CHS-CY1 logo
Focused certification exam prep
Start practice

CHS-CY1 Certification

TL;DR
  • CHS-CY1 is the CodeHS Cybersecurity Level 1 certification: 45 multiple-choice questions in an online timed exam.
  • CodeHS's FAQ lists a 90-minute time limit and a 60% passing score for this exam.
  • Six topic areas are tested, from Cybersecurity Essentials through Digital Safety and Data Security, with no published weights.
  • No prerequisites exist, but CodeHS recommends its Fundamentals of Cybersecurity course for preparation.

What the CodeHS Cybersecurity Level 1 Certification Actually Is

CHS-CY1 is the exam code for the CodeHS Cybersecurity Level 1 Certification, an entry-level credential issued by CodeHS. It is built around foundational cybersecurity and IT literacy rather than advanced penetration testing or enterprise security engineering. If you are searching for a vendor-neutral industry credential from another certifying body, this is not that exam. It is a CodeHS certification, and everything in this article applies to that specific exam only.

The certification is designed for learners who are early in their cybersecurity journey, most commonly students working through a high school or introductory course. That positioning shapes the exam: questions test whether you understand core concepts, vocabulary, and basic reasoning about threats and systems, not whether you can configure enterprise firewalls. For a deeper definition of the credential and its name, see our explainers on what CHS-CY1 certification is and what CHS-CY1 stands for.

Scope reminder: This credential covers Cybersecurity Level 1 only. Content from Cybersecurity Level 2 is not part of this exam, so you should not spend prep time on topics outside the six Level 1 areas listed below.

Exam Format, Timing, and Passing Score

The exam is straightforward in structure, which is good news for candidates who want to plan their preparation carefully. Here is what CodeHS publishes about the format:

Exam DetailWhat CodeHS States
IssuerCodeHS
Question count45 questions
Question typeMultiple choice
DeliveryOnline, timed exam
Time limit90 minutes (per the CodeHS Certifications FAQ)
Passing score60% (the FAQ lists 60% for all certification exams except Java)
PrerequisitesNone
Credential validityExpires after 10 years

Two practical observations follow from these numbers. First, 90 minutes for 45 questions averages two minutes per question, which is generous for a multiple-choice format. Time pressure is rarely the main obstacle; shaky recall of terminology is. Second, because the passing mark is 60%, you can miss a meaningful number of questions and still pass. That does not mean you should leave whole domains unstudied, since topic coverage across six areas means weak spots can accumulate quickly. Our CHS-CY1 passing score guide walks through what the threshold means in practice.

The Six Content Areas at a Glance

CodeHS lists six topic headings under "Topics & Concepts Covered." Percentage weights are not published, so you should not assume any one area dominates. Treat all six as fair game and prepare evenly, then adjust based on practice results. For a longer walkthrough of each area, read our complete guide to the six CHS-CY1 content areas.

Domain 1: Cybersecurity Essentials

The conceptual foundation of the exam, covering the threats and ethical frameworks that frame the rest of the course.

  • Ransomware and phishing as common attack types
  • Internet of Things security considerations
  • The CIA Triad (confidentiality, integrity, availability)
  • Cyber ethics, credit and copyright
  • Legal versus illegal hacking

Domain 2: Cryptography

Classical encryption and the ways it gets broken. This is the most hands-on, puzzle-like area.

  • Basic cryptography concepts
  • Code breaking, brute force, and frequency analysis
  • Caesar cipher and Vigenere cipher mechanics

Domain 3: System Administration

How computers, software, and users are managed day to day.

  • Operating systems and software licenses
  • Application security and browsers
  • System administration responsibilities
  • Command line systems

Domain 4: IT Concepts

How data finds its way across the internet.

  • Internet addresses, IPv4 and IPv6
  • DNS hierarchy
  • Routing
  • Packets and protocols

Domain 5: IT Infrastructure

The physical and logical pieces that make up computers and networks.

  • Internal components and peripheral devices
  • Network devices and storage options
  • Network options, communication, and management

Domain 6: Digital Safety and Data Security

Personal safety online plus an introduction to how web data is stored and attacked.

  • Digital footprint, cyberbullying, and internet safety
  • Clients and servers
  • SQL queries and SQL injection
  • Developer tools

Concepts That Trip Candidates Up

Because the exam is multiple choice, most mistakes come from confusing similar-sounding ideas rather than from not knowing anything. A few CHS-CY1-specific pairs deserve extra attention.

Caesar vs. Vigenere, and How Each Is Broken

The Caesar cipher shifts every letter by the same fixed amount, which makes it vulnerable to both brute force (there are only a small number of possible shifts) and frequency analysis. The Vigenere cipher uses a keyword to apply different shifts across the message, which flattens the letter-frequency pattern that makes simple substitution easy to crack. Expect questions that ask you to recognize which cipher is being described, or which attack technique fits a given scenario. Know the difference between trying every possible key (brute force) and studying how often letters appear (frequency analysis).

The CIA Triad in Scenario Form

Rather than asking you to recite the three words, questions often describe an incident and ask which principle was violated. Data altered without permission points to integrity. A service knocked offline points to availability. Private information exposed points to confidentiality. Practice mapping short scenarios to the correct principle until it becomes automatic.

Phishing vs. ransomware: Phishing is a deception technique, usually delivered through messages that trick someone into revealing information or clicking something harmful. Ransomware is malware that locks or encrypts data and demands payment. They often appear together in an attack chain, but they are distinct concepts, and exam questions may test whether you can tell the delivery method from the payload.

SQL Queries and SQL Injection

This pairing sits in the final domain and rewards basic literacy. You should be comfortable reading a simple query and understanding what it retrieves, and you should understand conceptually how SQL injection works: attacker-supplied input being treated as part of a database command. Know why validating and sanitizing input is the standard defense, even if you never write advanced queries.

IPv4, IPv6, and DNS

Know that IPv6 exists largely because IPv4 address space is limited, and understand DNS as the system that translates human-readable names into IP addresses through a hierarchy. Routing and packets round out this domain: data is broken into packets, which are forwarded between networks according to protocols. Questions tend to be definitional or lightly scenario-based.

Vouchers, Attempts, and Credential Lifespan

CodeHS handles exam access through vouchers. The key mechanics from the official sources are simple: each exam attempt requires a new voucher, there are no prerequisites to sit the exam, and the resulting credential expires after 10 years. CodeHS recommends, but does not require, its Fundamentals of Cybersecurity course as preparation.

Specific fee amounts and pass-rate statistics are not published in the sources we rely on, so we do not quote them here. If cost is a deciding factor, check the official CodeHS certification page directly and see our breakdown in the CHS-CY1 certification cost guide. For eligibility details and how to qualify, read CHS-CY1 requirements, and for scheduling questions consult CHS-CY1 exam dates.

Key Takeaway

Because every attempt needs a fresh voucher, treat your first sitting as the real thing. Finish a full timed practice run on our CHS-CY1 practice tests before redeeming a voucher, so you are not paying for a retake caused by a preventable gap.

Who Benefits From This Credential

CHS-CY1 is best understood as a foundational credential. It suits students in introductory cybersecurity courses, early-career learners exploring whether security is a good fit, and educators who want a structured way to validate student learning. It signals familiarity with core concepts, ethics, and basic IT literacy rather than job-ready technical specialization.

That framing matters if you are weighing career value. A Level 1 credential can strengthen a portfolio, support college or program applications, and give you a verifiable starting point, but it is not a substitute for hands-on experience or advanced certifications. If you want to explore the career side honestly, our articles on CHS-CY1 jobs, the CHS-CY1 salary guide, and whether the certification is worth it lay out realistic expectations without inflated promises.

A Domain-Ordered Preparation Plan

Since weights are unpublished, an even spread across the six areas is the safest approach. The ordering below puts conceptual groundwork first, because later domains build on the vocabulary you learn early. Adjust the pace to your schedule; the sequence is what matters.

Week 1

Cybersecurity Essentials

  • Memorize the CIA Triad and practice scenario mapping
  • Distinguish ransomware, phishing, and IoT risks
  • Review cyber ethics and legal versus illegal hacking
Week 2

Cryptography

  • Encrypt and decrypt by hand with Caesar and Vigenere
  • Work through brute force and frequency analysis examples
Week 3

System Administration and IT Concepts

  • Review operating systems, licenses, browsers, and basic command line
  • Learn IPv4, IPv6, DNS hierarchy, routing, and packets
Week 4

Infrastructure, Digital Safety, and Full Practice

  • Cover hardware, storage, and network devices
  • Study digital footprint, SQL injection, and developer tools
  • Finish with timed full-length practice and review every miss

For a fuller methodology, our CHS-CY1 study guide expands on how to structure review, and the CHS-CY1 cheat sheet gives you a compact refresher for the final days. If you are unsure how demanding the exam will feel, how hard the CHS-CY1 exam is offers a candid look at difficulty.

When you reach the final week, take timed practice sets that mirror the real format: 45 multiple-choice questions against a 90-minute clock. Review every missed question by domain, and revisit the area where your misses cluster. You can start with the free questions on our practice test site to find your weakest domain early.

Frequently Asked Questions

How many questions are on the CHS-CY1 exam?

The CodeHS Cybersecurity Level 1 exam has 45 multiple-choice questions, delivered as an online timed exam.

How long do I have, and what score do I need?

The CodeHS Certifications FAQ states a 90-minute time limit and a 60% passing score for all certification exams except Java, which includes this one.

Do I need to take a course before the exam?

No. CodeHS lists no prerequisites. It does recommend the Fundamentals of Cybersecurity course as preparation, which aligns closely with the exam topics.

What happens if I fail and want to retake it?

Each exam attempt requires a new voucher, so a retake means obtaining another one. Use full practice exams beforehand to reduce the chance of needing a second attempt.

How long is the certification valid?

CodeHS states that certification credentials expire after 10 years from earning them.

Ready to pass your CHS-CY1 exam?

Put this into practice with free CHS-CY1 questions across every exam domain.