Certified Blockchain Professional (CBCP) Exam — Questions and Answers
Question 1: In the context of blockchain, what is the relationship between a user's private key and public key?
- The public key is used to generate the private key.
- The public key is mathematically derived from the private key and can be shared freely. (Correct answer)
- The private key and public key are identical and can be used interchangeably.
- The private key is mathematically derived from the public key and must be kept secret.
Correct answer: The public key is mathematically derived from the private key and can be shared freely.
In public-key cryptography, a private key is generated first. A one-way mathematical function is then used to derive a corresponding public key from the private key. The private key must be kept secret as it is used to sign transactions and prove ownership, while the public key can be shared with others to receive funds.
Question 2: In a ring signature scheme used by privacy coins like Monero, what is concealed?
- The signature algorithm used to prevent fingerprinting
- The recipient's address using stealth key derivation
- The transaction amount only
- The identity of the actual signer among a group of possible signers (Correct answer)
Correct answer: The identity of the actual signer among a group of possible signers
Ring signatures allow a signer to produce a signature on behalf of a group, making it cryptographically indistinguishable which group member actually signed.
Question 3: What is 'token dilution' and why is it a concern for investors?
- The reduction in existing holders' ownership percentage when new tokens are minted or released (Correct answer)
- Mixing tokens from different blockchains in one wallet
- The loss of token value due to exchange hacking
- Converting tokens to stablecoins during market downturns
Correct answer: The reduction in existing holders' ownership percentage when new tokens are minted or released
Token dilution occurs when additional tokens enter circulation (via unlocks, mining, or minting), reducing the proportional ownership and potentially the value of existing holdings.
Question 4: What problem does the 'commit-reveal' scheme solve in smart contract-based applications?
- It prevents front-running by hiding a user's intent until after the commitment phase (Correct answer)
- It compresses calldata to reduce transaction size
- It reduces gas costs by batching state changes
- It enables cross-chain communication without a bridge
Correct answer: It prevents front-running by hiding a user's intent until after the commitment phase
In a commit-reveal scheme, users first submit a hash of their action (commit), then later reveal the actual action, preventing others from copying or front-running the intent.
Question 5: What is the function of a 'block explorer' in cryptocurrency?
- An exchange interface for converting between cryptocurrencies
- A tool that allows users to view and search all transactions and blocks on a blockchain (Correct answer)
- A wallet application for managing multiple cryptocurrencies
- Software that automatically discovers new coins to mine
Correct answer: A tool that allows users to view and search all transactions and blocks on a blockchain
A block explorer is a web-based tool providing a transparent, searchable interface to all on-chain data including transactions, addresses, and block details.
Question 6: In the context of NFTs, what does 'royalty enforcement' refer to?
- A DAO governance vote determining which artists can mint on a platform
- The exclusive right of marketplace platforms to set trading fees
- A legal requirement that NFT creators register their works with copyright offices
- A mechanism built into a smart contract that automatically pays the original creator a percentage of each secondary sale (Correct answer)
Correct answer: A mechanism built into a smart contract that automatically pays the original creator a percentage of each secondary sale
NFT royalty enforcement uses smart contract logic to automatically route a creator-specified percentage of secondary sale proceeds back to the original minter.
Question 7: In threshold signature schemes, what does a (t, n) configuration mean?
- t total keys are generated and n of them are published publicly
- n signatures are required but only t are verified
- t rounds of signing are needed with n validators each round
- Any t out of n key holders must cooperate to produce a valid signature (Correct answer)
Correct answer: Any t out of n key holders must cooperate to produce a valid signature
A (t, n) threshold scheme requires at least t participants from a group of n to jointly sign, so no single party controls the key.
Question 8: What is the purpose of the UTXO (Unspent Transaction Output) model used in Bitcoin?
- To cache recently used wallet addresses for faster lookup
- To track discrete units of cryptocurrency that have been received but not yet spent, preventing double-spending (Correct answer)
- To store metadata about smart contract state changes
- To record validator votes during the consensus process
Correct answer: To track discrete units of cryptocurrency that have been received but not yet spent, preventing double-spending
The UTXO model treats each coin as a discrete output; spending requires referencing existing UTXOs, and any remainder creates a new UTXO, ensuring each coin is spent only once.
Question 9: An organization plans to raise capital by issuing digital tokens that represent ownership shares in the company. This process will be conducted in full compliance with securities regulations, providing investors with rights similar to traditional stockholders, such as dividends and voting rights. What is this type of fundraising event called?
- Decentralized Autonomous Organization (DAO) Launch
- Security Token Offering (STO) (Correct answer)
- Initial Exchange Offering (IEO)
- Initial Coin Offering (ICO)
Correct answer: Security Token Offering (STO)
A Security Token Offering (STO) is a process where a company issues blockchain-based tokens that are classified as securities. These tokens represent ownership of an underlying asset, such as company equity or real estate, and must comply with financial regulations. This contrasts with an ICO, which often involved the sale of 'utility tokens' and frequently operated in a less regulated environment.
Question 10: A smart contract for a decentralized insurance dApp needs to automatically process a claim based on the real-world occurrence of a hurricane. Since the blockchain cannot directly access external weather data, what component is essential for the smart contract to receive this information securely and reliably?
- A state channel to communicate with weather APIs directly.
- An inter-blockchain communication protocol to query a weather-focused sidechain.
- A hard-fork of the main blockchain to include a weather data feed.
- A decentralized oracle network to fetch and verify external data. (Correct answer)
Correct answer: A decentralized oracle network to fetch and verify external data.
Blockchains are deterministic, isolated systems and cannot natively access off-chain data. A decentralized oracle network serves as a secure bridge, retrieving external data (like weather reports), verifying its accuracy through consensus, and delivering it to the smart contract to trigger its execution.
Question 11: In Solidity, what is the difference between 'storage' and 'memory' variable locations?
- Storage holds only primitive types; memory holds complex structs
- Storage is temporary and cheaper; memory is permanent and expensive
- Storage is permanent and persists on-chain; memory is temporary and exists only during execution (Correct answer)
- Storage is encrypted; memory is plaintext
Correct answer: Storage is permanent and persists on-chain; memory is temporary and exists only during execution
Storage variables are written to the blockchain and persist between transactions, while memory variables are temporary and discarded after function execution ends.
Question 12: What is the primary compliance concern with 'privacy coins' like Monero or Zcash for US-regulated exchanges?
- Slow block confirmation times
- High transaction fees
- Incompatibility with ERC-20 standards
- Inability to meet AML/KYC requirements due to transaction obfuscation (Correct answer)
Correct answer: Inability to meet AML/KYC requirements due to transaction obfuscation
Privacy coins obfuscate sender, recipient, and transaction amounts, making it extremely difficult for exchanges to comply with AML/KYC monitoring and reporting requirements.
Question 13: What is the primary purpose of a 'token lockup' period following a cryptocurrency presale?
- To comply with PoS slashing conditions
- To prevent early investors from immediately selling and crashing the token price at launch (Correct answer)
- To allow auditors to review the token contract
- To delay token minting until the mainnet launches
Correct answer: To prevent early investors from immediately selling and crashing the token price at launch
Lockup periods restrict early investors and team members from selling their tokens immediately after listing, reducing sell pressure and protecting public investors.
Question 14: What is the primary purpose of Ethereum's 'Verkle Tree' upgrade planned post-Cancun?
- Replace Merkle Patricia Tries with smaller witnesses to enable stateless clients and reduce node storage requirements (Correct answer)
- Replace ECDSA signatures with post-quantum cryptography
- Enable cross-shard communication without bridges
- Increase transaction throughput by 10x through parallel execution
Correct answer: Replace Merkle Patricia Tries with smaller witnesses to enable stateless clients and reduce node storage requirements
Verkle Trees produce compact proofs (witnesses) so nodes can verify blocks without storing the full state, enabling stateless Ethereum.
Question 15: How does a ring signature in Monero provide sender anonymity?
- It encrypts the sender's address using AES-256
- It replaces the sender's address with a stealth address shared with all nodes
- It allows a signer to sign on behalf of a group without revealing which group member actually signed (Correct answer)
- It uses zero-knowledge proofs to hide the transaction graph entirely
Correct answer: It allows a signer to sign on behalf of a group without revealing which group member actually signed
Ring signatures let one member of a group (ring) sign a message such that any ring member could plausibly be the signer, providing sender ambiguity.
Question 16: What is the purpose of a nonce in Bitcoin transaction signing versus in block mining?
- Transaction nonces order sender outputs; mining nonces find a hash below the target difficulty (Correct answer)
- Both nonces serve identical purposes — preventing duplicate block inclusion
- Transaction nonces set gas limits; mining nonces determine coinbase reward
- Transaction nonces prevent replay attacks; mining nonces are the hash target
Correct answer: Transaction nonces order sender outputs; mining nonces find a hash below the target difficulty
In transactions, the nonce is an account counter preventing replay; in mining, the nonce is iterated until the block hash meets the required difficulty target.
Question 17: Which Ethereum Improvement Proposal introduced the concept of 'meta-transactions' to allow users to interact with DApps without holding ETH for gas?
- EIP-4337 (Account Abstraction) (Correct answer)
- EIP-1559
- EIP-2612 and EIP-712 (gasless transactions via relayers)
- EIP-1820
Correct answer: EIP-4337 (Account Abstraction)
EIP-4337 (Account Abstraction) enables smart contract wallets and paymasters so users can pay gas in tokens or have a relayer sponsor fees, eliminating the need to hold ETH.
Question 18: What is 'flash loan' in DeFi smart contracts?
- A long-term undercollateralized loan issued by a DAO
- An uncollateralized loan that must be borrowed and repaid within a single transaction (Correct answer)
- A micro-loan protocol that uses off-chain credit scores
- A loan where repayment is enforced by a hardware security module
Correct answer: An uncollateralized loan that must be borrowed and repaid within a single transaction
Flash loans are atomic, uncollateralized loans where borrowing and repayment occur in one transaction; if repayment fails, the entire transaction reverts.
Question 19: A development team is building a decentralized social media platform. They want to ensure the user interface is fast and responsive, similar to a traditional web app, while the core logic for content ownership and user interactions is handled by smart contracts. Which of the following BEST describes a typical architectural stack for such a dApp?
- The application logic is run on a centralized server which then batches transactions and submits them to the blockchain.
- Smart contracts are used to query a centralized database where all user data and application logic is stored.
- A traditional frontend (HTML/CSS/JS) interacts with smart contracts for backend logic, and may use decentralized storage (like IPFS) for media files. (Correct answer)
- The entire application, including the frontend UI and all data, is stored and executed directly on the blockchain.
Correct answer: A traditional frontend (HTML/CSS/JS) interacts with smart contracts for backend logic, and may use decentralized storage (like IPFS) for media files.
A standard dApp architecture involves a separation of concerns. The frontend (user interface) is typically built with standard web technologies (HTML, CSS, JavaScript) for a good user experience. This frontend then communicates with the backend, which consists of smart contracts deployed on a blockchain. For large files like images or videos, decentralized storage solutions like IPFS are often used instead of storing them directly on the blockchain due to cost and performance constraints.
Question 20: What differentiates a deterministic wallet from a non-deterministic (random) wallet in terms of key management?
- Deterministic wallets support only one address; random wallets support many
- Deterministic wallets store keys in plaintext; random wallets encrypt each key separately
- Deterministic wallets use symmetric keys; random wallets use asymmetric keys
- Deterministic wallets derive all keys from a single seed, enabling full backup with one phrase (Correct answer)
Correct answer: Deterministic wallets derive all keys from a single seed, enabling full backup with one phrase
Deterministic wallets use a master seed to derive all private keys hierarchically, so a single seed phrase backs up every key in the wallet.
Question 21: Which consensus-related attack involves a miner reordering transactions in a block to profit from price movements in a DeFi protocol?
- Eclipse attack
- 51% attack
- Sybil attack
- Maximal Extractable Value (MEV) (Correct answer)
Correct answer: Maximal Extractable Value (MEV)
MEV refers to the profit miners or validators can extract by including, excluding, or reordering transactions within the blocks they produce.
Question 22: Which attack attempts to find any second input that hashes to the same value as a given first input?
- Preimage attack
- Second preimage attack (Correct answer)
- Length extension attack
- Birthday attack
Correct answer: Second preimage attack
A second preimage attack tries to find m2 ≠ m1 such that H(m2) = H(m1), given a known message m1 and its hash.
Question 23: What is 'MEV' (Maximal Extractable Value) in the context of Ethereum?
- The maximum gas fee a user can set for a transaction
- The total ETH issuance per epoch for validators
- The maximum value locked in a single DeFi protocol
- Profit validators or block proposers can earn by reordering, inserting, or censoring transactions within a block (Correct answer)
Correct answer: Profit validators or block proposers can earn by reordering, inserting, or censoring transactions within a block
MEV arises because block proposers control transaction ordering, enabling strategies like sandwich attacks, arbitrage, and liquidations.
Question 24: Which enterprise blockchain platform uses the concept of 'Flows' to orchestrate multi-party business processes?
- Ethereum with Solidity state machines
- R3 Corda with CorDapp Flows (Correct answer)
- Hyperledger Sawtooth with transaction families
- Hyperledger Fabric with chaincode workflows
Correct answer: R3 Corda with CorDapp Flows
R3 Corda uses Flows as a framework for writing multi-party business processes that coordinate communication and state transitions between Corda nodes.
Question 25: In Ethereum's beacon chain, what is an 'attestation'?
- A cryptographic proof of the validator's identity
- A proof of stake deposit confirmation
- A slashing report submitted by a whistleblower validator
- A validator's signed vote confirming a specific block as the head of the chain and a checkpoint as finalized (Correct answer)
Correct answer: A validator's signed vote confirming a specific block as the head of the chain and a checkpoint as finalized
Attestations are validators' LMD-GHOST and Casper FFG votes aggregated per slot to determine the canonical chain.
Question 26: Which of the following best describes the primary purpose of the difficulty adjustment in the Bitcoin protocol?
- To maintain a consistent average block time. (Correct answer)
- To increase the total supply of Bitcoin over time.
- To ensure miners are always profitable.
- To decrease the transaction fees for users.
Correct answer: To maintain a consistent average block time.
The difficulty adjustment is a fundamental mechanism in Bitcoin's Proof-of-Work system. It automatically modifies the complexity of the cryptographic puzzle that miners must solve. This adjustment occurs every 2,016 blocks (approximately every two weeks) to ensure that, regardless of how much total computing power (hashrate) is on the network, the average time to find a new block remains close to 10 minutes.
Question 27: What role does the Keccak-256 hash function play in Ethereum?
- It derives Ethereum addresses and is the primary hash used across the protocol (Correct answer)
- It signs transactions in place of ECDSA
- It is used to encrypt storage slots in the EVM
- It computes the proof-of-stake validator selection seed
Correct answer: It derives Ethereum addresses and is the primary hash used across the protocol
Ethereum uses Keccak-256 (a variant of SHA-3) for address derivation, transaction hashing, Merkle trees, and event topic encoding throughout the protocol.
Question 28: Which property ensures that a blockchain transaction, once confirmed in sufficient blocks, cannot be reversed by any single party?
- Finality (Correct answer)
- Transparency
- Decentralization
- Pseudonymity
Correct answer: Finality
Finality (probabilistic or absolute depending on consensus mechanism) is the property ensuring a confirmed transaction cannot be rolled back, providing settlement certainty to participants.
Question 29: In the context of cryptocurrency, what is a 'dust attack'?
- Sending tiny amounts of crypto to wallets to track and de-anonymize owners (Correct answer)
- A DDoS attack on blockchain nodes
- Spamming the mempool with low-fee transactions
- A method of front-running transactions
Correct answer: Sending tiny amounts of crypto to wallets to track and de-anonymize owners
Dust attacks involve sending negligible amounts of cryptocurrency to wallets to analyze transaction patterns and potentially link addresses to real identities.
Question 30: What aspect of a blockchain network's protection is also its feature?
- The more centralized the control of the blockchain is, the harder it is to secure the data and avoid fraud.
- The lower the number of miners in the blockchain, the higher the incentive is for securing the network.
- The more complicated the Proof of Work (PoW) algorithm is, the more rewarding it is to secure the network.
- The greater the number of full independent nodes, the harder it is to compromise the data in the blockchain. (Correct answer)
Correct answer: The greater the number of full independent nodes, the harder it is to compromise the data in the blockchain.
A blockchain network's protection is intrinsically linked to its decentralized nature and the number of independent nodes. The greater the number of full, independent nodes participating in the network, the harder it becomes for any single entity or group to compromise the data. Each node holds a copy of the ledger, making it extremely difficult and costly to alter or corrupt the data across the entire distributed network.
Question 31: Which enterprise blockchain platform is architecturally designed around a 'need-to-know' principle, where transaction data is NOT broadcast to all nodes on the network but is instead sent directly and privately only to the participants involved in that specific transaction?
- Hyperledger Fabric
- ConsenSys Quorum
- Ethereum (public mainnet)
- R3 Corda (Correct answer)
Correct answer: R3 Corda
R3 Corda is uniquely designed to avoid global broadcasting of transactions. Instead, it uses a peer-to-peer communication model where transaction details are shared only on a 'need-to-know' basis with the parties directly involved and any necessary notaries. [16, 18, 23] This approach provides a high degree of privacy by default, as no node has a complete view of all transactions on the network. [17]
Question 32: What is 'impermanent loss' in DeFi liquidity provision?
- The temporary reduction in value a liquidity provider experiences compared to simply holding the assets, caused by price divergence (Correct answer)
- Funds permanently lost due to a smart contract exploit
- Transaction fees lost when a trade fails to execute
- The penalty for withdrawing staked assets before the lock-up period ends
Correct answer: The temporary reduction in value a liquidity provider experiences compared to simply holding the assets, caused by price divergence
Impermanent loss occurs when the price ratio of pooled assets changes from deposit time; the loss becomes permanent only if the LP withdraws before prices revert.
Question 33: Which Solidity function visibility modifier makes a function accessible only within the contract that defines it and not by derived contracts?
- internal
- private (Correct answer)
- public
- external
Correct answer: private
Private functions are only accessible within the contract they are defined in, unlike internal functions which are also accessible in derived (child) contracts.
Question 34: What form of public witness do blockchains use?
- A preferred node can be elected to attest to the accuracy and truthfulness of information.
- A person sends a transaction over a public network to earn rewards as a public witness.
- A node on a blockchain network attests to the accuracy and truthfulness of information. (Correct answer)
- A digital courthouse or library acts as a public witness to store information to reference.
Correct answer: A node on a blockchain network attests to the accuracy and truthfulness of information.
Blockchains use a form of public witness where multiple independent nodes on the network collectively attest to the accuracy and truthfulness of information. Instead of relying on a single central authority, transactions and data are verified and confirmed by a distributed network of participants. This decentralized attestation ensures transparency, immutability, and trust in the ledger, as consensus is reached across the network.
Question 35: Which Hyperledger project provides a distributed ledger framework specifically designed for identity management and verifiable credentials?
- Hyperledger Burrow
- Hyperledger Fabric
- Hyperledger Indy (Correct answer)
- Hyperledger Besu
Correct answer: Hyperledger Indy
Hyperledger Indy is purpose-built for decentralized identity, providing tools for creating and using independent digital identities rooted on blockchain.
Question 36: What is a 'proxy pattern' in Ethereum smart contract upgradability?
- A contract that mirrors state from the mainnet to a sidechain
- A read-only contract that proxies view calls for gas savings
- A pattern where multiple contracts share a single storage layout
- A contract that delegates calls to an implementation contract, allowing logic to be upgraded without changing the proxy's address (Correct answer)
Correct answer: A contract that delegates calls to an implementation contract, allowing logic to be upgraded without changing the proxy's address
The proxy holds state and forwards calls via DELEGATECALL to an upgradeable logic contract, preserving the original address.
Question 37: What is 'impermanent loss' in DeFi liquidity provision?
- The gas fees paid when depositing tokens into a liquidity pool
- The temporary reduction in value a liquidity provider experiences compared to simply holding tokens when prices diverge (Correct answer)
- Interest lost when withdrawing funds before a lockup period ends
- Funds permanently lost when a smart contract is hacked
Correct answer: The temporary reduction in value a liquidity provider experiences compared to simply holding tokens when prices diverge
Impermanent loss occurs when the price ratio of tokens in a liquidity pool changes after deposit, making the LP's position less valuable than just holding the tokens outright.
Question 38: What is a 'flash loan' in DeFi?
- A short-term loan with a very high interest rate issued by centralized lenders
- A loan automatically liquidated if collateral value drops below 150%
- A loan issued by a DAO to fund protocol development with governance token repayment
- An uncollateralized loan that must be borrowed and repaid within the same blockchain transaction (Correct answer)
Correct answer: An uncollateralized loan that must be borrowed and repaid within the same blockchain transaction
Flash loans exploit atomic transaction properties to provide uncollateralized funds that must be returned within the same transaction block, or the entire operation reverts.
Question 39: What role does a Merkle tree serve within a blockchain block?
- It determines the mining difficulty target
- It provides an efficient summary of all transactions enabling fast verification (Correct answer)
- It encrypts wallet private keys
- It stores validator identity information
Correct answer: It provides an efficient summary of all transactions enabling fast verification
A Merkle tree hashes transactions in a binary tree structure, allowing a single root hash to represent all transactions and enabling efficient proof of inclusion.
Question 40: Due to the immutable nature of blockchains, fixing a bug in a deployed smart contract is a significant challenge. Which design pattern allows developers to update the application logic of a dApp without requiring users to migrate their data to a new contract address?
- The Singleton Pattern
- The Proxy Pattern (Correct answer)
- The Observer Pattern
- The Factory Pattern
Correct answer: The Proxy Pattern
The Proxy Pattern is a common method for enabling smart contract upgrades. It involves separating the contract's state and logic. Users interact with a proxy contract that holds the state (data), which then delegates calls to a separate logic contract. To upgrade, a new logic contract is deployed, and the proxy contract is simply updated to point to the new logic contract's address, preserving the original state and contract address for users.
Question 41: What is a 'proxy pattern' in smart contract architecture primarily used for?
- Enabling upgradeable smart contracts by separating logic from storage (Correct answer)
- Batching multiple transactions into one
- Reducing gas costs by caching results
- Encrypting contract storage on-chain
Correct answer: Enabling upgradeable smart contracts by separating logic from storage
The proxy pattern separates a contract's storage proxy from its logic implementation, allowing the logic to be upgraded without changing the contract address.
Question 42: What distinguishes a 'hard fork' from a 'soft fork' in blockchain protocol upgrades?
- Hard forks change transaction fees while soft forks change block size
- Hard forks only affect mining nodes while soft forks affect all nodes
- Hard forks require majority stake approval while soft forks require unanimous consent
- Hard forks are backward-incompatible while soft forks maintain backward compatibility (Correct answer)
Correct answer: Hard forks are backward-incompatible while soft forks maintain backward compatibility
A hard fork creates a permanent divergence by introducing rules that old nodes cannot validate, making it backward-incompatible, whereas a soft fork tightens rules that old nodes can still accept.
Question 43: In the blockchain, what is responsible for maintaining a distributed network of participants?
- The Network (Correct answer)
- Smart Contracts
- Hash Functions
- Transactions
Correct answer: The Network
In the blockchain, 'The Network' is responsible for maintaining a distributed network of participants, known as nodes. These nodes collectively store a copy of the blockchain ledger, validate transactions, and propagate new blocks across the system. This decentralized network ensures the blockchain's resilience, security, and consensus mechanism.
Question 44: In the context of mining pools, what is a 'share'?
- A fractional block reward paid per transaction validated
- A proof-of-work solution that meets a lower difficulty target, submitted to demonstrate mining effort (Correct answer)
- An equity stake in the mining pool company
- A cryptographic token representing partial block ownership
Correct answer: A proof-of-work solution that meets a lower difficulty target, submitted to demonstrate mining effort
Shares are partial proof-of-work solutions with a lower difficulty than the actual network target, used by pools to measure each miner's contributed work for reward distribution.
Question 45: What is a 'Layer 2' solution in the context of cryptocurrency scalability?
- A second cryptographic layer added to wallet security
- A second blockchain that replaces the main chain
- A regulatory framework for second-generation cryptocurrencies
- A protocol built on top of a base blockchain to increase throughput and reduce fees (Correct answer)
Correct answer: A protocol built on top of a base blockchain to increase throughput and reduce fees
Layer 2 solutions (e.g., Lightning Network, Optimism, Arbitrum) process transactions off the main chain while inheriting its security, dramatically improving scalability.
Question 46: Which year saw the development of blockchain technology?
- 2008 (Correct answer)
- 2009
- 2015
- 2010
Correct answer: 2008
Blockchain technology was first developed in 2008. It was conceptualized by an anonymous entity known as Satoshi Nakamoto, who published a whitepaper describing the technology as the underlying mechanism for the cryptocurrency Bitcoin. The Bitcoin network, the first practical application of blockchain, launched in early 2009.
Question 47: In enterprise blockchain governance, what is a 'permissioned' network's primary advantage over a public blockchain for regulated industries?
- Permissioned networks allow known, vetted identities and regulatory compliance controls (Correct answer)
- Permissioned networks have lower hardware requirements for node operation
- Permissioned networks eliminate the need for consensus mechanisms entirely
- Permissioned networks are always faster due to fewer nodes
Correct answer: Permissioned networks allow known, vetted identities and regulatory compliance controls
Permissioned blockchains restrict participation to vetted entities, enabling KYC/AML compliance, auditability by regulators, and governance controls required in finance, healthcare, and supply chain.
Question 48: Which of the following describes a Decentralized Autonomous Organization (DAO)?
- A corporation that uses blockchain to track its physical assets and supply chain.
- An internet-native organization where rules are encoded as smart contracts and operational decisions are made by its members, typically through voting with governance tokens. (Correct answer)
- A software company that develops dApps for a variety of blockchain platforms.
- A government agency that uses smart contracts to automate regulatory compliance.
Correct answer: An internet-native organization where rules are encoded as smart contracts and operational decisions are made by its members, typically through voting with governance tokens.
A Decentralized Autonomous Organization (DAO) is an entity with no central leadership. It is collectively owned and managed by its members. Its rules are encoded in smart contracts on a blockchain, and decisions are made through proposals and voting by members, who typically hold governance tokens that represent voting power.
Question 49: Choose the consensus algorithm that Ethereum's PoW mechanism will employ.
- Dagger Hashimoto
- Etchash
- SHA256 algorithm
- Ethash (Correct answer)
Correct answer: Ethash
Before its transition to Proof-of-Stake, Ethereum's Proof-of-Work (PoW) mechanism employed the Ethash consensus algorithm. Ethash was specifically designed to be ASIC-resistant, favoring GPU mining to promote decentralization and prevent the dominance of specialized hardware in the network.
Question 50: What role does the 'genesis block' play in a blockchain network?
- It contains the smart contract bytecode for the core consensus protocol
- It stores validator private keys encrypted with the network's master seed
- It is the first block hardcoded into the software, establishing the chain's starting state (Correct answer)
- It is regenerated monthly to reset chain difficulty to baseline
Correct answer: It is the first block hardcoded into the software, establishing the chain's starting state
The genesis block (block 0) is the first block in a blockchain, hardcoded into the node software, and establishes the initial state from which all subsequent blocks are linked.
Question 51: Why is blockchain referred to as the technology that gives the internet an extra layer of trust?
- It creates a dedicated virtual private network (VPN) tunnel between two or more parties to carry out online fund transfers.
- It provides mechanism for the government to create their own digital fiat currency as a replacement of physical currency.
- It provides multifactor authentication to create and update records of cryptocurrency transactions securely.
- It allows individuals and groups to work together without having to trust each other or establish authority. (Correct answer)
Correct answer: It allows individuals and groups to work together without having to trust each other or establish authority.
Blockchain is often called a 'trust layer' because its decentralized, immutable, and transparent nature allows parties to interact and transact without needing to trust a central authority or even each other. The cryptographic security and consensus mechanisms ensure that all transactions are verified and recorded accurately, creating a system where trust is built into the technology itself. This enables secure collaboration and value exchange in a trustless environment.
Question 52: A DeFi protocol's smart contract contains a function that sends funds to an external address. An attacker discovers that they can repeatedly call this function from their own malicious contract before the original function completes its state update, allowing them to withdraw more funds than they are entitled to. This vulnerability is known as a:
- Front-Running Attack
- Integer Overflow Attack
- Reentrancy Attack (Correct answer)
- Timestamp Dependence Vulnerability
Correct answer: Reentrancy Attack
A reentrancy attack occurs when an external call from a vulnerable contract allows the called contract to call back into the original contract before its state is updated. This can lead to the logic being executed multiple times, often to drain funds, as famously happened in the 2016 DAO hack.
Question 53: In the US, the CFTC primarily regulates cryptocurrencies that are classified as:
- Currency
- Securities
- Utility tokens
- Commodities (Correct answer)
Correct answer: Commodities
The Commodity Futures Trading Commission (CFTC) primarily regulates cryptocurrencies classified as commodities, such as Bitcoin and Ether, and their derivatives markets.
Question 54: How can basic blockchain security be attacked?
- By compromising the consensus mechanism (Correct answer)
- By manipulating the cryptographic algorithms
- By increasing network latency
- By exploiting smart contract vulnerabilities
Correct answer: By compromising the consensus mechanism
Fiduciary responsibility involves acting in the best interests of another party, typically shareholders. This responsibility is governed and demonstrated through transparent financial reporting, such as end-of-year financial ledgers, and is independently verified through audits, which provide assurance on the accuracy and fairness of those reports. Both are crucial for accountability.
Question 55: An individual with a moderately powerful mining rig is looking for the most consistent and predictable stream of income from mining a popular Proof-of-Work cryptocurrency. Which mining approach would be most suitable?
- Hybrid Mining
- Pool Mining (Correct answer)
- Solo Mining
- Cloud Mining
Correct answer: Pool Mining
Pool mining allows multiple miners to combine their computational resources (hashrate). This significantly increases the collective chance of solving a block and earning the reward. The reward is then distributed among the pool participants proportional to their contributed hashrate. This approach provides a much more frequent and predictable income stream compared to solo mining, where a miner with a moderate hashrate might go for years without finding a block.
Question 56: What is the primary purpose of the ERC-20 token standard on the Ethereum blockchain?
- To define Ethereum's consensus mechanism and block validation rules
- To standardize the smart contract security auditing process
- To define a standard for unique non-fungible tokens (NFTs)
- To create a common interface enabling interoperable fungible tokens on Ethereum (Correct answer)
Correct answer: To create a common interface enabling interoperable fungible tokens on Ethereum
ERC-20 defines a standard interface for fungible tokens on Ethereum, ensuring interoperability so that wallets, exchanges, and dApps can integrate any compliant token consistently.
Question 57: What is the primary security risk of reusing the same ECDSA nonce (k) for two different signatures with the same private key?
- The signature becomes invalid and is rejected by the network
- The hash of the transaction becomes predictable to miners
- The public key is exposed in plaintext in the transaction
- The private key can be mathematically extracted from the two signatures (Correct answer)
Correct answer: The private key can be mathematically extracted from the two signatures
If k is reused, an attacker with two signatures and the known nonce can solve for the private key algebraically using the ECDSA signature equations.
Question 58: How long does it take to mine a block of Ethereum?
- 12
- 10
- 0 (Correct answer)
- 30
Correct answer: 0
After Ethereum's transition to Proof-of-Stake (known as 'The Merge'), the concept of 'mining' a block in the traditional Proof-of-Work sense no longer applies. Instead, blocks are created and attested by validators at fixed intervals (slots), meaning there is no competitive mining process with a variable 'mining time.' Thus, the time to 'mine' a block is effectively 0 in the old sense, as blocks are now scheduled.
Question 59: The narcissism of little distinctions is one of the biggest risks to the blockchain community. What outcome does this narcissism of subtle differences produce?
- The community cares about and works to resolve small differences that cannot be perceived by outside groups.
- The community has grown closer and works together in a collaborative fashion to solve common problems.
- The community has developed many similar projects and these fight with one another over small differences. (Correct answer)
- One community group makes fun of another community group over small differences, resulting in greater collaboration.
Correct answer: The community has developed many similar projects and these fight with one another over small differences.
The 'narcissism of small distinctions' in the blockchain community refers to the proliferation of many similar projects that compete rather than collaborate. These projects often differentiate themselves based on minor technical or philosophical differences, leading to fragmentation and infighting within the ecosystem. This competition over subtle distinctions can hinder broader adoption and divert resources from addressing more significant challenges.
Question 60: What is 'tokenomics' in the context of DApp design?
- The process of converting ERC-20 tokens to ERC-721 tokens
- The cryptographic algorithm used to secure token transfers
- The economic model governing a token's supply, distribution, incentives, and utility within an ecosystem (Correct answer)
- A tax applied to token transactions on decentralized exchanges
Correct answer: The economic model governing a token's supply, distribution, incentives, and utility within an ecosystem
Tokenomics describes the economic design of a token system including total supply, emission schedule, staking rewards, and incentive structures that drive participant behavior.
Certified Blockchain Professional (CBCP) Exam
The Certified Blockchain Professional (CBCP) exam validates an individual's foundational knowledge of blockchain technology, including its concepts, principles, and applications.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds