# Revision and Interview Questions — Blockchain & Smart Contracts (Solidity)

Source: https://www.geekswithgeeks.com/en/solidity/g-revision

> Recall blockchain and Solidity concepts quickly for exams and interviews.

## Cheat sheet

**Blockchain**: hash-linked blocks, nodes, consensus, proof of stake since The Merge (2022), trade-offs. **Ethereum**: EOAs vs contract accounts, addresses, wei/gwei/ether, nonces, the EVM, gas, EIP-1559 base fee (burned) plus tip, gas limit, L2 rollups (optimistic vs ZK), testnets (Sepolia). **Keys**: private key, seed phrase, signatures, ECDSA recover, EIP-712, multisigs, account abstraction. **Solidity**: SPDX, pragma, state variables, constructor, visibility (public, external, internal, private is not secret), `msg.sender`, `msg.value`, `block.timestamp`, view/pure/payable, modifiers and `_;`, events and indexed parameters, `require`, custom errors, `revert`, `assert`, try/catch. **Types**: uintN, address, bytes32, no floats, mappings, structs, enums, checked arithmetic since 0.8, `unchecked`, constant and immutable. **Locations**: storage, memory, calldata, transient storage. **Reuse**: inheritance, virtual/override, interfaces, abstract contracts, libraries, OpenZeppelin, Ownable2Step, AccessControl. **Tokens**: ERC-20 (approve/transferFrom, decimals, SafeERC20, permit), ERC-721 (safeTransferFrom, tokenURI), ERC-1155, Merkle allowlists. **Ether**: receive/fallback, call with checked result, pull payments. **Calls**: delegatecall, proxies (UUPS, transparent), initializers, storage layout. **Security**: reentrancy and CEI, ReentrancyGuard, tx.origin, MEV, oracle manipulation, replay, rounding, DoS, Slither, fuzz and invariant tests, audits, bounties. **Tooling**: Foundry (forge, cast, anvil, cheatcodes), Hardhat, viem, ethers, wagmi. **Gas**: storage dominates, packing, caching, events. **DeFi**: AMMs, slippage, lending, stablecoins, ERC-4626, flash loans.

## Common interview questions

Answer each with a short code example or diagram.

```text
1. What is the difference between an EOA and a contract account?
2. How are transaction fees calculated after EIP-1559?
3. storage vs memory vs calldata: when do you use each?
4. What is reentrancy and how do you prevent it?
5. Why should you not use tx.origin for authorisation?
6. Explain ERC-20 approve and transferFrom, and the risks of unlimited approvals.
7. How does a proxy upgrade work, and what is a storage collision?
8. What is the difference between call, delegatecall and staticcall?
9. Why is on-chain randomness hard, and how do you get secure randomness?
10. How would you prevent signature replay?
11. Name three gas optimisations and their trade-offs.
12. How would you test and secure a contract before mainnet deployment?
```

## Show your security thinking

In smart contract interviews, explaining how a function could be attacked and how you would test against it (fuzzing, invariants, CEI, access control) often matters more than syntax.

**Quiz:** Which pattern is the primary defence against reentrancy?

- [ ] Using tx.origin
- [ ] Using transfer instead of call everywhere
- [ ] Making all functions public
- [x] Checks-effects-interactions: update state before making external calls

*Answer:* Checks-effects-interactions: update state before making external calls. CEI ensures re-entrant calls see updated state; ReentrancyGuard adds a safety net.
