- The Number: 60% on a 45-Question Exam
- What 60% Actually Means in Questions
- How the Exam Is Delivered and Scored
- Six Unweighted Domains: Why Coverage Beats Specialization
- Where Candidates Gain and Lose Points
- Vouchers, Retakes and Credential Lifespan
- Setting a Realistic Target Score
- A Four-Week Domain Schedule
- What a Pass Gets You
- Frequently Asked Questions
- CodeHS sets the passing score at 60% for all certification exams except Java, which includes Cybersecurity Level 1.
- The exam has 45 multiple-choice questions in a timed online format with a 90-minute limit.
- CodeHS does not publish percentage weights for the six topic areas, so study all six evenly.
- Each exam attempt requires a new voucher, so a failed attempt means obtaining another voucher.
The Number: 60% on a 45-Question Exam
If you are preparing for the CodeHS Cybersecurity Level 1 exam (CHS-CY1), the most important figure to know is simple: the passing score is 60%. According to the CodeHS Certifications FAQ, 60% is the passing threshold for all CodeHS certification exams except Java. Cybersecurity Level 1 is not the Java exam, so the 60% line applies to you.
The format is equally straightforward. The exam consists of 45 multiple-choice questions delivered as an online timed exam, and the FAQ states the time limit is 90 minutes. There is no essay component, no lab simulation described in the official sources, and no command-line practical. Everything you are scored on is a multiple-choice question.
For a wider orientation on the credential itself, see What Is CHS-CY1 Certification? and CHS-CY1 Requirements 2026: Eligibility, Prerequisites & How to Qualify.
What 60% Actually Means in Questions
Percentages feel abstract until you convert them into questions. With 45 items on the exam, 60% works out to 27 correct answers (27 divided by 45 equals exactly 0.60). That is the arithmetic floor if the exam is scored as a simple proportion of correct responses.
| Measure | Value | What it means for you |
|---|---|---|
| Total questions | 45 multiple choice | Every question is a single-selection style item with no written response |
| Passing threshold | 60% | Equivalent to 27 of 45 correct if scored proportionally |
| Questions you can miss | Up to 18 | Derived from the 60% line; leaves a real but not huge margin |
| Time limit | 90 minutes | Averages about 2 minutes per question |
| Prerequisites | None | Anyone may attempt the exam, though CodeHS recommends its Fundamentals of Cybersecurity course |
Notice the margin. Eighteen misses sounds comfortable, but it disappears quickly if an entire topic area is blank in your mind. Because the exam spans six areas, a single weak domain can cost you most of those eighteen misses on its own. That is why the next sections focus on how the content is distributed rather than just the pass line.
For a view on how demanding that margin feels in practice, read How Hard Is the CHS-CY1 Exam? Complete Difficulty Guide 2026.
How the Exam Is Delivered and Scored
Format and pacing
The CHS-CY1 is an online timed exam. With 45 questions in 90 minutes, you have roughly two minutes per item. For multiple-choice recall and concept questions, that is generous. Most candidates who know the material finish with time to review flagged items. The pacing risk is not the clock; it is overthinking questions where the answer depends on a precise definition.
What is and is not published
CodeHS publishes the passing score (60%), the question count (45), the time limit (90 minutes), the question type (multiple choice), the absence of prerequisites, the need for a new voucher per attempt, and the 10-year credential expiration. CodeHS does not publish a per-domain minimum, a per-domain weighting, or a breakdown of how many questions come from each topic area in the sources reviewed here. This matters, because it means you should not trust any site that claims to know "exactly" how many questions come from a given domain.
Six Unweighted Domains: Why Coverage Beats Specialization
The official exam topics are six headings: Cybersecurity Essentials, Cryptography, System Administration, IT Concepts, IT Infrastructure, and Digital Safety and Data Security. No percentage weights are published. For a 60% pass line, this has a practical consequence: you cannot safely skip a domain on the theory that it is "only a small slice."
Consider the math of a lopsided candidate. Suppose you are excellent at cryptography and networking but have never opened a command line or thought about SQL injection. If those weaker areas supply even a modest number of questions, you could burn through the 18-question miss allowance in just two domains while earning near-perfect marks elsewhere. Balanced competence is the safer strategy because the exam gives you no weighting map to exploit.
Key Takeaway
Aim for roughly 75% confidence in every one of the six domains rather than 95% in three and 30% in the rest. Because weights are unpublished, breadth protects your 60% line far better than depth in a favorite area. The full domain walkthrough is in CHS-CY1 Exam Domains 2026: Complete Guide to All 6 Content Areas.
Where Candidates Gain and Lose Points
Each domain below lists the exact subtopics from the official CHS-CY1 outline, with notes on the type of understanding multiple-choice questions typically reward.
Domain 1: Cybersecurity Essentials
This is the conceptual foundation, and it tends to be the most accessible domain for newcomers.
- Ransomware and phishing: recognize how each attack works and how a user would spot or prevent it
- Internet of Things: understand why connected devices expand the attack surface
- The CIA Triad: confidentiality, integrity and availability, and which one a given scenario violates
- Cyber ethics, credit and copyright, and legal versus illegal hacking: expect scenario questions about what is permitted
Domain 2: Cryptography
Points here come from mechanics, not memorized trivia.
- Basic cryptography and code breaking terminology
- Brute force versus frequency analysis: know when each attack applies
- Caesar cipher: the shift mechanism, and why it is easy to break
- Vigenere cipher: how a keyword changes the shift per letter, and why it resists simple frequency analysis better than Caesar
Domain 3: System Administration
Candidates without hands-on exposure often lose points here.
- Operating systems, software and software licenses
- Application security and browsers
- System administration responsibilities
- Command line system: be comfortable reading basic commands and predicting what they do
Domain 4: IT Concepts
This domain rewards precise definitions and the ability to trace how data moves.
- Internet addresses, IPv4 and IPv6: know the differences between the two address formats
- DNS hierarchy: how a name resolves to an address
- Routing, packets and protocols: what a packet is and how protocols govern communication
Domain 5: IT Infrastructure
Largely hardware and network vocabulary, so flashcard-style review works well here.
- Internal components and peripheral devices
- Network devices, storage options and network options
- Network communication and network management
Domain 6: Digital Safety and Data Security
Combines personal safety topics with introductory technical security.
- Digital footprint, cyberbullying and internet safety
- Clients and servers
- SQL queries and SQL injection: read a basic query and understand how unsanitized input can be exploited
- Developer tools: what browser developer tools reveal about a page
Candidates who have worked through the CodeHS Fundamentals of Cybersecurity course, which CodeHS recommends for preparation, will recognize most of this terrain. For a structured approach to covering all of it, see the CHS-CY1 Study Guide 2026: How to Pass on Your First Attempt.
Vouchers, Retakes and Credential Lifespan
Your passing score strategy should account for how attempts are handled. CodeHS requires a new voucher for each exam attempt. In practical terms, this means a failed attempt is not a free reset; you need to obtain another voucher before sitting the exam again. That raises the value of getting it right the first time and of using practice material to confirm you are comfortably above 60% before you begin.
CodeHS does not publish fee amounts in the sources reviewed for this article, so we will not quote a price. If you are budgeting, check with your instructor or school (many candidates take the exam through CodeHS-affiliated courses) and read CHS-CY1 Certification Cost 2026: Complete Pricing Breakdown for what is and is not known.
Once earned, the credential does not last forever: CodeHS states certification credentials expire after 10 years. For scheduling considerations around when you can test, see CHS-CY1 Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Setting a Realistic Target Score
The pass line is 60%, but your practice target should be higher. Practice questions are never identical to the real exam, and nerves, wording and unfamiliar phrasing all shave a few points off performance on test day. A reasonable approach:
- Treat 60% as the cliff edge, not the goal. Scoring exactly 27 of 45 in practice leaves no cushion.
- Aim to consistently score well above the line on full-length practice sets before booking your attempt, since each retake costs you another voucher.
- Check the floor by domain, not just the total. A decent overall score can hide a domain where you are guessing. Review any domain where you are missing roughly half the questions.
- Review wrong answers by concept. If you miss a Vigenere question, the fix is understanding keyword-based shifting, not memorizing that one answer.
You can take full-length timed practice sets on our CHS-CY1 practice test site to measure where you stand before you commit to an attempt.
A Four-Week Domain Schedule
Because no domain weights are published, this schedule spreads time across all six areas, front-loading the ones that most often require hands-on practice rather than memorization.
System Administration and IT Concepts
- Practice basic command-line navigation until reading commands feels natural
- Trace how a domain name resolves through the DNS hierarchy and how packets move across routes
- Compare IPv4 and IPv6 address formats side by side
Cryptography and Digital Safety and Data Security
- Encrypt and decrypt short messages by hand with Caesar and Vigenere ciphers
- Work through frequency analysis on a sample ciphertext
- Read simple SQL queries and identify what makes an injection possible
Cybersecurity Essentials and IT Infrastructure
- Map each attack scenario (ransomware, phishing, IoT compromise) to a CIA Triad property
- Build a vocabulary list of network devices, storage options and peripherals
- Review cyber ethics and the line between legal and illegal hacking
Full-Length Practice and Gap Repair
- Sit at least one full 45-question timed set under realistic conditions
- Score each domain separately and revisit any area where you are near or below the 60% line
- Use the CHS-CY1 Cheat Sheet 2026: One-Page Review of Must-Know Facts for a final pass
What a Pass Gets You
CodeHS Cybersecurity Level 1 is an entry-level credential, and it is best understood as a documented foundation rather than a job qualification on its own. Passing signals that you can handle core cybersecurity vocabulary and concepts across six areas, which is useful for students building a portfolio, educators documenting student achievement, and early-career candidates exploring technical paths. It does not replace more advanced security credentials or hands-on experience.
If you are weighing whether the effort is worthwhile, read Is the CHS-CY1 Certification Worth It? Complete ROI Analysis 2026 and the discussion of CHS-CY1 Jobs. We deliberately avoid quoting salary numbers here, because CodeHS does not publish earnings data tied to this credential.
Note also that the scope here is Cybersecurity Level 1 only. Topics belonging to a higher-level CodeHS cybersecurity exam are not part of this test, so you do not need to study beyond the six domains above to reach the 60% line.
Frequently Asked Questions
The passing score is 60%. The CodeHS Certifications FAQ states 60% is the threshold for all certification exams except Java, and Cybersecurity Level 1 falls under the 60% rule.
The exam has 45 multiple-choice questions, so 60% corresponds to 27 correct answers if scoring is a simple proportion. CodeHS does not publish a different scoring model in the sources reviewed, so plan on that basis and aim comfortably above it.
The exam is timed at 90 minutes for 45 questions. That works out to about two minutes per question, which is generally enough time for multiple-choice items if you know the material.
CodeHS lists six topic areas but publishes no percentage weights, so you should not assume any domain is negligible. Prepare across Cybersecurity Essentials, Cryptography, System Administration, IT Concepts, IT Infrastructure, and Digital Safety and Data Security.
You can try again, but CodeHS requires a new voucher for each exam attempt. Use practice tests to confirm you are consistently above the pass line before using a voucher, and review your weakest domain before any retake.