- What the CodeHS Cybersecurity Level 1 Certification Actually Is
- Exam Format, Timing, and Passing Score
- The Six Content Areas at a Glance
- Concepts That Trip Candidates Up
- Vouchers, Attempts, and Credential Lifespan
- Who Benefits From This Credential
- A Domain-Ordered Preparation Plan
- Frequently Asked Questions
- CHS-CY1 is the CodeHS Cybersecurity Level 1 certification: 45 multiple-choice questions in an online timed exam.
- CodeHS's FAQ lists a 90-minute time limit and a 60% passing score for this exam.
- Six topic areas are tested, from Cybersecurity Essentials through Digital Safety and Data Security, with no published weights.
- No prerequisites exist, but CodeHS recommends its Fundamentals of Cybersecurity course for preparation.
What the CodeHS Cybersecurity Level 1 Certification Actually Is
CHS-CY1 is the exam code for the CodeHS Cybersecurity Level 1 Certification, an entry-level credential issued by CodeHS. It is built around foundational cybersecurity and IT literacy rather than advanced penetration testing or enterprise security engineering. If you are searching for a vendor-neutral industry credential from another certifying body, this is not that exam. It is a CodeHS certification, and everything in this article applies to that specific exam only.
The certification is designed for learners who are early in their cybersecurity journey, most commonly students working through a high school or introductory course. That positioning shapes the exam: questions test whether you understand core concepts, vocabulary, and basic reasoning about threats and systems, not whether you can configure enterprise firewalls. For a deeper definition of the credential and its name, see our explainers on what CHS-CY1 certification is and what CHS-CY1 stands for.
Exam Format, Timing, and Passing Score
The exam is straightforward in structure, which is good news for candidates who want to plan their preparation carefully. Here is what CodeHS publishes about the format:
| Exam Detail | What CodeHS States |
|---|---|
| Issuer | CodeHS |
| Question count | 45 questions |
| Question type | Multiple choice |
| Delivery | Online, timed exam |
| Time limit | 90 minutes (per the CodeHS Certifications FAQ) |
| Passing score | 60% (the FAQ lists 60% for all certification exams except Java) |
| Prerequisites | None |
| Credential validity | Expires after 10 years |
Two practical observations follow from these numbers. First, 90 minutes for 45 questions averages two minutes per question, which is generous for a multiple-choice format. Time pressure is rarely the main obstacle; shaky recall of terminology is. Second, because the passing mark is 60%, you can miss a meaningful number of questions and still pass. That does not mean you should leave whole domains unstudied, since topic coverage across six areas means weak spots can accumulate quickly. Our CHS-CY1 passing score guide walks through what the threshold means in practice.
The Six Content Areas at a Glance
CodeHS lists six topic headings under "Topics & Concepts Covered." Percentage weights are not published, so you should not assume any one area dominates. Treat all six as fair game and prepare evenly, then adjust based on practice results. For a longer walkthrough of each area, read our complete guide to the six CHS-CY1 content areas.
Domain 1: Cybersecurity Essentials
The conceptual foundation of the exam, covering the threats and ethical frameworks that frame the rest of the course.
- Ransomware and phishing as common attack types
- Internet of Things security considerations
- The CIA Triad (confidentiality, integrity, availability)
- Cyber ethics, credit and copyright
- Legal versus illegal hacking
Domain 2: Cryptography
Classical encryption and the ways it gets broken. This is the most hands-on, puzzle-like area.
- Basic cryptography concepts
- Code breaking, brute force, and frequency analysis
- Caesar cipher and Vigenere cipher mechanics
Domain 3: System Administration
How computers, software, and users are managed day to day.
- Operating systems and software licenses
- Application security and browsers
- System administration responsibilities
- Command line systems
Domain 4: IT Concepts
How data finds its way across the internet.
- Internet addresses, IPv4 and IPv6
- DNS hierarchy
- Routing
- Packets and protocols
Domain 5: IT Infrastructure
The physical and logical pieces that make up computers and networks.
- Internal components and peripheral devices
- Network devices and storage options
- Network options, communication, and management
Domain 6: Digital Safety and Data Security
Personal safety online plus an introduction to how web data is stored and attacked.
- Digital footprint, cyberbullying, and internet safety
- Clients and servers
- SQL queries and SQL injection
- Developer tools
Concepts That Trip Candidates Up
Because the exam is multiple choice, most mistakes come from confusing similar-sounding ideas rather than from not knowing anything. A few CHS-CY1-specific pairs deserve extra attention.
Caesar vs. Vigenere, and How Each Is Broken
The Caesar cipher shifts every letter by the same fixed amount, which makes it vulnerable to both brute force (there are only a small number of possible shifts) and frequency analysis. The Vigenere cipher uses a keyword to apply different shifts across the message, which flattens the letter-frequency pattern that makes simple substitution easy to crack. Expect questions that ask you to recognize which cipher is being described, or which attack technique fits a given scenario. Know the difference between trying every possible key (brute force) and studying how often letters appear (frequency analysis).
The CIA Triad in Scenario Form
Rather than asking you to recite the three words, questions often describe an incident and ask which principle was violated. Data altered without permission points to integrity. A service knocked offline points to availability. Private information exposed points to confidentiality. Practice mapping short scenarios to the correct principle until it becomes automatic.
SQL Queries and SQL Injection
This pairing sits in the final domain and rewards basic literacy. You should be comfortable reading a simple query and understanding what it retrieves, and you should understand conceptually how SQL injection works: attacker-supplied input being treated as part of a database command. Know why validating and sanitizing input is the standard defense, even if you never write advanced queries.
IPv4, IPv6, and DNS
Know that IPv6 exists largely because IPv4 address space is limited, and understand DNS as the system that translates human-readable names into IP addresses through a hierarchy. Routing and packets round out this domain: data is broken into packets, which are forwarded between networks according to protocols. Questions tend to be definitional or lightly scenario-based.
Vouchers, Attempts, and Credential Lifespan
CodeHS handles exam access through vouchers. The key mechanics from the official sources are simple: each exam attempt requires a new voucher, there are no prerequisites to sit the exam, and the resulting credential expires after 10 years. CodeHS recommends, but does not require, its Fundamentals of Cybersecurity course as preparation.
Specific fee amounts and pass-rate statistics are not published in the sources we rely on, so we do not quote them here. If cost is a deciding factor, check the official CodeHS certification page directly and see our breakdown in the CHS-CY1 certification cost guide. For eligibility details and how to qualify, read CHS-CY1 requirements, and for scheduling questions consult CHS-CY1 exam dates.
Key Takeaway
Because every attempt needs a fresh voucher, treat your first sitting as the real thing. Finish a full timed practice run on our CHS-CY1 practice tests before redeeming a voucher, so you are not paying for a retake caused by a preventable gap.
Who Benefits From This Credential
CHS-CY1 is best understood as a foundational credential. It suits students in introductory cybersecurity courses, early-career learners exploring whether security is a good fit, and educators who want a structured way to validate student learning. It signals familiarity with core concepts, ethics, and basic IT literacy rather than job-ready technical specialization.
That framing matters if you are weighing career value. A Level 1 credential can strengthen a portfolio, support college or program applications, and give you a verifiable starting point, but it is not a substitute for hands-on experience or advanced certifications. If you want to explore the career side honestly, our articles on CHS-CY1 jobs, the CHS-CY1 salary guide, and whether the certification is worth it lay out realistic expectations without inflated promises.
A Domain-Ordered Preparation Plan
Since weights are unpublished, an even spread across the six areas is the safest approach. The ordering below puts conceptual groundwork first, because later domains build on the vocabulary you learn early. Adjust the pace to your schedule; the sequence is what matters.
Cybersecurity Essentials
- Memorize the CIA Triad and practice scenario mapping
- Distinguish ransomware, phishing, and IoT risks
- Review cyber ethics and legal versus illegal hacking
Cryptography
- Encrypt and decrypt by hand with Caesar and Vigenere
- Work through brute force and frequency analysis examples
System Administration and IT Concepts
- Review operating systems, licenses, browsers, and basic command line
- Learn IPv4, IPv6, DNS hierarchy, routing, and packets
Infrastructure, Digital Safety, and Full Practice
- Cover hardware, storage, and network devices
- Study digital footprint, SQL injection, and developer tools
- Finish with timed full-length practice and review every miss
For a fuller methodology, our CHS-CY1 study guide expands on how to structure review, and the CHS-CY1 cheat sheet gives you a compact refresher for the final days. If you are unsure how demanding the exam will feel, how hard the CHS-CY1 exam is offers a candid look at difficulty.
When you reach the final week, take timed practice sets that mirror the real format: 45 multiple-choice questions against a 90-minute clock. Review every missed question by domain, and revisit the area where your misses cluster. You can start with the free questions on our practice test site to find your weakest domain early.
Frequently Asked Questions
The CodeHS Cybersecurity Level 1 exam has 45 multiple-choice questions, delivered as an online timed exam.
The CodeHS Certifications FAQ states a 90-minute time limit and a 60% passing score for all certification exams except Java, which includes this one.
No. CodeHS lists no prerequisites. It does recommend the Fundamentals of Cybersecurity course as preparation, which aligns closely with the exam topics.
Each exam attempt requires a new voucher, so a retake means obtaining another one. Use full practice exams beforehand to reduce the chance of needing a second attempt.
CodeHS states that certification credentials expire after 10 years from earning them.