Ethereum?
Answer: Efficiently encoding and verifying account balances, storage, and transaction data in each block
Ethereum uses Merkle Patricia Tries to store world state, transactions, and receipts, allowing cryptographic proofs of inclusion with minimal data.
An Initial Exchange Offering (IEO) is a fundraising model that evolved from the traditional ICO. What is the key difference between an IEO and an ICO?
Answer: In an IEO, the token sale is conducted and vetted by a cryptocurrency exchange.
In an Initial Exchange Offering (IEO), the token sale is managed and hosted on a cryptocurrency exchange's platform. The exchange typically vets the project for legitimacy, which provides a layer of due diligence and trust for investors, and the token is usually listed on that exchange shortly after the sale, ensuring immediate liquidity.
What is the main purpose of a bug bounty program in the cryptocurrency ecosystem?
Answer: Incentivize ethical hackers to find and report vulnerabilities
Bug bounty programs pay security researchers to responsibly disclose vulnerabilities before malicious actors exploit them.
What is a key aspect of security & risk management?
Answer: Applying industry-standard protocols and knowledge
For robust security and risk management in the cryptocurrency domain, applying industry-standard protocols and knowledge is indispensable. This means adopting globally recognized security certifications, employing expert cybersecurity teams, and regularly updating security infrastructure. Such practices are essential for combating sophisticated cyber threats and maintaining the integrity and confidentiality of cryptocurrency operations.
Under US law, which type of crypto transaction is most clearly subject to capital gains tax?
Answer: Selling Bitcoin for USD at a profit
Selling cryptocurrency for fiat currency at a profit is a clearly taxable disposition event generating capital gains under IRS guidance.
Which of the following technical chart patterns is widely considered a bearish reversal pattern, often signaling that a prior uptrend is losing momentum and a downtrend may begin?
Answer: Head and Shoulders
The Head and Shoulders pattern is a classic bearish reversal formation. It consists of three peaks, with the middle peak (the head) being the highest and the two side peaks (the shoulders) being lower and roughly equal. A break below the support level, known as the neckline, confirms the pattern and signals a potential downtrend.
A perpetual futures contract on BTC pays a funding rate of 0.05% every 8 hours. A market-neutral trader buys 1 BTC spot at $60,000 and shorts 1 BTC perpetual to collect funding. What is the approximate annualized APY (compounded) this strategy generates, ignoring transaction costs?
Answer: ~72.9%
Funding pays 3 times per day. The daily compounded growth factor is (1.0005)^3 = 1.001501. Annualized: (1.001501)^365 ≈ e^(0.001499 × 365) = e^0.5474 ≈ 1.729, or ~72.9% APY. Simple annualization (0.15% × 365 = 54.75%) is a common distractor but ignores compounding. The other options miscount payment frequency or conflate the per-payment rate with the annual rate.
What is 'yield farming' in DeFi?
Answer: Actively moving assets across protocols to maximize returns from liquidity incentives and fees
Yield farming involves strategically allocating assets across multiple DeFi protocols to maximize returns from a combination of trading fees, interest, and token incentives.
Which security measure is most vulnerable to a 'SIM swap' attack, potentially leading to the compromise of a user's cryptocurrency exchange account?
Answer: SMS-based two-factor authentication (2FA)
In a SIM swap attack, a fraudster convinces a mobile carrier to transfer the victim's phone number to a SIM card they control. This allows them to intercept SMS messages, including 2FA codes, giving them access to accounts secured by this method. Authenticator apps and hardware keys are not vulnerable to this specific attack.
OFAC's 2021 sanctions designation of Suex OTC and its 2022 designation of Tornado Cash established an important precedent in crypto enforcement. Which legal argument, raised in subsequent litigation (Van Loon v. Department of Treasury), challenged the Tornado Cash designation on constitutional grounds?
Answer: That immutable smart contracts are not 'property' under IEEPA because they cannot be owned or controlled by any person, including their original developer
The core legal argument in Van Loon v. Department of Treasury (5th Circuit, 2024) was that immutable, autonomous smart contracts — once deployed — cannot constitute 'property' of a foreign national under IEEPA (International Emergency Economic Powers Act) because no person, including the original developer, retains ownership or control over them. The 5th Circuit agreed with this reasoning regarding the immutable pool contracts, ruling that OFAC overstepped. This distinction between mutable (controlled) and immutable (autonomous) code is central to the case. First Amendment arguments, dollar thresholds, and SEC shareholder frameworks were not the primary basis of the ruling.
Under the EU's Transfer of Funds Regulation (TFR) as amended to cover crypto-assets (effective 2023), what rule applies to transfers between a regulated VASP and an unhosted (self-custodied) wallet when the transfer amount exceeds EUR 1,000?
Answer: The VASP must collect originator and beneficiary information, verify that the unhosted wallet belongs to its own customer, and apply enhanced due diligence measures
The amended EU Transfer of Funds Regulation requires VASPs, for transfers exceeding EUR 1,000 to or from unhosted wallets, to collect information about the originator and beneficiary AND to verify that the unhosted wallet is actually controlled by their own customer (e.g., through cryptographic proof-of-ownership or micro-transaction verification). Standard KYC completion alone is insufficient — the wallet ownership link must be established. Transfers are not blanket-prohibited, and the EUR 1,000 threshold — not EUR 10,000 — triggers the enhanced requirements.
A sophisticated trader wants to exploit a triangular arbitrage opportunity across three trading pairs on the same exchange: BTC/USDT, ETH/BTC, and ETH/USDT. After executing all three legs, they find no profit despite the price discrepancy appearing on screen. Which factor most likely eliminated the arbitrage profit?
Answer: Trading fees compounding across all three legs consumed the spread between the implied and actual cross rate
Triangular arbitrage opportunities on centralized exchanges are typically very thin (fractions of a percent). When trading fees (e.g., 0.1% per leg) are applied across all three legs, the compounded fee burden (roughly 0.3% total) often equals or exceeds the apparent price discrepancy. Most visible 'arbitrage' spreads on a single exchange already fall within the fee band, making them unprofitable in practice.
What is 'block propagation' and why does it matter for blockchain security?
Answer: The time it takes for a newly mined block to reach all network nodes; slower propagation increases fork risk
Slow block propagation increases the chance of temporary forks because two miners may solve blocks before either hears of the other's solution, wasting hash power and risking chain reorganization.
What is the primary purpose of a whitepaper in an Initial Coin Offering (ICO)?
Answer: To detail the project's technical architecture, goals, tokenomics, and team.
A whitepaper is the foundational document for a new cryptocurrency project, intended to provide potential investors with comprehensive information about its purpose, technology, roadmap, and the team behind it. It is not a legal contract or a guarantee of profit but rather a detailed technical and business prospectus.
Which attack vector exploits clipboard hijacking to redirect cryptocurrency transactions?
Answer: Clipper malware
Clipper malware monitors the clipboard and replaces copied wallet addresses with the attacker's address, redirecting funds during paste.
A blockchain game uses a 'soulbound' token (SBT) mechanic for player reputation scores, implementing EIP-5192 (Minimal Soulbound NFT). A secondary market exploits the fact that EOA private keys can be sold. To truly prevent reputation transfer, the MOST effective additional mechanism is:
Answer: Restricting token minting to wallets that have passed on-chain KYC via a decentralized identity protocol, then binding reputation updates to zero-knowledge proofs of continued identity
The fundamental weakness of EIP-5192 soulbinding is that it prevents token transfer but not private key sale — the EOA itself can be handed over. The only robust mitigation is binding the credential to a persistent, non-transferable identity rather than a key. Zero-knowledge proof systems (e.g., Semaphore, Polygon ID) allow identity to be proven without revealing it, and re-issuance can require ZK proof of the original biometric or credential, making key sale useless. The ETH balance burn is easily gamed, periodic re-signing only proves key possession (still transferable), and centralization defeats the point of on-chain reputation.
What is the primary risk of investing in an ICO project that lacks a 'minimum viable product' (MVP) at the time of its token sale?
Answer: Investors are funding a concept with unproven technology, increasing the risk that the project never delivers its promised platform
Without an MVP, investors have only promises and a whitepaper, making it extremely difficult to assess technical feasibility and significantly increasing the risk of total loss.
Which of the following is a primary characteristic of a decentralized exchange (DEX) that distinguishes it from a centralized exchange (CEX)?
Answer: Users retain full control over their private keys and assets.
On a decentralized exchange (DEX), users trade directly from their personal wallets and never surrender custody of their private keys to the exchange. This non-custodial nature is a fundamental difference from centralized exchanges (CEXs), where the exchange holds and manages user funds in its own wallets.
Which Ethereum Improvement Proposal introduced the ERC-20 token standard?
Answer: EIP-20
EIP-20 formally codified the ERC-20 fungible token standard, defining the interface functions like transfer, approve, and allowance.