Certified Blockchain Security Expert (CBSE) — Questions and Answers
Question 1: Which regulatory framework specifically governs data privacy implications of storing personal data on an immutable enterprise blockchain in the EU?
- GDPR (General Data Protection Regulation) (Correct answer)
- PCI-DSS v4.0
- SOX (Sarbanes-Oxley Act)
- HIPAA Security Rule
Correct answer: GDPR (General Data Protection Regulation)
GDPR's 'right to erasure' creates a direct conflict with blockchain immutability, requiring enterprises to use off-chain storage or cryptographic deletion techniques for EU personal data.
Question 2: A contract uses 'delegatecall' to load logic from a library. The library's storage layout differs from the calling contract's layout. What is the risk?
- Infinite loop causing denial of service
- Gas theft by the library
- Permanent locking of funds in the library
- Storage collision, leading to unintended state overwrites (Correct answer)
Correct answer: Storage collision, leading to unintended state overwrites
delegatecall executes the library code in the caller's storage context, so mismatched slot layouts cause the library to overwrite critical state variables.
Question 3: Which attack exploits the fact that a smart contract reads its own balance during execution and that balance can be manipulated before the call completes?
- Integer overflow
- Front-running
- Timestamp dependency
- Reentrancy (Correct answer)
Correct answer: Reentrancy
Reentrancy allows an external malicious contract to repeatedly call back into the victim contract before its state is updated, draining funds.
Question 4: Which of the following is the correct test to check for an 'uninitialized storage pointer' vulnerability in a Solidity contract?
- Check that all events are emitted in the correct order
- Call the contract constructor twice and observe state
- Deploy the contract and read storage slot 0 before any initialization occurs (Correct answer)
- Fuzz all public functions with zero-value inputs
Correct answer: Deploy the contract and read storage slot 0 before any initialization occurs
Reading storage slot 0 before initialization reveals whether an uninitialized pointer aliases it, potentially allowing unintended state overwrites.
Question 5: A threat model rates a vulnerability with high likelihood but low impact. How should this be prioritized compared to a low-likelihood, high-impact threat?
- Use risk scoring (likelihood × impact) to compare and prioritize objectively (Correct answer)
- Always prioritize the high-likelihood threat regardless of impact
- Always prioritize the high-impact threat regardless of likelihood
- Defer both threats since neither scores maximum on both axes
Correct answer: Use risk scoring (likelihood × impact) to compare and prioritize objectively
Risk scoring multiplies likelihood and impact to produce a comparable risk value, enabling objective prioritization across asymmetric threat profiles.
Question 6: What is a 'nothing-at-stake' problem in Proof-of-Stake consensus?
- Attackers can stake zero tokens to gain consensus power
- Validators lose all staked funds if they go offline
- Nodes have no incentive to participate in block validation
- Validators can vote on multiple competing forks at no additional cost (Correct answer)
Correct answer: Validators can vote on multiple competing forks at no additional cost
Nothing-at-stake means validators can simultaneously vote on all fork candidates without penalty, undermining finality and enabling double-spend attacks.
Question 7: A tester is evaluating a blockchain bridge contract and wants to confirm that a double-spend via replayed Merkle proofs is impossible. Which test is most appropriate?
- Check that the bridge contract's Ether balance matches total deposits
- Verify that the bridge emits a Deposit event for each transfer
- Submit the same valid Merkle proof twice and verify the second claim is rejected (Correct answer)
- Test that the bridge owner can pause the contract
Correct answer: Submit the same valid Merkle proof twice and verify the second claim is rejected
Replaying an already-processed Merkle proof tests whether the bridge contract tracks used proofs and correctly rejects duplicates.
Question 8: Which consensus security property ensures that if two honest nodes both finalize a block, those blocks must be the same block?
- Accountability
- Termination
- Safety (agreement) (Correct answer)
- Liveness
Correct answer: Safety (agreement)
Safety (also called agreement or consistency) guarantees that no two correct nodes ever commit different values at the same block height.
Question 9: An attacker performs a 51% attack and attempts to double-spend. Which cryptographic property of SHA-256 makes rewriting deep blockchain history computationally prohibitive even with majority hash power?
- Second pre-image resistance prevents altering the Merkle root
- Collision resistance prevents the attacker from finding any valid block hash
- The avalanche effect ensures that any small change to block data changes the nonce randomly
- Pre-image resistance forces the attacker to redo all proof-of-work for every block in the rewritten chain (Correct answer)
Correct answer: Pre-image resistance forces the attacker to redo all proof-of-work for every block in the rewritten chain
Pre-image resistance means there is no shortcut to find a nonce satisfying the target — the attacker must brute-force redo every block's proof-of-work for the rewritten chain.
Question 10: When documenting mitigations in a blockchain threat model, what distinguishes a 'compensating control' from a 'primary control'?
- A compensating control is applied at the network layer while a primary control is applied at the application layer
- A compensating control reduces risk when the primary control cannot be fully implemented, without eliminating the vulnerability (Correct answer)
- A compensating control applies only during incident response while a primary control is preventive
- A compensating control is automated while a primary control is manual
Correct answer: A compensating control reduces risk when the primary control cannot be fully implemented, without eliminating the vulnerability
A compensating control is a secondary measure that reduces residual risk when the ideal primary control is technically infeasible or too costly to implement fully.
Question 11: A blockchain development team is choosing a public-key cryptography algorithm for their new platform. They require high security with smaller key sizes to optimize for speed and reduce storage demands. Which algorithm best meets these requirements?
- SHA-256
- AES (Advanced Encryption Standard)
- ECC (Elliptic Curve Cryptography) (Correct answer)
- RSA (Rivest-Shamir-Adleman)
Correct answer: ECC (Elliptic Curve Cryptography)
Elliptic Curve Cryptography (ECC) provides the same level of security as other algorithms like RSA but with significantly smaller key sizes. This efficiency reduces computational overhead and storage requirements, making it ideal for resource-constrained environments and blockchain applications where performance is critical.
Question 12: Which cryptographic primitive ensures that a node's peer discovery messages in Ethereum's discv5 protocol cannot be forged by a third party?
- ECDSA signatures over the packet payload using the node's private key (Correct answer)
- HMAC-MD5 message authentication codes
- Symmetric AES-GCM encryption with a shared secret
- SHA-3 checksums appended to each packet
Correct answer: ECDSA signatures over the packet payload using the node's private key
discv5 packets are signed with ECDSA using the node's secp256k1 private key, binding each discovery message to a verifiable node identity.
Question 13: What does 'weak subjectivity' mean in the context of Proof-of-Stake security?
- PoS nodes are required to use social consensus to resolve disputes
- New nodes joining the network must trust a recent checkpoint rather than syncing from genesis to avoid long-range attacks (Correct answer)
- Validators must subjectively rate the quality of each block before voting
- New validators must accept reduced rewards until their stake is fully verified
Correct answer: New nodes joining the network must trust a recent checkpoint rather than syncing from genesis to avoid long-range attacks
Weak subjectivity acknowledges that PoS nodes syncing from scratch cannot cryptographically verify which chain is canonical without a trusted recent checkpoint.
Question 14: Which consensus-layer test verifies that a Byzantine node cannot force honest nodes to accept an invalid block?
- Byzantine fault tolerance (BFT) test (Correct answer)
- Sybil resistance test
- Throughput benchmark
- Peer discovery test
Correct answer: Byzantine fault tolerance (BFT) test
BFT testing injects nodes that send conflicting or invalid messages and checks whether honest nodes still reach correct consensus.
Question 15: Which consensus mechanism is most susceptible to a Sybil attack in an enterprise permissioned blockchain?
- Proof of Work (PoW) (Correct answer)
- Proof of Authority (PoA)
- Practical Byzantine Fault Tolerance (PBFT)
- Delegated Proof of Stake (DPoS)
Correct answer: Proof of Work (PoW)
Proof of Work is vulnerable to Sybil attacks because an attacker can create many identities and accumulate hashing power without a trusted identity layer.
Question 16: During an enterprise blockchain incident response, which forensic artifact is most valuable for reconstructing the sequence of malicious transactions?
- Network flow data captured by an IDS between peers
- The administrator's last login timestamp in the auth service
- The node's RAM dump at the time of detection
- The immutable on-chain transaction history and event logs (Correct answer)
Correct answer: The immutable on-chain transaction history and event logs
The blockchain's immutable ledger provides a tamper-evident, time-ordered record of all transactions and emitted events, making it the primary forensic source for incident reconstruction.
Question 17: What does 'transaction malleability' allow an attacker to do at the network level before a transaction is confirmed?
- Replay the same transaction on a forked chain
- Change the transaction amount without invalidating the signature
- Double-spend by broadcasting two conflicting transactions
- Alter the transaction ID (txid) by modifying the scriptSig without changing its validity (Correct answer)
Correct answer: Alter the transaction ID (txid) by modifying the scriptSig without changing its validity
Transaction malleability lets a third party tweak the scriptSig data, producing a different txid for the same economic transaction, which can confuse tracking systems.
Question 18: Which EVM feature limits the depth of nested calls, and what vulnerability arises when this limit is hit unexpectedly?
- Storage limit — causes data truncation
- Gas limit — causes out-of-gas revert
- Call stack depth limit (1024) — causes unexpected call failures (Correct answer)
- Memory limit — causes memory overflow
Correct answer: Call stack depth limit (1024) — causes unexpected call failures
The EVM enforces a maximum call stack depth of 1,024; an attacker can pre-fill the stack so a subsequent call in the victim contract fails silently if unchecked.
Question 19: Which vulnerability occurs when a Solidity contract performs arithmetic that silently wraps around due to type constraints in versions below 0.8.0?
- Reentrancy
- Short address attack
- Overflow/underflow (Correct answer)
- Signature replay
Correct answer: Overflow/underflow
Prior to Solidity 0.8.0, integer arithmetic did not automatically revert on overflow or underflow; values would silently wrap, enabling exploits like minting unlimited tokens.
Question 20: Which type of exam format does the CBSE certification primarily use?
- Portfolio submission and review
- Open-book essay format
- Oral interview with a panel of experts
- Multiple-choice questions administered in a proctored environment (Correct answer)
Correct answer: Multiple-choice questions administered in a proctored environment
The CBSE exam consists of multiple-choice questions delivered in a proctored, computer-based testing environment.
Question 21: Which firewall rule set best protects a Bitcoin full node while still allowing legitimate peer-to-peer traffic on mainnet?
- Allow inbound TCP 8333, block all other inbound; allow all outbound (Correct answer)
- Block all inbound and outbound traffic except port 443
- Allow all traffic on port 8333 and 8332 with no restrictions
- Allow all inbound TCP, block all UDP
Correct answer: Allow inbound TCP 8333, block all other inbound; allow all outbound
Bitcoin P2P runs on TCP 8333; restricting other inbound ports limits attack surface while allowing peers to connect, and blocking RPC port 8332 from inbound prevents remote RPC abuse.
Question 22: When designing a multi-signature wallet contract, what is the primary security risk of setting the required-signature threshold too low?
- Slower block confirmation times
- Increased gas costs per transaction
- Incompatibility with hardware wallets
- Reduced resistance to key compromise enabling unauthorized fund transfer (Correct answer)
Correct answer: Reduced resistance to key compromise enabling unauthorized fund transfer
A low threshold means compromising fewer keys is sufficient for an attacker to authorize transactions unilaterally.
Question 23: Which of the following best describes a 'griefing attack' test in the context of blockchain smart contracts?
- An attacker deploys a competing contract with lower fees
- An attacker steals private keys through phishing
- An attacker mines empty blocks to delay transactions
- An attacker causes a victim's transaction to fail or become expensive without direct financial gain (Correct answer)
Correct answer: An attacker causes a victim's transaction to fail or become expensive without direct financial gain
Griefing attack tests confirm that an adversary cannot force victims into costly failed transactions or endless loops without themselves profiting.
Question 24: What is a stealth address in privacy-focused blockchains, and which cryptographic operation is it based on?
- A one-time address per transaction derived via Diffie-Hellman key exchange between sender and recipient (Correct answer)
- A hash of the recipient's public key salted with the transaction nonce
- A zero-knowledge commitment to the recipient's real address
- A ring signature output used as a transaction destination
Correct answer: A one-time address per transaction derived via Diffie-Hellman key exchange between sender and recipient
Stealth addresses use ECDH between the sender's ephemeral key and the recipient's public key to generate a one-time address per transaction, unlinkable to the recipient's public identity.
Question 25: Which of the following correctly describes the role of a verifiable random function (VRF) in blockchain protocols like Algorand?
- It enables threshold signatures where the random value is only revealed after f+1 nodes agree
- It produces a publicly verifiable pseudorandom output tied to a private key, used for unpredictable but provable leader election (Correct answer)
- It provides a commitment to future random values used in smart contract lotteries
- It generates entropy for mining nonces that cannot be predicted by any single node
Correct answer: It produces a publicly verifiable pseudorandom output tied to a private key, used for unpredictable but provable leader election
VRFs let a node produce a random output along with a proof that the output was correctly computed from their private key, enabling fair and verifiable leader selection without a trusted third party.
Question 26: Which blockchain-specific threat involves an attacker deliberately delaying block propagation to increase the chance that their competing block is accepted?
- Grinding attack
- Selfish mining (Correct answer)
- Long-range attack
- Eclipse attack
Correct answer: Selfish mining
Selfish mining withholds discovered blocks to gain a disproportionate share of block rewards by forcing honest miners to waste work on orphaned chains.
Question 27: In Hyperledger Fabric, what component enforces which nodes are permitted to join the network and sign transactions?
- Orderer cluster
- CouchDB state database
- Gossip Service
- Membership Service Provider (MSP) (Correct answer)
Correct answer: Membership Service Provider (MSP)
The MSP manages digital identities (X.509 certificates) and defines policies that determine which identities can endorse, order, or submit transactions.
Question 28: A zero-knowledge proof allows a prover to convince a verifier of a statement's truth without revealing:
- The hash of the statement
- Any information beyond the validity of the statement itself (Correct answer)
- The identity of the verifier
- The public key used in the proof
Correct answer: Any information beyond the validity of the statement itself
Zero-knowledge proofs allow the prover to demonstrate knowledge of a secret (e.g., a private key) without disclosing any information about the secret itself.
Question 29: What is the primary security function of a blockchain oracle in a smart contract architecture?
- Providing authenticated real-world data to on-chain contracts (Correct answer)
- Encrypting private keys for external accounts
- Validating block headers across sidechains
- Generating randomness for consensus leader election
Correct answer: Providing authenticated real-world data to on-chain contracts
Oracles act as trusted data bridges, feeding external facts (prices, events) into smart contracts that cannot natively access off-chain information.
Question 30: Which testing technique is most effective for discovering re-entrancy vulnerabilities in smart contracts?
- Static code analysis
- Unit testing with mocked external calls
- Load testing
- Fuzz testing with recursive call injection (Correct answer)
Correct answer: Fuzz testing with recursive call injection
Fuzz testing with recursive call injection generates unexpected re-entrant call sequences that static analysis may miss.
Question 31: A blockchain node operator notices abnormally high CPU usage caused by peers repeatedly requesting the same large block. Which denial-of-service technique is being used?
- Bandwidth exhaustion via block re-request flooding (Correct answer)
- Block withholding attack
- Replay attack
- Timejacking
Correct answer: Bandwidth exhaustion via block re-request flooding
Flooding a node with repeated large-block requests wastes CPU and bandwidth resources, constituting a bandwidth exhaustion DoS against that node.
Question 32: Which document type is typically submitted to verify work experience during the CBSE accreditation process?
- Personal blog posts
- Social media endorsements
- Self-signed affidavit only
- Employer attestation or letter of reference (Correct answer)
Correct answer: Employer attestation or letter of reference
An employer attestation or reference letter from a supervisor verifies the authenticity of the candidate's claimed blockchain security experience.
Question 33: A smart contract function updates a user's balance after making an external call to an untrusted address. Which vulnerability is most likely to be exploited in this scenario?
- Reentrancy (Correct answer)
- Timestamp Dependency
- Gas Limit DoS
- Integer Overflow
Correct answer: Reentrancy
A reentrancy attack occurs when a function makes an external call to another contract before it updates its own state. An attacker can create a malicious contract with a fallback function that calls back into the original function repeatedly, draining funds before the balance is updated. The recommended mitigation is to follow the 'Checks-Effects-Interactions' pattern, where state changes are made *before* external calls.
Question 34: What does Shamir's Secret Sharing (SSS) accomplish in blockchain key management?
- It duplicates keys across multiple servers for redundant storage
- It encrypts private keys using the recipient's public key
- It generates child keys from a parent key using one-way derivation
- It splits a secret into shares where a minimum threshold can reconstruct the original (Correct answer)
Correct answer: It splits a secret into shares where a minimum threshold can reconstruct the original
Shamir's Secret Sharing splits a key into N shares where any M shares reconstruct the secret, distributing risk so no single share compromises the key and no single loss destroys it.
Question 35: An attacker sends ETH directly to a contract address using 'selfdestruct' before the contract is deployed (via CREATE2). What impact can this have?
- The Ethereum network forks automatically
- The contract deployment will fail permanently
- The pre-loaded ETH may break invariants that assume the contract starts with zero balance (Correct answer)
- The attacker gains ownership of the contract
Correct answer: The pre-loaded ETH may break invariants that assume the contract starts with zero balance
Because a CREATE2 address is deterministic, an attacker can seed ETH to that address beforehand; contracts that assume they start with zero balance (e.g., checking address(this).balance == 0) will behave incorrectly.
Question 36: During a security design review of a new token vesting smart contract, an auditor notes that the contract has a single `owner` role with unrestricted administrative privileges, including the ability to change vesting schedules, withdraw all tokens, and change ownership. This design most directly violates which core security principle?
- Defense in Depth
- Principle of Least Privilege (Correct answer)
- Open Design
- Psychological Acceptability
Correct answer: Principle of Least Privilege
The Principle of Least Privilege dictates that an entity should only have the minimum set of permissions necessary to perform its specific function. The `owner` role in this scenario has excessive, centralized power, creating a significant security risk. A better design would separate these powerful functions into different roles or require a multi-signature consensus to adhere to least privilege.
Question 37: A blockchain design uses a separate chain for high-frequency micropayments that periodically settles to the main chain. This pattern is best described as:
- Cross-chain atomic swap
- Sidechain (Correct answer)
- State channel / payment channel
- Sharding
Correct answer: Sidechain
A sidechain runs independently with its own consensus and periodically anchors or transfers assets back to the main chain.
Question 38: An attacker observes a large buy order for a specific token in the mempool of a decentralized exchange. They quickly submit their own buy order for the same token with a higher gas fee, followed immediately by a sell order. What is this type of attack called?
- Unchecked External Call
- Timestamp Dependency
- Front-Running (Sandwich Attack) (Correct answer)
- Integer Overflow
Correct answer: Front-Running (Sandwich Attack)
This is a classic example of a front-running attack, specifically a 'sandwich attack'. The attacker sees a pending transaction in the mempool and places a transaction before it (by paying a higher gas fee) and another one after it. This allows them to profit from the price slippage caused by the victim's large trade.
Question 39: In a blockchain security audit, which property is verified by 'liveness testing'?
- That node software cannot be remotely crashed
- That private keys are stored securely
- That the network eventually processes valid transactions (Correct answer)
- That block hashes are collision-resistant
Correct answer: That the network eventually processes valid transactions
Liveness testing confirms that the blockchain system continues to make progress and process valid transactions under normal and adverse conditions.
Question 40: An attacker who controls 34% of staked ETH in Ethereum's PoS can threaten which consensus property?
- They can rewrite all blocks in the last 24 hours
- They can immediately double-spend any transaction
- They can halt the P2P gossip layer entirely
- They can prevent finality by withholding enough votes to block the 2/3 supermajority (Correct answer)
Correct answer: They can prevent finality by withholding enough votes to block the 2/3 supermajority
Ethereum's Casper FFG requires a 2/3 supermajority to finalize checkpoints; 34% stake allows an attacker to indefinitely block finality without achieving majority control.
Question 41: A forensics investigator needs to prove a specific transaction occurred at a certain time on a public blockchain. What provides this proof?
- The transaction hash, block number, and block timestamp anchored to the immutable chain (Correct answer)
- The mempool receipt
- The contract owner's signature
- A timestamping certificate from a CA
Correct answer: The transaction hash, block number, and block timestamp anchored to the immutable chain
The combination of transaction hash, block number, and finalized block timestamp provides tamper-evident, court-admissible proof of occurrence.
Question 42: Which attack model assumes the adversary can request signatures on arbitrary messages but cannot choose the message after seeing the signature?
- Chosen-message attack (Correct answer)
- Adaptive chosen-message attack
- Chosen-ciphertext attack
- Known-message attack
Correct answer: Chosen-message attack
In a chosen-message attack, the adversary selects messages to be signed before seeing any signatures, testing if forging new signatures is possible.
Question 43: Which testing approach is most appropriate for validating that a permissioned blockchain's access control policies are correctly enforced at the network layer?
- Network-level penetration testing with unauthorized node identities (Correct answer)
- Merkle root verification
- Gas profiling of transactions
- Unit testing of smart contract modifiers
Correct answer: Network-level penetration testing with unauthorized node identities
Network-level penetration testing using unauthorized node certificates or identities directly tests whether the permissioning layer rejects unauthorized participants.
Question 44: What is the primary purpose of a blockchain node's mempool (memory pool) from a security perspective?
- Storing private keys for hot wallets
- Permanently storing confirmed transactions
- Holding unconfirmed transactions pending inclusion in a block (Correct answer)
- Caching block headers for fast retrieval
Correct answer: Holding unconfirmed transactions pending inclusion in a block
The mempool temporarily holds unconfirmed transactions; attackers can exploit it via transaction pinning or fee manipulation to delay or block legitimate transactions.
Question 45: Which network segmentation practice best reduces the blast radius if a single blockchain node in an enterprise deployment is compromised?
- Disabling TLS between internal nodes to reduce latency
- Running all nodes on the same VLAN to simplify monitoring
- Using a single shared API gateway for all node RPC calls
- Isolating each node in its own network segment with strict inter-node firewall rules (Correct answer)
Correct answer: Isolating each node in its own network segment with strict inter-node firewall rules
Network microsegmentation limits lateral movement; a compromised node cannot directly reach other nodes' RPC ports or internal services if each segment has dedicated ACLs.
Question 46: Which LINDDUN privacy threat category is most relevant when a blockchain's transaction graph allows de-anonymization of user identities?
- Unawareness
- Detectability
- Non-repudiation
- Linkability (Correct answer)
Correct answer: Linkability
Linkability in LINDDUN describes the ability to correlate transactions or identities across a system, enabling de-anonymization in transparent blockchains.
Question 47: Slashing conditions in Ethereum's Casper PoS protocol are designed primarily to penalize which behavior?
- Connecting to too many peer nodes simultaneously
- Staking below the minimum required validator balance
- Failing to produce a block when selected as proposer
- Equivocation — signing two conflicting blocks at the same height (Correct answer)
Correct answer: Equivocation — signing two conflicting blocks at the same height
Slashing penalizes equivocation (double-voting or double-proposing) by destroying a portion of the offending validator's staked ETH.
Question 48: Ethereum's Gasper consensus combines Casper FFG with LMD-GHOST. What does LMD-GHOST stand for?
- Latency-Minimized Directed Gossip Heuristic Over Stake Trees
- Longest Message Directed Graph Heuristic Ordering System Tree
- Least-Median Distance Greedy Hash Ordered Subtree
- Latest Message Driven Greediest Heaviest Observed SubTree (Correct answer)
Correct answer: Latest Message Driven Greediest Heaviest Observed SubTree
LMD-GHOST uses each validator's latest message to weight the fork-choice rule, selecting the subtree with the most accumulated validator support.
Question 49: Which attack type specifically manipulates users into voluntarily revealing wallet credentials or seed phrases?
- 51% attack on the blockchain network
- Phishing and social engineering attacks (Correct answer)
- Eclipse attack on network nodes
- Replay attack on signed transactions
Correct answer: Phishing and social engineering attacks
Social engineering and phishing attacks exploit human psychology to trick users into voluntarily disclosing wallet credentials, seed phrases, or private keys to attackers.
Question 50: A threat model for a cross-chain bridge identifies that the bridge's multi-sig wallet requires only 2-of-5 signers. What threat does this primarily expose?
- Replay attacks across chains
- Threshold compromise allowing unauthorized fund transfers with only 2 colluding signers (Correct answer)
- Denial of service via key exhaustion
- Reentrancy in the bridge smart contract
Correct answer: Threshold compromise allowing unauthorized fund transfers with only 2 colluding signers
A low threshold means only 2 signers need to be compromised or collude for an attacker to authorize fraudulent cross-chain transfers.
Question 51: A development team is architecting a decentralized gaming application that requires thousands of transactions per second with low fees. Deploying directly on a popular Layer 1 blockchain would be prohibitively slow and expensive. Which architectural approach should they adopt to achieve the required performance while retaining the security guarantees of the underlying Layer 1?
- Create their own private Proof-of-Authority sidechain without a link to the mainnet.
- Instruct users to pay higher gas fees to prioritize their transactions.
- Increase the complexity of their smart contract logic.
- Utilize a Layer 2 scaling solution, such as an optimistic or ZK-rollup. (Correct answer)
Correct answer: Utilize a Layer 2 scaling solution, such as an optimistic or ZK-rollup.
Layer 2 scaling solutions (like rollups) are designed specifically for this purpose. They process transactions off-chain at high speed and low cost, then bundle or "roll up" the results and post a compressed summary and cryptographic proof back to the secure Layer 1. This provides high throughput while inheriting the security and finality of the main chain.
Question 52: During smart contract testing, a developer notices that arithmetic on uint8 values silently wraps at 255 in older Solidity versions. Which mitigation should the test verify is in place?
- Use of the SafeMath library or Solidity ^0.8.x built-in overflow checks (Correct answer)
- Adding a require statement only on subtraction operations
- Casting all uint8 values to uint256 before display
- Using unchecked blocks for all arithmetic
Correct answer: Use of the SafeMath library or Solidity ^0.8.x built-in overflow checks
SafeMath or Solidity 0.8.x automatic overflow/underflow reversion prevents silent wraparound that attackers can exploit to manipulate balances.
Question 53: In Byzantine Fault Tolerant (BFT) consensus, what is the maximum fraction of faulty nodes the system can tolerate while still reaching agreement?
- Less than one-third of all nodes (Correct answer)
- Less than one-half of all nodes
- Less than two-thirds of all nodes
- Any fraction, as long as faulty nodes are identified
Correct answer: Less than one-third of all nodes
Classical BFT requires that fewer than one-third of nodes are Byzantine (malicious or faulty) to guarantee safety and liveness.
Question 54: In STRIDE threat modeling applied to a blockchain node, which threat category specifically addresses a malicious node falsely claiming to be a trusted validator?
- Spoofing (Correct answer)
- Repudiation
- Tampering
- Information Disclosure
Correct answer: Spoofing
Spoofing in STRIDE covers identity impersonation, such as a node falsely presenting itself as a legitimate validator to gain trust.
Question 55: In HD (Hierarchical Deterministic) wallets defined by BIP-32, child private keys are derived using HMAC-SHA512 applied to:
- The wallet password and a random salt
- The master seed and the block height
- The transaction hash and the derivation index
- The parent public key (or private key) and a chain code (Correct answer)
Correct answer: The parent public key (or private key) and a chain code
BIP-32 child key derivation uses HMAC-SHA512 with the parent key material and chain code as inputs, producing a deterministic child key and new chain code.
Question 56: Which vulnerability is introduced when an upgradeable contract's 'initialize' function lacks an 'initializer' modifier or equivalent guard?
- Any caller can invoke initialize multiple times, potentially resetting ownership or critical state to attacker-controlled values (Correct answer)
- The implementation contract's constructor runs every time initialize is called
- The contract cannot be upgraded after deployment
- The proxy contract will reject all delegatecall instructions
Correct answer: Any caller can invoke initialize multiple times, potentially resetting ownership or critical state to attacker-controlled values
Without an initializer guard, the initialize function can be called repeatedly or by an unauthorized party, allowing an attacker to take ownership of the contract.
Question 57: In Ethereum's Keccak-256 implementation, how does it differ from the NIST standardized SHA-3?
- Ethereum uses a 512-bit output truncated to 256 bits
- Ethereum uses a different padding scheme than the NIST finalized SHA-3 standard (Correct answer)
- Ethereum applies SHA-3 twice for added security
- Ethereum's version applies a key derivation step before hashing
Correct answer: Ethereum uses a different padding scheme than the NIST finalized SHA-3 standard
Ethereum adopted Keccak-256 before NIST finalized SHA-3 and applied a different padding rule; NIST's SHA-3 uses a different domain separation suffix, making them produce different outputs.
Question 58: A private consortium blockchain uses the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm. The network consists of 10 validator nodes. What is the maximum number of malicious or faulty nodes the network can withstand while still guaranteeing consensus?
- 5
- 4
- 1
- 3 (Correct answer)
Correct answer: 3
Practical Byzantine Fault Tolerance (PBFT) is designed to function correctly as long as the number of faulty or malicious nodes (f) is less than one-third of the total number of nodes (n). The formula is (n-1)/3. In a network with 10 nodes, n=10. The maximum number of faulty nodes (f) would be (10-1)/3 = 3.
Question 59: A DeFi protocol relies on an oracle to provide real-world asset prices to its smart contracts. To ensure architectural robustness and security, which of the following is the most critical design choice to mitigate risks of price manipulation and single points of failure?
- Caching the price data on-chain to reduce external calls.
- Implementing a decentralized oracle network (DON) that aggregates data from multiple independent nodes and sources. (Correct answer)
- Using a single, highly trusted data source like a major exchange API.
- Choosing an oracle that provides the fastest data updates.
Correct answer: Implementing a decentralized oracle network (DON) that aggregates data from multiple independent nodes and sources.
A decentralized oracle network (DON) is the standard architectural pattern for secure oracle design. It uses multiple independent nodes to fetch data from numerous sources, aggregates the results, and reports a consensus value to the smart contract. This decentralization prevents a single point of failure and makes data manipulation significantly more difficult and expensive.
Question 60: A DevSecOps engineer wants to detect if a blockchain node binary has been tampered with before deployment. What is the most reliable verification method?
- Checking the file size matches the expected value
- Verifying the cryptographic hash (SHA-256) against the official signed release hash (Correct answer)
- Running the binary and checking its version output string
- Comparing the file modification timestamp to the release date
Correct answer: Verifying the cryptographic hash (SHA-256) against the official signed release hash
A SHA-256 hash verified against a developer-signed checksum file ensures the binary is byte-for-byte identical to the official release, detecting any tampering or supply-chain substitution.
Question 61: Which of the following best explains why blockchain security is a distinct discipline from traditional cybersecurity?
- Blockchain security only concerns hardware wallet firmware vulnerabilities
- Blockchain systems do not use cryptography, so standard tools do not apply
- Blockchain introduces decentralized trust models, immutable ledgers, and smart contract attack surfaces unique to the technology (Correct answer)
- Blockchain networks are fully air-gapped and immune to internet-based attacks
Correct answer: Blockchain introduces decentralized trust models, immutable ledgers, and smart contract attack surfaces unique to the technology
Blockchain's decentralized architecture, immutability, and smart contract logic create a unique threat landscape that extends beyond conventional cybersecurity domains.
Question 62: Which audit technique is most effective for discovering integer overflow vulnerabilities in Solidity contracts older than version 0.8.0?
- Reviewing only the Natspec documentation for missing SafeMath references
- Running the contract through an ERC-20 linter
- Checking the Solidity pragma version alone is sufficient
- Dynamic fuzz testing with maximum uint256 boundary values (Correct answer)
Correct answer: Dynamic fuzz testing with maximum uint256 boundary values
Fuzz testing with extreme boundary values (e.g., type(uint256).max) automatically surfaces wrap-around behavior that manual review or linting may miss.
Question 63: A threat model for a blockchain wallet identifies seed phrase backup as a critical asset. Which threat to this asset is classified as an 'insider threat'?
- A phishing site tricking the user into entering their seed phrase
- A remote attacker brute-forcing the wallet password
- A malicious wallet developer embedding a seed exfiltration backdoor in the app (Correct answer)
- A supply chain compromise of a hardware wallet firmware update
Correct answer: A malicious wallet developer embedding a seed exfiltration backdoor in the app
An insider threat originates from a trusted party with privileged access, such as a developer intentionally inserting malicious code to steal seed phrases.
Question 64: In a DeFi protocol threat model, what does 'oracle manipulation' represent as an attack surface?
- Bypassing gas fee limits in smart contracts
- Compromising the RPC node API endpoint
- Feeding false external price data to influence on-chain contract logic (Correct answer)
- Exploiting the block reward algorithm
Correct answer: Feeding false external price data to influence on-chain contract logic
Oracle manipulation involves supplying tampered off-chain data (e.g., asset prices) to smart contracts, allowing attackers to exploit dependent logic.
Question 65: A blockchain tester wants to verify that a node correctly enforces the longest-chain rule during a network partition. Which test environment best supports this?
- Simulated network with configurable partition controls (Correct answer)
- Single-node testnet
- Mainnet fork snapshot
- Ganache in-memory blockchain
Correct answer: Simulated network with configurable partition controls
A simulated network with configurable partition controls lets testers isolate node clusters and observe fork-resolution behavior.
Question 66: Which mitigation directly addresses the risk of a compromised or malicious contract being set as the logic implementation in an upgradeable proxy?
- Using a timelocked upgrade process with a multi-signature governance requirement (Correct answer)
- Replacing delegatecall with staticcall for all implementation calls
- Compiling the proxy with optimizer runs set to zero
- Disabling selfdestruct in the implementation contract
Correct answer: Using a timelocked upgrade process with a multi-signature governance requirement
A timelock combined with multi-sig governance ensures no single party can instantly swap in malicious logic; stakeholders have a window to detect and cancel a malicious upgrade.
Question 67: A security analyst is performing a threat modeling exercise on a new DeFi lending protocol. The protocol uses a decentralized price oracle to determine asset values for collateralization. A potential threat identified is that an attacker could manipulate the oracle's price feed to cause unfair liquidations. Using the DREAD model to rate this threat, which component would likely score the highest?
- Reproducibility
- Affected Users
- Damage Potential (Correct answer)
- Discoverability
Correct answer: Damage Potential
The Damage Potential of a successful price oracle manipulation attack on a DeFi lending protocol is extremely high, as it could lead to the mass liquidation of user positions and the theft of millions of dollars in collateral. While other DREAD components are relevant, the potential for catastrophic financial loss makes Damage Potential the most significant factor.
Question 68: In a Sybil attack against a proof-of-stake blockchain, what is the primary resource an attacker leverages to gain disproportionate influence over the network?
- Exploiting a zero-day vulnerability in the node's client software.
- A large number of IP addresses to create seemingly distinct nodes.
- Control over a large amount of the network's staked cryptocurrency. (Correct answer)
- Significant computational power to solve complex cryptographic puzzles.
Correct answer: Control over a large amount of the network's staked cryptocurrency.
In a proof-of-stake (PoS) system, influence (such as the ability to validate transactions and create new blocks) is proportional to the amount of cryptocurrency a user is staking. A Sybil attack in a PoS context involves an attacker using a large stake, possibly distributed across many addresses they control, to gain undue influence. While having many IP addresses can help create the illusion of many participants, the core of the attack's power in PoS comes from the staked capital, not computational power (as in PoW) or just the number of node identities.
Question 69: Which design pattern prevents a malicious contract from consuming all available gas in a loop when processing an unbounded array of user records?
- Proxy upgrade pattern
- Pull-over-push payment pattern
- Batch processing with gas limit checks per iteration (Correct answer)
- Circuit breaker pattern
Correct answer: Batch processing with gas limit checks per iteration
Checking remaining gas inside each loop iteration and halting gracefully prevents out-of-gas failures from unbounded on-chain iteration.
Question 70: A government agency wants to build a blockchain-based system for citizens to vote. A critical design requirement is that the system must be able to verify that a person is an eligible voter and has only voted once, all without revealing who the voter is or which candidate they chose. Which architectural component is essential for meeting this privacy requirement?
- A Proof-of-Work consensus mechanism to secure the voting record.
- Implementation of Zero-Knowledge Proofs (ZKPs) to validate voter eligibility and uniqueness. (Correct answer)
- A transparent public ledger where all votes are pseudonymously recorded.
- The use of a centralized server to tally votes before publishing results.
Correct answer: Implementation of Zero-Knowledge Proofs (ZKPs) to validate voter eligibility and uniqueness.
Zero-Knowledge Proofs (ZKPs) are a cryptographic method that allows one party to prove to another that a statement is true, without revealing any information beyond the validity of the statement itself. In this scenario, a ZKP could prove a voter is on the eligible list and has not yet voted, without revealing their identity, thus preserving privacy.
Question 71: Which of the following is a primary focus of threat modeling specifically for the smart contract layer of a blockchain application, as opposed to the network or consensus layer?
- Re-entrancy and integer overflow vulnerabilities (Correct answer)
- Selfish mining strategies
- Sybil attacks on network nodes
- Eclipse attacks isolating a particular node
Correct answer: Re-entrancy and integer overflow vulnerabilities
Re-entrancy and integer overflow are vulnerabilities that exist within the code of the smart contract itself. Threat modeling at this layer involves analyzing the application logic for such flaws. The other options (Sybil attacks, eclipse attacks, selfish mining) are primarily threats against the consensus and network layers of the blockchain protocol.
Question 72: What is the key difference between cryptographic hashing and encryption in the context of blockchain security?
- Hashing is a reversible process, while encryption is irreversible.
- Encryption is a one-way function, while hashing is a two-way function.
- Hashing is a one-way function primarily for data integrity, while encryption is a two-way function for data confidentiality. (Correct answer)
- Hashing is used for data confidentiality, while encryption is used for data integrity.
Correct answer: Hashing is a one-way function primarily for data integrity, while encryption is a two-way function for data confidentiality.
The fundamental difference is reversibility and purpose. Hashing is a one-way, irreversible function that converts data into a unique digest to verify integrity. Encryption is a two-way, reversible process that converts plaintext to ciphertext and back again using a key, with the primary goal of ensuring data confidentiality.
Question 73: In a Proof-of-Work blockchain, what condition must an attacker satisfy to execute a 51% attack successfully?
- Own more than half of all circulating tokens
- Compromise more than half of all validator nodes
- Control more than half of the network's total hash rate (Correct answer)
- Possess private keys for more than half of all wallets
Correct answer: Control more than half of the network's total hash rate
A 51% attack requires the attacker to control the majority of the network's computational hash rate, enabling them to rewrite recent blocks and double-spend.
Question 74: What is the security implication of running a blockchain node with the '--rpcallowip=0.0.0.0/0' flag in Bitcoin Core?
- It exposes the RPC server to all IP addresses, allowing any host to send commands (Correct answer)
- It forces all wallet operations through a hardware security module
- It enables faster block validation by allowing parallel RPC calls
- It disables transaction broadcast to external peers
Correct answer: It exposes the RPC server to all IP addresses, allowing any host to send commands
Setting rpcallowip to 0.0.0.0/0 removes IP-based access control on the RPC port, allowing any internet host to issue wallet and node-management commands.
Question 75: What security property distinguishes 'safety' from 'liveness' in distributed consensus?
- Safety prevents double-spending; liveness prevents eclipse attacks
- Safety guarantees no two honest nodes commit conflicting values; liveness guarantees the system eventually makes progress (Correct answer)
- Safety guarantees fast block finality; liveness guarantees resistance to Sybil attacks
- Safety requires BFT node counts; liveness requires PoW hash rate thresholds
Correct answer: Safety guarantees no two honest nodes commit conflicting values; liveness guarantees the system eventually makes progress
Safety means the system never produces contradictory finalized outputs; liveness means honest nodes will eventually reach a decision even under adversarial conditions.
Question 76: Grover's quantum algorithm poses a threat to symmetric cryptography by reducing the effective security of an n-bit key to approximately:
- log₂(n) bits
- n-128 bits
- n/2 bits (Correct answer)
- n/4 bits
Correct answer: n/2 bits
Grover's algorithm provides a quadratic speedup for brute-force search, effectively halving the bit security of symmetric keys, so AES-256 retains ~128 bits of quantum security.
Question 77: A contract emits an 'Approval' event but never actually updates the allowance mapping. Which vulnerability category does this represent?
- Reentrancy through event callbacks
- Cross-contract read inconsistency
- Event spoofing / misleading event emission (Correct answer)
- Integer underflow in the allowance mapping
Correct answer: Event spoofing / misleading event emission
Emitting events without corresponding state changes deceives off-chain systems (wallets, indexers) into believing an action occurred, which can be exploited to authorize operations that were never truly granted.
Question 78: A smart contract allows the owner to withdraw all Ether with a single function call with no time-lock. Which test case best captures the associated risk?
- Call the withdraw function as a non-owner and verify it reverts
- Test that the owner can drain all funds instantly, simulating a rug-pull scenario (Correct answer)
- Verify that the function emits a Transfer event
- Test that the contract balance matches expected deposits
Correct answer: Test that the owner can drain all funds instantly, simulating a rug-pull scenario
Simulating an owner-initiated full drain reveals the rug-pull risk that users face when a contract has unrestricted withdrawal authority.
Question 79: Which architectural pattern ensures that a blockchain network can continue operating and reaching consensus even when a minority of validator nodes go offline simultaneously?
- Optimistic rollup with a fraud proof window
- Byzantine Fault Tolerant protocol with liveness under (n - f) > 2f honest nodes (Correct answer)
- Synchronous network assumption with timeout-based recovery
- Proof-of-Authority with a designated backup leader
Correct answer: Byzantine Fault Tolerant protocol with liveness under (n - f) > 2f honest nodes
BFT protocols guarantee liveness as long as more than two-thirds of nodes are honest and responsive, so a minority outage does not halt the network.
Question 80: Which smart contract design pattern directly reduces the attack surface of upgradeable contracts by separating logic from state?
- Observer pattern with event-driven state updates
- Singleton pattern with a global registry
- Proxy pattern with separated storage and logic contracts (Correct answer)
- Factory pattern
Correct answer: Proxy pattern with separated storage and logic contracts
The proxy pattern keeps state in one contract while logic lives in a separate implementation contract, allowing upgrades without migrating stored data.
Certified Blockchain Security Expert (CBSE)
The CBSE certification by 101 Blockchains validates expertise in blockchain security across threat modeling, cryptography, consensus algorithm security, smart contract security, node/network security, and enterprise blockchain security. It is designed for security professionals seeking to identify and mitigate risks in blockchain ecosystems.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds