CCA Study Guide 2026

Everything you need to pass the CCA exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 CCA Exam Format at a Glance

100
Questions
60 min
Time Limit
60.00%
Passing Score

📚 CCA Topics to Study (57)

✍️ Sample CCA Questions & Answers

1. Which control best mitigates the risk of compromised API keys being used to drain a cryptocurrency exchange's hot wallet?
Implementing IP allowlisting and withdrawal address whitelisting on API keys

IP allowlisting restricts API key usage to known IP addresses, and withdrawal address whitelisting limits where funds can be sent even if a key is stolen.

2. During a DeFi protocol audit, which finding would be classified as a 'critical' severity vulnerability?
Reentrancy vulnerability allowing an attacker to drain all protocol funds in a single transaction

A reentrancy vulnerability enabling total fund drainage is critical because it directly threatens all user assets and can be exploited immediately upon deployment.

3. Which risk category does 'validator centralization' fall under in a Proof-of-Stake blockchain?
Systemic/concentration risk

Validator centralization creates systemic concentration risk because a small group controlling majority stake can collude to censor transactions or perform 51% attacks.

4. During an exchange audit, the auditor notices customer deposit addresses are reused for multiple clients. What is the primary audit concern?
It makes it impossible to attribute individual deposits to customers without off-chain ledger records

Reusing deposit addresses across multiple customers means that on-chain data alone cannot identify which customer made a deposit, creating a complete reliance on the exchange's internal records for attribution.

5. In a multi-signature (multisig) transaction audit, what document should an auditor review to verify the required signing threshold?
The redeem script embedded in the P2SH or P2WSH output

The redeem script specifies the M-of-N threshold and the participating public keys, making it the authoritative source for multisig verification.

6. Which of the following best describes a 'layering' stage red flag specific to cryptocurrency transactions?
Rapid sequential transfers through multiple wallets or exchanges across different blockchains with no apparent business purpose

Rapid multi-hop transfers across wallets and chains with no economic rationale are a classic layering technique to distance funds from their illicit origin.

🎯 Free CCA Practice Tests

📖 CCA Guides & Articles

Your CCA Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?