- The CodeHS Cybersecurity Level 1 exam is 45 multiple-choice questions in a 90-minute online timed session.
- The passing score is 60%, which is the standard for all CodeHS certification exams except Java.
- Six topic areas are tested, and CodeHS publishes no percentage weights, so study all six evenly.
- Each exam attempt requires a new voucher, and the credential expires after 10 years.
The Exam at a Glance
This page condenses everything you need to remember for the CodeHS Cybersecurity Level 1 exam (CHS-CY1) into one scannable review. It is built from the official CodeHS exam overview and the CodeHS Certifications FAQ, so every number below is one CodeHS actually publishes. If you want the full strategy behind these facts, pair this sheet with our CHS-CY1 Study Guide: How to Pass on Your First Attempt.
| Exam Fact | What CodeHS States |
|---|---|
| Issuer | CodeHS |
| Format | Online timed exam |
| Question count | 45 multiple-choice questions |
| Time limit | 90 minutes |
| Passing score | 60% (all CodeHS certification exams except Java) |
| Prerequisites | None |
| Recommended prep | CodeHS Fundamentals of Cybersecurity course |
| Retakes | A new voucher is required for each attempt |
| Credential validity | Expires after 10 years |
| Topic areas | Six, with no published percentage weights |
Fees, pass rates, and domain weightings are not published in the CodeHS sources, so any site quoting precise percentages for this exam is guessing. For what we can say about cost mechanics, see CHS-CY1 Certification Cost 2026, and for the score threshold in detail, see CHS-CY1 Passing Score 2026.
Domain 1: Cybersecurity Essentials
This is the vocabulary-and-ethics domain. Expect scenario questions that describe an event and ask you to name it, or describe a situation and ask which principle or rule applies.
Ransomware, Phishing, and the Internet of Things
Know what each threat does and how a victim typically encounters it.
- Ransomware: malware that locks or encrypts a victim's data and demands payment to restore access.
- Phishing: deceptive messages, usually email, designed to trick someone into revealing credentials or clicking a malicious link.
- Internet of Things (IoT): everyday connected devices such as cameras, thermostats, and wearables, which often ship with weak default security.
The CIA Triad
This is one of the most testable ideas in the whole exam. Memorize all three pillars and be able to match a scenario to the one being violated.
- Confidentiality: only authorized people can see the data.
- Integrity: data is accurate and has not been altered improperly.
- Availability: authorized users can reach the data and systems when they need them.
Cyber Ethics, Credit and Copyright, Legal vs. Illegal Hacking
These topics test judgment. The recurring dividing line is permission.
- Legal hacking is authorized, such as a penetration test with written permission to probe a system.
- Illegal hacking is access without authorization, regardless of intent.
- Giving credit and respecting copyright are ethical and legal obligations when you use someone else's work.
For a deeper walkthrough of this and the other five areas, read CHS-CY1 Exam Domains 2026: Complete Guide to All 6 Content Areas.
Domain 2: Cryptography
This domain rewards hands-on practice more than memorization. If you can encrypt and decrypt a short message by hand, you can answer most questions here.
Caesar Cipher
A substitution cipher that shifts every letter by a fixed number of positions in the alphabet.
- The shift amount is the key. With a shift of 3, A becomes D, B becomes E, and so on.
- To decrypt, shift in the opposite direction by the same amount.
- It has only 25 meaningful shifts, which makes it trivial to break.
Vigenere Cipher
A stronger relative of the Caesar cipher that uses a keyword, so different letters are shifted by different amounts.
- Each letter of the keyword sets the shift for the matching plaintext letter, and the keyword repeats along the message.
- Because the same plaintext letter can encrypt to different ciphertext letters, simple letter-frequency counting is much less effective.
Code Breaking: Brute Force and Frequency Analysis
Know the two attack styles and when each works.
- Brute force: try every possible key until the message makes sense. Practical against a Caesar cipher because the key space is tiny.
- Frequency analysis: count how often letters appear in the ciphertext and compare against typical language patterns, such as E being the most common letter in English.
Domain 3: System Administration
This domain covers how computers are run, secured, and maintained day to day. Questions tend to be practical and definition-driven.
- Operating systems: know what an OS does, namely managing hardware, memory, files, and running programs, and recognize the common families.
- Software and software licenses: understand the difference between proprietary, open-source, and free software, and that a license defines what you may legally do with the code.
- Application security: keeping software updated and patched closes known vulnerabilities, and unpatched software is a classic attack path.
- Browsers: recognize browser security features and settings, and why keeping a browser current matters.
- System administration: the role involves managing user accounts, permissions, updates, and backups.
- Command line: be comfortable reading basic commands for navigating directories, listing files, and creating or removing them.
Key Takeaway
Do not skim the command-line material. Even a short session typing basic navigation and file commands makes the multiple-choice questions on this topic feel like recall rather than guesswork.
Domain 4: IT Concepts
This is the networking-fundamentals domain, and it is where many first-time candidates lose points because the vocabulary looks similar across terms.
Internet Addresses: IPv4 vs. IPv6
Every device on a network needs an address, and two versions are in use.
- IPv4: 32-bit addresses written as four numbers separated by dots, such as 192.168.1.1. The address pool is limited.
- IPv6: 128-bit addresses written in hexadecimal groups separated by colons, created to provide a vastly larger pool.
DNS Hierarchy
DNS translates human-readable domain names into IP addresses so you do not have to memorize numbers.
- Names are resolved through a hierarchy, reading right to left: the top-level domain (like .com), then the domain, then any subdomain.
- Think of DNS as the internet's phone book.
Routing, Packets, and Protocols
Data does not travel as one big block.
- Information is split into packets, each carrying a piece of the data plus addressing details.
- Routers forward packets toward their destination across multiple networks.
- Protocols are the agreed rules that let different devices communicate and reassemble the data correctly.
Domain 5: IT Infrastructure
Here the exam moves from software concepts to the physical and networked pieces that make up a working IT environment. The question style is mostly "which component does what."
| Category | What to Know |
|---|---|
| Internal components | The parts inside a computer, such as the processor, memory, and storage, and the role each plays |
| Peripheral devices | External input and output devices connected to a computer, such as keyboards, printers, and monitors |
| Network devices | Hardware that connects and directs traffic, such as routers and switches |
| Storage options | The different ways data can be stored and the tradeoffs between them |
| Network options | Wired versus wireless connectivity and when each makes sense |
| Network communication | How devices on a network exchange data |
| Network management | Monitoring, configuring, and maintaining a network so it stays reliable and secure |
A reliable memory trick is to sort every device into one of three buckets: it computes or stores (internal), it connects a person to a computer (peripheral), or it connects computers to each other (network device). Most questions in this domain become easy once you classify the item correctly.
Domain 6: Digital Safety and Data Security
This domain blends personal online safety with a first look at how web applications are attacked. The SQL material is the most technical content on the exam, so give it focused attention.
Digital Footprint, Cyberbullying, and Internet Safety
These are behavior-and-consequences questions.
- A digital footprint is the trail of data you leave online, both what you post and what is collected about you, and it can be long-lasting.
- Cyberbullying is harassment carried out through digital channels, and the right response involves saving evidence and reporting it.
- Safe habits include strong unique passwords, limiting personal information shared publicly, and being skeptical of unexpected links.
Clients and Servers, Developer Tools
- A client requests resources, and a server provides them. Your browser is the client; the website's host machine is the server.
- Browser developer tools let you inspect a page's structure, network activity, and behavior, which is useful for understanding how a site works.
SQL Queries and SQL Injection
Learn the legitimate use first, then the abuse.
- SQL is the language used to ask a database for, add, change, or remove data. A basic query selects specific columns from a table with optional conditions.
- SQL injection happens when an attacker types SQL code into an input field and the application runs it as part of its own query, potentially exposing or altering data.
- The core defense is to never trust user input: validate it and use parameterized queries instead of building queries by gluing strings together.
Quick-Recall Comparison Table
These are the pairs of terms most easily confused under exam pressure.
| Term A | Term B | The Difference |
|---|---|---|
| Brute force | Frequency analysis | Trying every key versus analyzing letter patterns in the ciphertext |
| Caesar cipher | Vigenere cipher | One fixed shift versus keyword-driven shifting |
| IPv4 | IPv6 | 32-bit dotted numbers versus 128-bit hexadecimal addresses |
| Client | Server | Requests resources versus provides them |
| Router | DNS | Forwards packets between networks versus translates names to addresses |
| Confidentiality | Integrity | Who can see data versus whether data is unaltered |
| Legal hacking | Illegal hacking | Authorized by the owner versus unauthorized access |
| Phishing | Ransomware | Tricks people into revealing information versus locks data for payment |
Scheduling the Six Domains
Because CodeHS publishes no weights, treat the six domains as roughly equal and plan around where your own background is thinnest. Here is a four-week layout that front-loads the topics people find most unfamiliar.
Cryptography and Cybersecurity Essentials
- Encrypt and decrypt sample messages with Caesar and Vigenere by hand
- Memorize the CIA Triad and match it to real scenarios
- Drill the ethics and legal-versus-illegal hacking distinctions
IT Concepts
- Practice reading IPv4 and IPv6 addresses
- Trace how a domain name resolves through the DNS hierarchy
- Explain packets, routing, and protocols in your own words
System Administration and IT Infrastructure
- Type through basic command-line navigation and file commands
- Sort hardware into internal, peripheral, and network buckets
- Review software licenses and application security basics
Digital Safety, SQL, and Full Review
- Write simple SQL queries, then study how injection breaks them
- Take timed practice sets on our CHS-CY1 practice test
- Re-study only the domains where your practice scores lag
If you are unsure how much effort to budget, How Hard Is the CHS-CY1 Exam? breaks down which areas candidates tend to find most demanding. For context on whether the credential is worth the time, see Is the CHS-CY1 Certification Worth It?.
Key Takeaway
Finish with timed practice in the same multiple-choice format you will face on test day. Reading the cheat sheet builds recognition, but only practice questions show you which terms you still confuse. You can start with the free practice questions at chscy1exam.com.
Frequently Asked Questions
The exam has 45 multiple-choice questions, delivered as an online timed exam with a 90-minute limit.
CodeHS states a 60% passing score for all of its certification exams except Java. On 45 questions, that means 27 correct answers.
No. CodeHS lists no prerequisites, though it recommends the Fundamentals of Cybersecurity course for preparation. See CHS-CY1 Requirements 2026 for the full picture.
Yes, but CodeHS requires a new voucher for each exam attempt, so plan your preparation to avoid unnecessary retakes.
CodeHS states that certification credentials expire after 10 years.