CCAS Sample Questions

CCAS Sample Questions & Answers

AML foundations for crypto-related financial crime and building risk management programs tie for the largest share, with the remainder on blockchain fundamentals, virtual asset service providers, wallets and how blockchain transactions actually work.

Launch the full CCAS simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Cryptoassets and Blockchain · Types of Cryptoassets and VASPs

    A financial institution is assessing the risk of onboarding a client who operates a crypto ATM network. Unlike online exchanges, crypto ATMs (or BTMs) present unique AML challenges. Which of the following is considered the primary inherent risk factor specific to crypto ATMs?

    Show answer & explanation

    Correct answer: D

    The primary risk with crypto ATMs is the interface between physical cash and crypto. Smurfs often use them to deposit illicit cash into the crypto ecosystem. The lack of human interaction and the cash-intensive nature make them high risk for placement.

  2. Question 2Advanced

    Cryptoassets and Blockchain · Mining and coin generation

    A compliance officer is investigating a customer who claims their source of wealth is 'early mining.' The customer provides a list of addresses they claim to own. The officer notices that the funds in these addresses originate from 'Coinbase' transactions rather than coinbase (mining reward) transactions. What is the technical distinction the officer must understand?

    Show answer & explanation

    Correct answer: B

    In technical blockchain terms, the 'coinbase transaction' is the special transaction that rewards the miner with new coins. This is distinct from the company 'Coinbase'. If the funds came from the exchange Coinbase, the user was trading/buying, not mining.

  3. Question 3IntermediateSelect 2

    Cryptoassets and Blockchain · Types of Cryptoassets and VASPs

    Select TWO characteristics that accurately describe 'Privacy Coins' such as Monero (XMR) or Zcash (ZEC) in contrast to transparent blockchains like Bitcoin. (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    Stealth addresses allow a sender to generate a one-time address for the recipient, ensuring the recipient's actual address doesn't appear in the public transaction history.

    Privacy coins utilize advanced cryptography (Ring Signatures for Monero, Zero-Knowledge Proofs/zk-SNARKs for Zcash) to hide transaction details on the ledger.

  4. Question 4Intermediate

    Cryptoassets and Blockchain · Transactions, Wallets, and Blockchain Mechanics

    True or False: A non-custodial wallet provider that does not host wallet software but merely sells hardware devices (cold storage) is generally classified as a VASP under FATF guidance because they facilitate the storage of assets.

    Show answer & explanation

    Correct answer: B

    False. According to FATF guidance, hardware wallet manufacturers and non-custodial software providers that do not hold private keys or conduct transactions on behalf of customers are typically NOT considered VASPs. They provide technology, not financial services.

  5. Question 5Intermediate

    Cryptoassets and Blockchain · Blockchain Analytics, Tracing, and Attribution

    A blockchain investigator is attempting to de-anonymize a cluster of addresses. They identify a transaction where multiple inputs from different addresses are combined to fund a single output. What does this 'Common Input Ownership' heuristic suggest?

    Show answer & explanation

    Correct answer: C

    The Common Input Ownership heuristic (or co-spend) assumes that if multiple addresses sign inputs to the same transaction, the private keys for those addresses are controlled by the same wallet/entity, allowing analysts to cluster them together.

  6. Question 6Intermediate

    Cryptoassets and Blockchain · Mining and coin generation

    Which component of a blockchain block header is specifically manipulated by miners in a Proof of Work system to produce a hash lower than the target difficulty?

    Show answer & explanation

    Correct answer: A

    The Nonce (Number used ONCE) is the 32-bit field in the block header that miners increment/change repeatedly to alter the block hash until it meets the difficulty target.

Ready for the real thing?

The full CCAS simulator has every exam-style question, timed mode, and instant scoring.

Go to the CCAS simulator →