NFT Development Certification Exam — Questions and Answers
Question 1: Which parameters does royaltyInfo accept?
- _contract and _value
- _buyer and _seller
- _tokenId and _salePrice (Correct answer)
- _owner and _amount
Correct answer: _tokenId and _salePrice
royaltyInfo takes the token ID and the sale price, then computes the royalty owed.
Question 2: A marketplace shows a stale price after an item sells. Which integration practice best prevents this?
- Refreshing only once per day
- Trusting the buyer to report sales
- Polling the image URL
- Listening to on-chain events (e.g., OrderFulfilled, Transfer) to invalidate cached orders (Correct answer)
Correct answer: Listening to on-chain events (e.g., OrderFulfilled, Transfer) to invalidate cached orders
Subscribing to fulfillment and transfer events lets the integration remove or update orders the moment state changes on-chain.
Question 3: In November 2025, which of the following Bollywood actors recently released his own collection of NFTs?
- Hrithik Roshan
- Akshay Kumar
- Amitabh Bachchan (Correct answer)
- None of the options are correct
- Shahrukh Khan
Correct answer: Amitabh Bachchan
In November 2021, legendary Bollywood actor Amitabh Bachchan released his own collection of NFTs, which included unique digital collectibles like his father's poems and signed posters. This marked a significant entry of a major Indian celebrity into the burgeoning NFT space. The question's year '2025' is likely a typo, referring to a past event.
Question 4: What data structure is most commonly used to implement gas-efficient NFT allowlists on Ethereum?
- Binary search tree
- Linked list of addresses
- On-chain address array
- Merkle tree (Correct answer)
Correct answer: Merkle tree
Merkle trees represent the entire allowlist with a single 32-byte root stored on-chain, while users provide off-chain proofs to verify membership.
Question 5: Which Solidity pattern helps prevent reentrancy attacks during minting or withdrawals?
- Batch transfer
- Proxy delegation
- Lazy minting
- Checks-Effects-Interactions (Correct answer)
Correct answer: Checks-Effects-Interactions
The Checks-Effects-Interactions pattern updates state before external calls, preventing reentrancy.
Question 6: A marketplace calls royaltyInfo with a salePrice of 0. What is the expected royaltyAmount?
- Reverts the transaction
- A default minimum fee
- The full creator royalty
- 0 (Correct answer)
Correct answer: 0
Royalty is calculated as a fraction of salePrice, so a zero salePrice yields a zero royalty.
Question 7: Why should the contract address be included in the signed message payload for signature-based allowlists?
- To allow the contract to auto-verify the caller's identity without ecrecover()
- To comply with EIP-712 domain separator requirements for gas savings
- To prevent cross-contract replay attacks where a valid signature for one NFT collection is submitted to a different collection's contract (Correct answer)
- To reduce gas by hashing fewer parameters together
Correct answer: To prevent cross-contract replay attacks where a valid signature for one NFT collection is submitted to a different collection's contract
Binding the signature to a specific contract address ensures it cannot be replayed against a different contract that uses the same trusted signer, even if deployed by the same team.
Question 8: What vulnerability arises from using delegatecall to an untrusted contract in an upgradeable NFT proxy?
- It doubles all gas costs
- It prevents the token from being transferred
- The called code runs in the proxy's storage context and can overwrite critical state (Correct answer)
- It permanently disables the fallback function
Correct answer: The called code runs in the proxy's storage context and can overwrite critical state
delegatecall executes external code against the caller's storage, so a malicious implementation can corrupt or hijack proxy state.
Question 9: What is the ERC-165 interface ID for EIP-2981?
- 0x2a55205a (Correct answer)
- 0x80ac58cd
- 0x01ffc9a7
- 0x5b5e139f
Correct answer: 0x2a55205a
0x2a55205a is the interface ID corresponding to the royaltyInfo selector for EIP-2981.
Question 10: Why should a frontend estimate gas (e.g., estimateGas) before submitting a mint transaction?
- To bypass the wallet
- To increase the token supply
- To change the contract owner
- To catch reverts early and show the user an accurate fee preview (Correct answer)
Correct answer: To catch reverts early and show the user an accurate fee preview
estimateGas simulates the call, surfacing reverts and giving a fee estimate before the user signs.
Question 11: Why is hardcoding a contract ABI's full source unnecessary, and a minimal 'human-readable ABI' often sufficient on the frontend?
- The full ABI breaks MetaMask
- ABIs are illegal to include
- Only the function and event signatures the app calls are needed to encode/decode calls (Correct answer)
- ABIs must be base64 only
Correct answer: Only the function and event signatures the app calls are needed to encode/decode calls
The frontend only needs the signatures of the functions and events it interacts with to encode calls.
Question 12: Why should NFT contracts avoid using `_safeMint` when minting to known EOA addresses in bulk?
- _safeMint skips event emission
- _safeMint does not update ownership records
- _safeMint is deprecated in OpenZeppelin v5
- _safeMint makes an external call to check ERC-721 receiver support, adding gas overhead (Correct answer)
Correct answer: _safeMint makes an external call to check ERC-721 receiver support, adding gas overhead
`_safeMint` calls `onERC721Received` on the recipient if it's a contract, adding an external call and re-entrancy guard overhead unnecessary for plain EOAs.
Question 13: What is 'lazy minting' in NFT development?
- Pre-minting all tokens at contract deployment
- Deferring on-chain minting until the first purchase or claim (Correct answer)
- Minting tokens on a testnet before mainnet
- Minting tokens without any metadata
Correct answer: Deferring on-chain minting until the first purchase or claim
Lazy minting defers the actual on-chain transaction until a buyer claims the NFT, so the creator avoids upfront gas costs.
Question 14: In ERC-721, what does approve(address, uint256) grant?
- Permission for one address to transfer one specific token (Correct answer)
- Operator rights over all tokens
- The right to burn the contract
- Ownership of the token
Correct answer: Permission for one address to transfer one specific token
approve authorizes a single address to transfer that one specific tokenId.
Question 15: Which of the following best describes the core mechanic and intended purpose of a Soulbound Token (SBT) as proposed in standards like EIP-5192?
- It can be fractionally owned by multiple wallets through ERC-20 tokens.
- It allows an NFT's metadata to be dynamically updated by a trusted oracle.
- It bundles multiple fungible and non-fungible tokens into a single token ID.
- It is permanently bound to a single account and cannot be transferred. (Correct answer)
Correct answer: It is permanently bound to a single account and cannot be transferred.
The defining characteristic of a Soulbound Token is that it is non-transferable. Once issued to an account (a "soul"), it cannot be sold or sent to another account, making it ideal for representing personal achievements, credentials, or affiliations that should not be tradable.
Question 16: Which Ethereum standard is the foundation for non-fungible tokens?
- ERC-777
- ERC-20
- ERC-721 (Correct answer)
- ERC-1155
Correct answer: ERC-721
ERC-721 defines the standard interface for unique, non-fungible tokens.
Question 17: What is a key risk when integrating a marketplace that allows arbitrary external contract calls in order fulfillment?
- Shorter token names
- Higher royalty payouts
- Slower image loading
- Malicious orders could trigger phishing approvals or drain wallets (Correct answer)
Correct answer: Malicious orders could trigger phishing approvals or drain wallets
Allowing arbitrary calls during fulfillment can be abused to trick users into harmful approvals or transfers, so such flows need strict validation.
Question 18: In ethers.js v6, what does a 'Contract' instance need to send a state-changing mint transaction rather than just read data?
- Only a JSON-RPC provider
- A signer connected to the contract (Correct answer)
- A private key hardcoded in the frontend
- An Infura API key in the HTML
Correct answer: A signer connected to the contract
Read calls work with a provider, but write transactions require a signer that can authorize and submit them.
Question 19: What is the most common and standardized method for 'burning' an ERC-721 NFT, effectively removing it from circulation?
- Overwriting the token's metadata URI to make it invalid.
- Transferring the token to the zero address (0x000...000). (Correct answer)
- Deleting the token's data from the contract's storage.
- Sending the token to a verifiably un-spendable 'burner' contract.
Correct answer: Transferring the token to the zero address (0x000...000).
The standard convention for burning a token is to transfer it to the zero address (`address(0)`). This address has no corresponding private key, meaning any assets sent there are permanently irrecoverable and inaccessible, thus effectively removing them from the circulating supply.
Question 20: A developer wants to set different royalty percentages for different tokens within the same ERC-721 collection (e.g., rare tokens have a higher royalty). How can this be achieved while complying with EIP-2981?
- By implementing logic within the `royaltyInfo` function that checks the `_tokenId` and calculates the `royaltyAmount` accordingly. (Correct answer)
- This is not possible, as EIP-2981 only allows for a single, contract-wide royalty percentage.
- By deploying a separate EIP-2981 extension contract for each royalty tier.
- By using the `setApprovalForAll` function to specify royalty information for each token.
Correct answer: By implementing logic within the `royaltyInfo` function that checks the `_tokenId` and calculates the `royaltyAmount` accordingly.
EIP-2981 is flexible. The `royaltyInfo` function receives the `_tokenId` as a parameter, allowing developers to implement custom logic. This can include looking up a specific royalty percentage for that token ID or applying different rules based on token traits, enabling per-token royalties within a single contract.
Question 21: When a marketplace enforces on-chain royalties via an operator filter registry, what does it restrict?
- The buyer's wallet balance
- The image resolution
- Transfers to marketplaces that do not honor creator royalties (Correct answer)
- The total number of NFTs minted
Correct answer: Transfers to marketplaces that do not honor creator royalties
Operator filter registries block approved operators (marketplaces) that bypass royalties, enforcing payment at the transfer level.
Question 22: In a typical NFT mint function, what is commonly enforced to prevent abuse?
- A fixed block number
- Mandatory KYC on-chain
- A maximum supply and per-wallet limit (Correct answer)
- A minimum gas price
Correct answer: A maximum supply and per-wallet limit
Mint functions usually cap total supply and limit how many tokens one wallet can mint.
Question 23: Which interface must a contract implement to be recognized for capability detection like ERC-721 support?
- ERC-1167
- ERC-20
- ERC-777
- ERC-165 (Correct answer)
Correct answer: ERC-165
ERC-165 defines supportsInterface, allowing contracts to advertise which interfaces they implement.
Question 24: In OpenZeppelin's ERC-721, what does _mint(to, tokenId) require about the tokenId?
- It must already exist
- It must be even
- It must not already be owned (Correct answer)
- It must be zero
Correct answer: It must not already be owned
_mint reverts if the tokenId already exists, preventing duplicate ownership.
Question 25: In a burn function, what check should occur before destroying a token?
- That the contract is paused
- That gas price is below a threshold
- That the caller is the owner or approved for the token (Correct answer)
- That the token price has increased
Correct answer: That the caller is the owner or approved for the token
Only the owner or an approved operator should be permitted to burn a token.
Question 26: When migrating a collection from ERC-721 to ERC-1155, what is a common challenge?
- ERC-1155 cannot hold metadata
- Royalties are impossible after migration
- Marketplace compatibility and mapping unique tokens to ID/amount semantics (Correct answer)
- No challenge; they are identical
Correct answer: Marketplace compatibility and mapping unique tokens to ID/amount semantics
Differing transfer/approval semantics and marketplace support require careful mapping during migration.
Question 27: What is the primary gas advantage of Merkle tree allowlists over storing all allowed addresses in an on-chain mapping?
- Mappings require more function calls to initialize
- Merkle trees compress addresses to 16 bytes each
- Merkle proofs are computed in fewer EVM opcodes
- Only the 32-byte root is stored on-chain, regardless of how many addresses are allowlisted (Correct answer)
Correct answer: Only the 32-byte root is stored on-chain, regardless of how many addresses are allowlisted
Storing a Merkle root costs one SSTORE (32 bytes), whereas an on-chain mapping requires one storage slot per address, making large allowlists orders of magnitude cheaper with Merkle trees.
Question 28: What is the benefit of writing automated tests for an NFT contract before deployment?
- Tests catch logic errors and vulnerabilities since deployed contracts are immutable (Correct answer)
- Tests mint the NFTs for free
- Tests automatically lower gas fees
- Tests reduce the contract's bytecode size
Correct answer: Tests catch logic errors and vulnerabilities since deployed contracts are immutable
Because deployed smart contracts are immutable, thorough tests catch bugs before they become permanent and costly.
Question 29: Which layer-2 network is commonly used to reduce NFT minting gas costs?
- Litecoin
- Dogecoin
- Polygon (Correct answer)
- Bitcoin
Correct answer: Polygon
Polygon offers low fees and is widely used for affordable NFT mints.
Question 30: Which hashing approach lets IPFS content addresses guarantee data integrity?
- Random UUIDs
- Sequential integer IDs
- Owner signatures
- Content-addressed CIDs derived from the file's hash (Correct answer)
Correct answer: Content-addressed CIDs derived from the file's hash
IPFS CIDs are derived from the content hash, so any change to the file changes the address.
Question 31: What does a 'gas griefing' finding in an NFT batch-transfer function describe?
- Overflow in token IDs
- An owner stealing funds
- A stale oracle
- An attacker forcing failures by consuming gas in a callback (Correct answer)
Correct answer: An attacker forcing failures by consuming gas in a callback
Gas griefing occurs when a malicious recipient's callback burns gas to cause the caller's transaction to fail.
Question 32: Why is updating the baseURI the typical reveal step rather than re-minting tokens?
- Re-minting is impossible after deployment
- It changes token ownership
- tokenURI derives from baseURI so changing it updates all metadata cheaply (Correct answer)
- It refunds the original gas
Correct answer: tokenURI derives from baseURI so changing it updates all metadata cheaply
Since tokenURI concatenates baseURI and tokenId, swapping the base reveals all tokens at once.
Question 33: Why is gas-efficient ERC721A used for large PFP collections?
- It enforces soulbound
- It removes royalties
- It optimizes batch minting to reduce per-token gas (Correct answer)
- It stores art on-chain
Correct answer: It optimizes batch minting to reduce per-token gas
ERC721A optimizes minting multiple tokens in one transaction, cutting gas costs for large mints.
Question 34: Which storage approach makes NFT image data most resistant to disappearing?
- Arweave permanent storage (Correct answer)
- Email attachment
- A single AWS bucket
- A personal web server
Correct answer: Arweave permanent storage
Arweave offers pay-once permanent storage, making hosted assets highly durable.
Question 35: A blockchain-based game developer needs to create multiple in-game assets. Some assets are unique, like a legendary sword (NFT), while others are stackable, like health potions (fungible tokens). Which token standard is most suitable for this scenario and why?
- ERC-1155, because it is exclusively designed for fungible tokens, which are more common in games.
- ERC-721, because it allows for more detailed metadata for each unique item.
- ERC-1155, because it supports both fungible and non-fungible tokens within a single smart contract. (Correct answer)
- ERC-721, because it is the most established standard for all types of game assets.
Correct answer: ERC-1155, because it supports both fungible and non-fungible tokens within a single smart contract.
ERC-1155 is the ideal choice because it is a multi-token standard. This allows a developer to create and manage different types of tokens—non-fungible (like the sword), fungible (like potions), and even semi-fungible—all within one contract, which is highly efficient for complex systems like games.
Question 36: What is fractionalization of an NFT?
- Splitting one NFT into many fungible ownership shares (Correct answer)
- Lowering royalties
- Minting in batches
- Adding metadata layers
Correct answer: Splitting one NFT into many fungible ownership shares
Fractionalization locks an NFT in a vault and issues fungible tokens representing partial ownership.
Question 37: After deploying a new ERC-721 contract, a developer notices that marketplaces are not displaying the collection's overall name, description, or logo, although individual NFTs and their traits appear correctly. Which of the following is the most likely missing feature in the contract?
- The ERC721Enumerable extension.
- An implementation of the EIP-2981 royalty standard.
- A `contractURI()` function that points to collection-level metadata. (Correct answer)
- A `tokenURI` function returning invalid JSON.
Correct answer: A `contractURI()` function that points to collection-level metadata.
Marketplaces like OpenSea use the `contractURI()` function to pull collection-level metadata, including the name, description, and image for the collection page. While a broken `tokenURI` would affect individual NFTs, the problem described is with the collection as a whole.
Question 38: In the ERC-721 metadata JSON, which field conventionally holds the displayed picture link?
- owner
- hash
- supply
- image (Correct answer)
Correct answer: image
The metadata standard uses an 'image' field containing a URL to the asset.
Question 39: What does ERC-721 tokenURI(tokenId) typically return?
- The owner's address
- The token's raw image bytes
- The contract bytecode
- A URI pointing to the token's JSON metadata (Correct answer)
Correct answer: A URI pointing to the token's JSON metadata
tokenURI returns a URI (often IPFS/HTTP) to a JSON file describing name, image, and attributes.
Question 40: A developer implements a public `mint()` function in an ERC-721 contract that increments a counter to assign a new `tokenId`. What is the primary purpose of adding a `require(totalSupply() < MAX_SUPPLY, "Max supply reached")` check at the beginning of this function?
- To reserve a specific range of token IDs for the project developers.
- To enforce a hard cap on the total number of NFTs that can ever be created for the collection. (Correct answer)
- To ensure the `tokenId` does not exceed the maximum value for a `uint256`.
- To prevent gas-intensive minting transactions when the collection is small.
Correct answer: To enforce a hard cap on the total number of NFTs that can ever be created for the collection.
This `require` statement is a crucial access control mechanism that enforces the scarcity and defined size of an NFT collection. By checking the current total supply against a predefined maximum supply, it prevents the creation of more tokens than were originally promised, which is a key factor in the collection's value proposition.
Question 41: When deploying an NFT contract, why verify the source on a block explorer?
- To enable minting
- To reduce gas
- To let users read and trust the contract code (Correct answer)
- To set royalties
Correct answer: To let users read and trust the contract code
Verification publishes the human-readable source, increasing transparency and collector confidence.
Question 42: If a tokenURI returns base64-encoded JSON inline (on-chain metadata), what must the frontend do before parsing it?
- Convert it to a private key
- Upload it to IPFS
- Send it to the contract
- Decode the base64 data URI to get the JSON string (Correct answer)
Correct answer: Decode the base64 data URI to get the JSON string
On-chain metadata is delivered as a data:application/json;base64 URI that must be decoded before JSON.parse.
Question 43: Why are NFT images and metadata often stored on IPFS rather than directly on-chain?
- Ethereum bans storing images
- IPFS encrypts all data automatically
- On-chain storage of large files is prohibitively expensive in gas (Correct answer)
- IPFS is faster than any database
Correct answer: On-chain storage of large files is prohibitively expensive in gas
Storing large media on-chain costs enormous gas, so decentralized off-chain storage like IPFS is used.
Question 44: In a marketplace order, what role does the 'salt' value typically play?
- It identifies the buyer's country
- It encrypts the NFT image
- It ensures order hash uniqueness to prevent collisions and replay of identical orders (Correct answer)
- It sets the sale price
Correct answer: It ensures order hash uniqueness to prevent collisions and replay of identical orders
A random salt makes otherwise-identical orders produce distinct hashes, preventing accidental collisions and signature reuse.
Question 45: What does the ERC-2981 standard add to NFT contracts?
- Royalty payment information (Correct answer)
- On-chain metadata storage
- Batch minting support
- Soulbound enforcement
Correct answer: Royalty payment information
ERC-2981 provides a standardized way to signal royalty amount and recipient for secondary sales.
Question 46: What problem does the ERC-721 Enumerable extension solve?
- Listing all tokens and tokens owned by an address on-chain (Correct answer)
- Royalty payments
- Gas-free transfers
- Metadata encryption
Correct answer: Listing all tokens and tokens owned by an address on-chain
ERC721Enumerable adds totalSupply and indexing so tokens can be enumerated on-chain.
Question 47: Why might a frontend cache fetched NFT metadata rather than re-requesting it on every render?
- It changes the tokenId
- Metadata is typically immutable on IPFS, so caching reduces gateway load and latency (Correct answer)
- It lowers gas fees
- Caching mints new tokens
Correct answer: Metadata is typically immutable on IPFS, so caching reduces gateway load and latency
Pinned IPFS metadata rarely changes, so caching avoids repeated slow gateway requests.
Question 48: What defines a soulbound token (SBT)?
- A fractionalized NFT
- A token with high royalties
- A token that auto-mints
- A non-transferable token bound to one address (Correct answer)
Correct answer: A non-transferable token bound to one address
Soulbound tokens are non-transferable, permanently tied to the holder's address.
Question 49: What does 'order cancellation' on-chain typically require from the seller?
- Emailing the marketplace
- Sending the NFT to a burn address
- A transaction that invalidates the order's nonce or hash, costing gas (Correct answer)
- Just deleting the listing from the website
Correct answer: A transaction that invalidates the order's nonce or hash, costing gas
On-chain cancellation submits a transaction marking the order hash/nonce as filled or cancelled so it can no longer be fulfilled.
Question 50: What does 'on-chain' NFT metadata mean?
- Metadata in the marketplace database
- Metadata stored on IPFS
- Metadata hosted on AWS
- Metadata and artwork encoded directly in the contract storage (Correct answer)
Correct answer: Metadata and artwork encoded directly in the contract storage
Fully on-chain NFTs store the SVG/JSON in the contract itself, removing external dependencies.
NFT Development Certification Exam
The NFT Development Certification Exam exam validates essential knowledge and skills required for certification or licensure in this field.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds