CBDE Practice Questions
Prepare for CBDE with more than an answer.
- Exam fee
- $275 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Ethereum Fundamentals and Architecture20%
- Solidity Programming35%
- Smart Contract Security20%
- Development Tools and Testing15%
- Web3 and DApp Development10%
- 1
True or False: A smart contract can prevent a specific Externally Owned Account (EOA) from ever interacting with it by adding the EOA's address to a blacklist mapping and checking it with a
requirestatement in every public and external function.Show answer details
Correct answer: B
False. While this method can prevent direct calls from the blacklisted EOA, it cannot prevent indirect interaction. The blacklisted user can simply deploy a new, intermediate smart contract (a 'proxy' or 'wrapper' contract) and use it to call the target contract. From the target contract's perspective,
msg.senderwill be the address of the intermediate contract, not the blacklisted EOA, thus bypassing the check. More robust access control might involve checkingtx.origin, but that has its own security implications (e.g., phishing attacks). - 2
In Solidity, what is the primary security risk associated with using
tx.originfor authorization checks in a smart contract?Show answer details
Correct answer: C
The
tx.originglobal variable always refers to the original EOA that initiated the entire transaction chain. If a contract usesrequire(tx.origin == owner)for an authorization check, it can be exploited. An attacker can create a malicious contract (e.g., a fake NFT minting contract) and trick the legitimate owner into calling it. The malicious contract would then call the target contract's critical function. Because the owner initiated the transaction,tx.originwould be the owner's address, and the check would pass, allowing the malicious contract to act on the owner's behalf. For this reason,msg.sendershould almost always be used for authorization. - 3
A developer is writing a function to transfer ownership of an ERC721 token. The function must ensure that the recipient is capable of receiving NFTs to prevent tokens from being locked forever. Which standard should the recipient contract implement to signal this capability?
Show answer details
Correct answer: D
The ERC721 standard specifies a receiver hook mechanism to prevent tokens from being accidentally sent to contracts that don't know how to handle them. When using
safeTransferFrom, the sending contract checks if the recipient is a contract. If it is, it calls theonERC721Receivedfunction on the recipient contract. The recipient must implement theIERC721Receiverinterface and return a specific magic value (bytes4(keccak256("onERC721Received(address,address,uint256,bytes)"))) to acknowledge the receipt. If it doesn't, the transfer is reverted. - 4
What is the role of a 'Provider' in a Web3 library like Web3.js or Ethers.js?
Show answer details
Correct answer: B
A Provider is an abstraction for a connection to the Ethereum network. It allows a dApp to make read-only requests (like getting a balance or calling a
viewfunction) and send raw transactions via the JSON-RPC protocol to an Ethereum node (e.g., one hosted by Infura, Alchemy, or a local node like Ganache). It does not handle private keys or transaction signing; that is the role of a 'Signer'. - 5
The diagram below shows the UUPS proxy pattern. Based on this pattern, which statement is correct?
graph TD User -->|Transaction| Proxy subgraph Contract Logic Proxy -->|delegatecall| Implementation_V1 Implementation_V1 -- contains --> UpgradeLogic[upgradeTo(...)] end Implementation_V1 |storage| ProxyState[Proxy Contract State] subgraph Upgrade Process Admin -->|Calls upgradeTo| Implementation_V1 Implementation_V1 -->|Updates Proxy| Proxy Proxy -->|delegatecall| Implementation_V2 endShow answer details
Correct answer: C
The diagram correctly illustrates the UUPS pattern. The user interacts with the Proxy, which uses
delegatecallto run code from an Implementation contract while using the Proxy's own storage (state). The critical feature of UUPS is that theupgradeTo(...)logic resides within the implementation contract itself. An authorized admin calls this function on the implementation (through the proxy), and this function then updates a storage slot in the Proxy to point to the new implementation address (Implementation_V2). The Proxy's state is preserved across upgrades. - 6
A financial institution is developing a smart contract to issue bonds on Ethereum. A key requirement is that the total supply of bonds must be strictly capped and can never be changed after deployment. Which of the following Solidity code patterns most effectively and securely enforces this immutable cap?
Show answer details
Correct answer: D
Using the
immutablekeyword is the optimal solution. An immutable variable can be assigned a value only once, either at the point of declaration or within the constructor. This ensures the value is set at deployment time and cannot be altered thereafter. It is also more gas-efficient than a standard state variable because its value is directly embedded into the contract's bytecode. Aconstantvariable must be known at compile time, which might not be suitable if the supply is determined by a constructor parameter. A standard public or private state variable could be accidentally modified by another function if not properly protected. - 7
A developer is building a decentralized autonomous organization (DAO) where voting power is determined by the amount of a specific ERC20 token a user held at the time a proposal was created. To prevent users from buying tokens after a proposal is made to influence the vote, which technique should be implemented?
Show answer details
Correct answer: B
The correct approach is to implement a snapshot mechanism. When a proposal is created, the current block number is recorded. The ERC20 token contract should be designed to allow querying a user's balance at a past block number. This prevents users from acquiring tokens after a proposal is live to gain voting power for that specific proposal. OpenZeppelin's ERC20Votes extension is a standard implementation of this pattern. Simply checking the current balance at vote time is vulnerable to this exact exploit.
- 8
A developer is writing a smart contract that interacts with multiple other contracts. One of the external contracts is untrusted and known to be potentially malicious. To prevent reentrancy attacks, which of the following design patterns and security measures are most critical to implement? (Select TWO)
Show answer details
Correct answer: A, B
The Checks-Effects-Interactions pattern is a fundamental principle for preventing reentrancy. It dictates that you should perform all internal state checks and updates (Checks, Effects) before making any external calls (Interactions). Using
transfer()(orsend()) for sending Ether is another key mitigation because it forwards a fixed, small amount of gas (2300), which is not enough for the receiving contract to make a reentrant call back. Usingcall()with a large gas stipend is what enables reentrancy. Increasing gas price and using low-level calls do not prevent reentrancy. - 9
True or False: Using
msg.senderwithin a function called viadelegatecallwill refer to the address of the contract that initiated thedelegatecall, not the original transaction signer.Show answer details
Correct answer: B
False. The
delegatecallopcode is unique because it executes the code of another contract but preserves the context of the calling contract. This means thatmsg.senderandmsg.valueremain those of the original caller of the function that initiated thedelegatecall. This behavior is fundamental to implementing proxy patterns for upgradeable smart contracts. - 10
A development team is deploying a complex smart contract system using Hardhat. They need to deploy several contracts, link libraries, and initialize state in a specific, repeatable sequence on both the local testnet and the Sepolia testnet. What is the most appropriate Hardhat feature to automate this process?
Show answer details
Correct answer: B
Hardhat's scripting capabilities, located in the
scripts/directory, are designed for this exact purpose. Developers can write JavaScript or TypeScript files that use the Ethers.js or Web3.js plugins to define a precise, repeatable sequence of deployments and contract interactions. These scripts can be run against any configured network (likelocalhostorsepolia) using thehardhat run --networkcommand, ensuring consistency and automation. The other options are either manual, not designed for deployment, or part of a different framework.
