CBSA Practice Questions
Prepare for CBSA with more than an answer.
- Exam fee
- $275 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Blockchain Fundamentals and Architecture25%
- Consensus Mechanisms and Proof Systems20%
- Blockchain Types and Classifications20%
- Cryptography and Security20%
- Solution Architecture and Implementation15%
- 1
A blockchain solution is being developed to track ethical sourcing of diamonds, from mine to retailer. The solution requires a high degree of privacy, control over participants, and high transaction throughput. The participants (mining companies, certifiers, distributors) are known and trusted entities. Which type of blockchain architecture is most suitable for this use case?
Show answer details
Correct answer: B
A private/permissioned blockchain is the best fit. The requirements for privacy, participant control (only known entities can join), and high throughput are characteristic of enterprise use cases that are not suitable for a public blockchain. Platforms like Hyperledger Fabric or R3 Corda are designed for such consortium models.
- 2
A solution architect must design a system that allows for private transactions on a public, Ethereum-based blockchain. The goal is to obscure the sender, receiver, and amount for specific transactions to protect user privacy. Which technology would be most appropriate to integrate into the solution to achieve this?
Show answer details
Correct answer: C
Protocols like Tornado Cash use Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge (zk-SNARKs) to enable private transactions on public blockchains. A user deposits funds into a smart contract and can later withdraw them to a different address without creating a link between the deposit and withdrawal on-chain. The zk-SNARK proves that the user has the right to withdraw funds without revealing which deposit corresponds to the withdrawal, effectively breaking the transaction graph and providing privacy.
- 3
Which of the following statements accurately describes the concept of 'finality' in the context of blockchain consensus? (Select TWO)
Show answer details
Correct answer: B, C
This is a correct definition of probabilistic finality. The transaction is considered 'final' after a certain number of confirmations (e.g., 6 for Bitcoin), but there is always a non-zero, though exponentially decreasing, probability of a chain reorganization that could reverse it.
This is a correct definition of absolute or deterministic finality. In systems like pBFT, once a supermajority of validators agrees on a block, it is considered final and cannot be reverted, short of a catastrophic failure of the consensus assumptions.
- 4
True or False: A 51% attack is only a theoretical threat to Proof of Work blockchains and has never been successfully executed against a major public cryptocurrency.
Show answer details
Correct answer: B
This statement is false. While difficult and expensive to execute against large networks like Bitcoin, 51% attacks are a very real threat and have been successfully carried out against several smaller but significant Proof of Work blockchains, including Ethereum Classic (ETC), Bitcoin Gold (BTG), and Verge (XVG). These attacks allowed the perpetrators to double-spend coins and reorganize parts of the chain.
- 5
A solutions architect needs to design a high-performance blockchain for a gaming application. The key requirements are sub-second transaction finality and the ability to process thousands of transactions per second. The architect is considering a non-traditional blockchain structure. Which of the following consensus mechanisms uses a Directed Acyclic Graph (DAG) structure to allow for parallel transaction processing, thus achieving high throughput and low latency?
Show answer details
Correct answer: B
Hashgraph, used by Hedera, is a consensus algorithm that utilizes a Directed Acyclic Graph (DAG) structure. Unlike traditional blockchains that have a single chain of blocks, DAGs allow transactions to be added in parallel, referencing multiple previous transactions. This structure, combined with a gossip protocol and virtual voting, enables extremely high throughput and fast finality, making it suitable for high-performance applications like gaming.
- 6
A team is building a decentralized autonomous organization (DAO) on Ethereum. They need to create a smart contract that allows token holders to vote on proposals. A critical security requirement is to prevent 'flash loan' attacks, where an attacker borrows a large number of tokens, votes on a proposal, and then repays the loan all within the same transaction. What architectural pattern should be implemented in the voting contract to mitigate this risk?
Show answer details
Correct answer: C
The most effective and standard pattern to prevent flash loan governance attacks is to take a snapshot of token balances at a specific block height, typically the block when the proposal was created. Voting power is then determined by the balance at that past block, not the current block. Since a flash loan is borrowed and returned within a single transaction (and thus a single block), the attacker's balance at the snapshot block would be their original, pre-loan amount, rendering the attack ineffective.
- 7
What is the primary function of a Merkle Tree in a Bitcoin block?
Show answer details
Correct answer: C
A Merkle Tree is a data structure that efficiently summarizes and verifies the integrity of large sets of data. In a Bitcoin block, all transaction hashes are repeatedly hashed together until a single hash, the Merkle Root, remains. This root is included in the block header. This allows for quick verification that a specific transaction is part of a block without downloading the entire block, a feature used by Simplified Payment Verification (SPV) clients.
- 8
A financial consortium is designing a permissioned blockchain for interbank settlements. They are evaluating consensus mechanisms. The primary requirements are high transaction finality, low latency, and the ability to function correctly even if up to one-third of the validator nodes are malicious or offline. Which consensus algorithm is specifically designed to meet these requirements?
Show answer details
Correct answer: C
Practical Byzantine Fault Tolerance (pBFT) is the ideal choice for this scenario. It is designed for permissioned networks, provides immediate transaction finality, offers low latency, and is resilient to f = (n-1)/3 faulty nodes, which matches the requirement of tolerating up to one-third malicious or offline nodes. PoW has probabilistic finality and high latency. PoS is generally for public networks and also has probabilistic finality in many implementations. RAFT is not Byzantine fault-tolerant and cannot handle malicious actors.
- 9
A supply chain solution is being built on Hyperledger Fabric. To comply with GDPR, personally identifiable information (PII) related to European customers must only be accessible to the European members of the consortium. However, the hash of this PII data needs to be written to the main channel's ledger for auditability by all members. Which Hyperledger Fabric feature should be used to achieve this?
Show answer details
Correct answer: B
Private Data Collections (PDCs) are specifically designed for this use case. They allow a subset of organizations on a channel to endorse, commit, and query private data without having to create a separate channel. The actual private data is stored peer-to-peer in a separate state database, while a hash of the data is written to the channel's public ledger, providing the required auditability for all members without exposing the sensitive PII.
- 10
A startup is creating a decentralized application (dApp) for digital art provenance on a public blockchain. To prevent users from having to pay high gas fees for every metadata update, the architect proposes an off-chain storage solution. Which of the following combinations provides a decentralized, content-addressed storage solution for the digital art files and their metadata, while keeping an immutable link on-chain? (Select TWO)
Show answer details
Correct answer: B, C
IPFS provides content-addressed, decentralized storage. Files are identified by a unique hash (CID), which can be stored on-chain efficiently.
This is the correct pattern. The large file is stored off-chain in a decentralized system like IPFS, and the small, immutable CID is stored on-chain as a verifiable link to the data.
