CHS-CY1 logo
Focused certification exam prep
Start practice

CHS-CY1 Exam Domains 2026: Complete Guide to All 6 Content Areas

TL;DR
  • CodeHS lists six topic areas for Cybersecurity Level 1 but publishes no percentage weights, so prepare evenly.
  • The exam is 45 multiple-choice questions, timed at 90 minutes, with a 60% passing score.
  • Cryptography covers Caesar and Vigenere ciphers, brute force, and frequency analysis, so practice them by hand.
  • Domain 6 pairs SQL queries with SQL injection, so know both how queries work and how they get abused.

How the CodeHS Cybersecurity Level 1 Exam Is Built

The CodeHS Cybersecurity Level 1 certification (CHS-CY1) is an online timed exam made up of 45 multiple-choice questions. According to the CodeHS Certifications FAQ, the exam is timed at 90 minutes, and the passing score is 60% for all CodeHS certification exams except Java. That means you need to answer at least 27 of the 45 questions correctly. For a deeper look at that threshold, see our breakdown of the CHS-CY1 passing score.

The official exam overview groups content into six "Topics & Concepts Covered" headings. CodeHS does not publish percentage weights for these headings, and this guide does not invent any. Treat the six areas as roughly equal in importance until you see otherwise in your own practice results. There are no prerequisites to sit for the exam, though CodeHS recommends its Fundamentals of Cybersecurity course as preparation. If you want the full eligibility picture, read CHS-CY1 requirements and how to qualify.

Why unpublished weights matter: Because CodeHS does not state how many of the 45 questions come from each heading, you cannot safely skip a domain. A candidate who ignores Cryptography or Digital Safety could lose a meaningful share of the questions. Balanced preparation is the only defensible strategy.

Each exam attempt requires a new voucher, so a failed attempt cannot simply be retaken for free. That makes first-attempt readiness more valuable than it might be on exams with built-in retakes. Our CHS-CY1 study guide for passing on the first attempt covers the broader plan; this article focuses on the content itself.

Domain 1: Cybersecurity Essentials

The first domain covers the foundational vocabulary and ideas of the field. The official topic list is: Ransomware; Phishing; Internet of Things; The CIA Triad; Cyber Ethics; Credit and Copyright; and Legal vs. Illegal Hacking. This is the most conceptual domain, and questions tend to test whether you can recognize a scenario and name the correct concept.

Ransomware and Phishing

Know what each attack does, how it reaches a victim, and how users and organizations defend against it.

  • Ransomware encrypts or locks data and demands payment for access.
  • Phishing uses deceptive messages to trick people into revealing credentials or clicking malicious links.
  • Be able to spot the warning signs in a sample message: urgency, mismatched sender addresses, and suspicious links.
  • Understand why backups are a core ransomware defense.

The CIA Triad

Confidentiality, Integrity, and Availability form the standard framework for thinking about security goals.

  • Confidentiality means only authorized people can see the data.
  • Integrity means data has not been altered improperly.
  • Availability means systems and data are accessible when needed.
  • Expect scenario questions: given an incident, which part of the triad was violated?

Internet of Things, Ethics, Copyright, and Legal Hacking

These topics test judgment as much as definitions.

  • Internet of Things devices expand the attack surface because many are poorly secured.
  • Cyber ethics asks what responsible behavior looks like online.
  • Credit and copyright covers properly attributing work and respecting ownership.
  • Legal versus illegal hacking turns on authorization: permission is the dividing line.

Domain 2: Cryptography

Cryptography is the domain where hands-on practice pays off most. The official topics are: Basic Cryptography; Code Breaking; Brute Force; Frequency Analysis; Caesar Cipher; and Vigenere Cipher. Many candidates find this domain the most distinctive part of CHS-CY1 because it asks you to actually work a cipher, not just define one.

Ciphers You Should Be Able to Work by Hand

The Caesar cipher shifts each letter by a fixed amount. The Vigenere cipher uses a repeating keyword so that different letters shift by different amounts. You should be able to encrypt and decrypt short messages with both, and explain why Vigenere is harder to crack than Caesar.

TechniqueWhat It IsWhat to Know for the Exam
Caesar CipherFixed-shift substitutionFew possible keys, so it is easy to break
Vigenere CipherKeyword-based shiftingResists simple frequency analysis better than Caesar
Brute ForceTrying every possible keyPractical against small key spaces
Frequency AnalysisCounting letter occurrencesExploits predictable letter patterns in language
Connect attack to cipher: A common way to think about this domain is matching each attack to the cipher it defeats. Brute force works well on Caesar because there are so few shifts to try. Frequency analysis works because common letters like E appear predictably in English text. Understanding why each attack succeeds will serve you better than memorizing definitions.

Domain 3: System Administration

This domain moves from concepts to the tools and environments that administrators manage. The official topics are: Operating Systems; Software & Software Licenses; Application Security; Browsers; System Administration; and Command Line System.

Operating Systems and Software Licensing

Know what an operating system does and how software is legally distributed and used.

  • The operating system manages hardware resources and provides a platform for applications.
  • Software licenses define what users are allowed to do with a program.
  • Be prepared to distinguish between common licensing models at a conceptual level.

Application Security and Browsers

Applications and browsers are frequent attack targets, so security hygiene matters.

  • Keeping software updated closes known vulnerabilities.
  • Browsers handle cookies, extensions, and permissions that affect safety.
  • Understand the risk of installing software from untrusted sources.

System Administration and the Command Line

The command line is a text-based way to control a system, and CHS-CY1 expects basic comfort with it.

  • Know what an administrator is responsible for: users, permissions, updates, and monitoring.
  • Be able to recognize common command-line operations such as navigating directories and listing or managing files.
  • Practice reading short command sequences and predicting what they do.

Domain 4: IT Concepts

This is the networking-theory domain. The official topics are: Internet Addresses; IPv4 and IPv6; DNS Hierarchy; Routing; and Packets and Protocols. Questions here reward candidates who can trace how data actually travels from one machine to another.

Addresses, DNS, and Routing

Every device on a network needs an address. You should understand the difference between IPv4 and IPv6, including why IPv6 exists: the older format offers a limited number of addresses. DNS translates human-readable names into IP addresses, and its hierarchy runs from the root down through top-level domains to individual domains. Routing is the process of forwarding traffic between networks toward its destination.

Key Takeaway

Walk through one complete scenario in your head: you type a website name, DNS resolves it to an IP address, your data is broken into packets, and routers forward those packets hop by hop. If you can narrate that sequence, most Domain 4 questions become straightforward.

Packets and Protocols

Data on a network is divided into packets, and protocols are the agreed-upon rules that let devices communicate. Know what a packet contains at a high level and why standardized protocols make the internet interoperable.

Domain 5: IT Infrastructure

This domain covers the physical and logical building blocks of computing environments. The official topics are: Internal Components; Peripheral Devices; Network Devices; Storage Options; Network Options; Network Communication; and Network Management. It is the broadest domain by topic count, with seven headings.

Hardware: Internal Components, Peripherals, and Storage

Expect recognition and function questions.

  • Identify what internal components such as the processor, memory, and storage do inside a computer.
  • Distinguish peripheral devices that connect to a computer for input or output.
  • Compare storage options and their trade-offs in speed, capacity, and portability.

Networking: Devices, Options, Communication, and Management

These topics connect hardware to the networks it participates in.

  • Know the roles of common network devices such as routers and switches.
  • Understand the differences between wired and wireless network options.
  • Recognize how devices communicate and how administrators monitor and manage networks.
Overlap with Domain 4: Domains 4 and 5 both touch networking, but from different angles. Domain 4 asks how data moves and how addressing works; Domain 5 asks what physical and logical equipment makes that possible. Studying them back to back helps the two sets of ideas reinforce each other.

Domain 6: Digital Safety and Data Security

The final domain blends personal online safety with technical data security. The official topics are: Digital Footprint; Cyberbullying; Internet Safety; Clients and Servers; SQL Queries; SQL Injection; and Developer Tools. It is the most mixed domain, so candidates need to shift between human-centered and technical thinking.

The Human Side

Digital footprint refers to the trail of data you leave online, both intentionally and unintentionally. Cyberbullying and internet safety questions typically ask you to identify appropriate responses and protective behaviors. These tend to be judgment-based and reward careful reading of the scenario.

The Technical Side: Clients, Servers, SQL, and Developer Tools

Clients request services and servers provide them; know how that relationship underlies web activity. SQL is the language used to query databases, so you should be able to read a basic query and understand what data it retrieves. SQL injection is the attack in which malicious input is inserted into a query to manipulate a database. Developer tools in a browser let you inspect pages and see how they are built.

SQL Queries and SQL Injection Together

These two topics are best studied as a pair, because the attack only makes sense once you understand the normal query.

  • Learn the structure of a simple SELECT query with a condition.
  • Understand how unsanitized user input can alter the meaning of that query.
  • Recognize that validating and sanitizing input is the core defense.

Sequencing the Six Domains in Your Prep

You do not need an elaborate schedule, but the order in which you tackle the domains can help. A sensible approach starts with the conceptual vocabulary, moves into the skills that require hands-on practice, and finishes with the mixed domain that draws on everything.

Week 1

Cybersecurity Essentials and Digital Safety

  • Build vocabulary: ransomware, phishing, the CIA Triad, digital footprint.
  • These topics are concept-heavy and set the language for everything else.
Week 2

Cryptography

  • Work Caesar and Vigenere ciphers by hand until they feel automatic.
  • Practice matching brute force and frequency analysis to the ciphers they break.
Week 3

IT Concepts and IT Infrastructure

  • Study addressing, DNS, routing, and packets together with network devices and options.
  • Trace a full request from browser to server to reinforce both domains.
Week 4

System Administration, SQL, and Full Review

  • Practice reading command-line sequences and basic SQL queries, then study SQL injection.
  • Finish with timed sets of 45 questions to simulate the real exam.

Timed practice matters because the real exam allows 90 minutes for 45 questions, which is generous but still rewards steady pacing. You can run through realistic question sets on our CHS-CY1 practice test to check which domains need more attention. If you are unsure how demanding the exam will feel, our guide on how hard the CHS-CY1 exam is sets expectations honestly, and the CHS-CY1 cheat sheet is a handy final review.

Where the Credential Fits

CHS-CY1 is an entry-level credential from CodeHS, and it is best understood as a structured way to demonstrate foundational cybersecurity literacy. It carries no prerequisites, and CodeHS states that certification credentials expire after 10 years. It is aimed at the beginner end of the field, so it is most useful as an early milestone rather than a standalone job qualification.

Questions about cost, earnings, and career impact come up often, but they depend on details outside the CodeHS sources used for this guide. For the money side, see CHS-CY1 certification cost; for the bigger picture, is the CHS-CY1 certification worth it weighs the value qualitatively. When you are ready to test yourself across all six domains, head back to the main practice test site.

Key Takeaway

Because CodeHS does not publish domain weights, your best protection is breadth. Make sure you can explain each of the roughly forty named topics in a sentence or two, and work the ciphers, queries, and network traces by hand rather than only reading about them.

Frequently Asked Questions

How many domains does the CHS-CY1 exam cover?

CodeHS lists six topic areas: Cybersecurity Essentials, Cryptography, System Administration, IT Concepts, IT Infrastructure, and Digital Safety and Data Security. CodeHS does not publish percentage weights for them.

How many questions are on the exam and how long do I have?

The exam has 45 multiple-choice questions delivered as an online timed exam. According to the CodeHS FAQ, the time limit is 90 minutes.

What score do I need to pass?

CodeHS states a 60% passing score for all certification exams except Java. On a 45-question exam, that works out to at least 27 correct answers.

Do I need to complete a course before taking the exam?

No. CodeHS states there are no prerequisites. It does recommend the Fundamentals of Cybersecurity course as preparation, and each exam attempt requires a new voucher.

Which domain should I prioritize?

Since weights are not published, spread your effort evenly. Many candidates benefit from extra hands-on practice in Cryptography and from pairing SQL queries with SQL injection in Digital Safety and Data Security.

Ready to pass your CHS-CY1 exam?

Put this into practice with free CHS-CY1 questions across every exam domain.