← All CCA Flashcard Decks

Blockchain Fundamentals Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Blockchain Fundamentals flashcards as text
  1. What is a 'blockchain fork' scenario that creates the highest compliance risk for a cryptocurrency custodian?

    Answer: A contentious hard fork creating two competing chains with the same transaction history up to the split

    A contentious hard fork creates two separate chains with divergent histories, forcing custodians to determine asset ownership, support obligations, and accounting treatment for both resulting tokens.

  2. How does a 'multi-signature wallet' reduce fraud risk compared to a single-key wallet?

    Answer: It requires M-of-N key holders to authorize transactions, preventing unilateral fund movement

    Multi-signature schemes require a threshold number of independent key holders to co-sign before funds move, implementing a cryptographic separation of duties that prevents single-point theft or error.

  3. What is 'chain reorganization' (reorg) and why should auditors flag exchanges that don't account for it?

    Answer: A situation where a longer competing chain replaces the canonical chain, potentially reversing confirmed transactions

    Chain reorganizations can reverse transactions that appeared confirmed, creating settlement risk for exchanges that credit user accounts too quickly — auditors should verify minimum confirmation policies.

  4. Which cryptographic primitive underpins the generation of cryptocurrency wallet addresses from public keys?

    Answer: A combination of SHA-256 and RIPEMD-160 hashing (or equivalent one-way functions)

    Bitcoin-style addresses are derived by hashing the public key through SHA-256 then RIPEMD-160, producing a shorter one-way fingerprint that cannot be reversed to expose the public key.

  5. What is the role of a 'blockchain oracle' and what audit risk does it introduce?

    Answer: An oracle feeds external real-world data into smart contracts; its risk is manipulation of that data feed

    Oracles bridge off-chain data (e.g., asset prices, event outcomes) to on-chain smart contracts, but a manipulated or compromised oracle can cause contracts to execute incorrectly, creating significant financial and audit risk.

  6. When auditing a DeFi protocol, what does 'total value locked' (TVL) measure and what are its limitations?

    Answer: TVL measures assets deposited into smart contracts; its limitation is that it can be inflated by circular deposits or token price volatility

    TVL represents the USD value of assets deposited in a DeFi protocol's smart contracts, but it can be inflated by self-referential deposits and fluctuates with token prices, making it an imprecise solvency metric.

  7. What distinguishes a 'public key' from a 'private key' in a blockchain wallet, and what is the audit implication of private key exposure?

    Answer: Public keys derive wallet addresses shared openly; private keys authorize transactions and their exposure means total loss of funds

    The private key is the sole authorization mechanism for spending funds; if exposed, anyone possessing it can irreversibly drain the wallet, representing a complete and unrecoverable asset loss.