Mixed Deck — All CBSA Topics Flashcards
100 cards from real CBSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CBSA Topics flashcards as text
A company is deploying a multi-cloud blockchain solution using Ethereum. Which deployment strategy best ensures high availability across cloud providers?
Answer: Active-active multi-region node deployment with load balancing
Active-active multi-region deployment ensures continuous availability by distributing nodes across providers so any single cloud failure does not disrupt the network.
What is the purpose of a 'block header' in a blockchain block?
Answer: It contains metadata including the previous block hash, timestamp, Merkle root, and nonce
The block header contains the cryptographic linkage (previous hash) and summary data (Merkle root) that allow lightweight verification without downloading all transactions.
A consortium of airlines wants to share loyalty points so passengers can redeem miles across carriers. Which blockchain type is most appropriate?
Answer: Consortium permissioned blockchain governed by participating airlines
A consortium permissioned blockchain lets competing airlines share a trusted loyalty ledger without any single carrier controlling it, balancing privacy with interoperability.
In the context of smart contract design, what is the primary purpose of the 'Checks-Effects-Interactions' pattern?
Answer: To prevent reentrancy attacks by performing state changes before external calls.
The 'Checks-Effects-Interactions' pattern is a security best practice designed to mitigate reentrancy vulnerabilities. It dictates that a function should first perform all necessary checks (e.g., `require` statements), then apply all effects to the contract's state (e.g., updating balances), and only then interact with external contracts or addresses. This ensures the internal state is consistent before any external code is executed.
In Ethereum smart contracts, what is a 'reentrancy attack'?
Answer: An external contract recursively calling back into the victim contract before state updates complete
Reentrancy attacks occur when a malicious contract calls back into the victim before its state (like balance) is updated, draining funds.
A pharmaceutical company wants to prevent counterfeit drugs from entering the supply chain. Which blockchain capability is MOST critical for this use case?
Answer: Immutable provenance tracking
Immutable provenance tracking ensures each drug's origin and chain of custody is permanently recorded and tamper-proof, directly combating counterfeiting.
An architect needs to design a blockchain solution that stores medical records. The solution must comply with HIPAA's right-to-erasure provisions. What is the recommended approach?
Answer: Store PII off-chain with only hashes on-chain
Storing personally identifiable information off-chain with only cryptographic hashes on-chain allows deletion of sensitive data while preserving the integrity proof on the immutable ledger.
A blockchain solution architect is evaluating consensus mechanisms and is primarily concerned with minimizing environmental impact and energy consumption. Which of the following mechanisms is designed to be the MOST energy-efficient alternative to Proof of Work (PoW)?
Answer: Proof of Stake (PoS)
Proof of Stake (PoS) was specifically developed as a more energy-efficient alternative to Proof of Work. Instead of requiring miners to expend vast amounts of computational power to solve cryptographic puzzles, PoS selects validators based on the amount of cryptocurrency they are willing to 'stake' as collateral. This eliminates the need for energy-intensive mining hardware, drastically reducing the network's overall energy consumption. While DPoS, PoA, and PoB are also more energy-efficient than PoW, PoS is the most direct and widely recognized alternative designed to solve the energy consumption problem.
A CBSA candidate is evaluating a public blockchain for a high-value asset tokenization platform. Which consensus feature is most critical for regulatory compliance?
Answer: Deterministic finality preventing transaction reversal
Asset tokenization for regulated markets requires deterministic finality so that settled transactions cannot be reversed, meeting financial regulators' settlement finality requirements.
Which feature of zero-knowledge proofs makes them valuable for blockchain privacy solutions?
Answer: They allow one party to prove knowledge of information without revealing the information itself
ZK proofs enable transaction validity to be verified without disclosing the underlying data, enabling privacy-preserving yet auditable blockchain transactions.
In a hybrid blockchain architecture, private transactions are typically handled by:
Answer: Off-chain databases with on-chain hash anchoring
Hybrid architectures often store sensitive data off-chain while anchoring cryptographic hashes on the public chain to ensure integrity without exposing private information.
What property of a Merkle tree allows efficient proof that a specific transaction is included in a block without downloading the entire blockchain?
Answer: Merkle proof (SPV proof)
A Merkle proof (used in Simplified Payment Verification) requires only a logarithmic number of hashes to prove inclusion without the full dataset.
What is the primary role of a mempool in blockchain architecture?
Answer: Holding unconfirmed transactions awaiting inclusion
The mempool (memory pool) is a node's local buffer of broadcast transactions not yet included in a block.
Which deployment model is most appropriate for a consortium blockchain where multiple competing companies must each independently verify transactions without trusting a central operator?
Answer: Decentralized deployment where each organization operates its own peer nodes
Each organization operating its own peer nodes ensures no single party controls validation, aligning with the trust model of a competitive consortium.
When a blockchain architect evaluates 'finality,' what property are they assessing?
Answer: The guarantee that a committed transaction cannot be reversed or altered
Finality describes the point after which a transaction is irreversibly settled; probabilistic finality (PoW) grows over time, while deterministic finality (BFT) is immediate.
When integrating a blockchain solution with an existing REST API ecosystem, which approach best maintains backward compatibility?
Answer: Deploy a middleware adapter layer that translates REST calls to blockchain transactions
A middleware adapter layer translates existing REST API calls into blockchain transactions, preserving backward compatibility for existing consumers.
A consortium is creating a blockchain-based platform for trading voluntary carbon credits. A key requirement is to prevent the 'double counting' of credits, where the same credit is sold or claimed multiple times. How does tokenizing carbon credits on a blockchain solve this specific problem?
Answer: By assigning a unique digital token to each verified carbon credit, which can be tracked from issuance to retirement on an immutable ledger.
Tokenization creates a unique digital representation for each distinct carbon credit. This token can be tracked on the blockchain's immutable ledger throughout its lifecycle. When the credit is 'used' or retired to offset emissions, the transaction is recorded permanently, preventing that specific token (and its underlying credit) from ever being sold or used again, thus solving the double-counting problem.
What is a 'full node' in a blockchain network architecture?
Answer: A node that stores and validates the complete blockchain history
Full nodes download, store, and independently validate every block and transaction in the blockchain's history, providing the highest level of trustless verification.
What is the architectural purpose of a 'channel' in Hyperledger Fabric?
Answer: To create isolated sub-networks with their own ledger, enabling data privacy between participant subsets
Channels in Fabric create private communication sub-networks; only channel members see transactions, allowing different consortia to share infrastructure while keeping data confidential.
What is the role of a Hardware Security Module (HSM) in a blockchain infrastructure deployment?
Answer: To securely store and manage cryptographic keys offline
An HSM is a dedicated hardware device that securely stores cryptographic keys and performs cryptographic operations, ensuring private keys never leave the secure environment.