CHS-CY1 logo
Focused certification exam prep
Start practice

CHS-CY1 Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • The exam has 45 multiple-choice questions, a 90-minute limit, and a 60% passing score per the CodeHS FAQ.
  • Six content areas are tested, but CodeHS publishes no percentage weights, so prepare evenly across all six.
  • Each attempt requires a new voucher, so a failed try means obtaining another one before retesting.
  • Hands-on practice with Caesar and Vigenere ciphers, IP addressing, and SQL injection pays off on exam day.

What the CodeHS CHS-CY1 Exam Actually Is

CHS-CY1 is the CodeHS Cybersecurity Level 1 certification exam. It is issued by CodeHS, the education technology company behind a widely used library of computer science and cybersecurity courses for schools and independent learners. If you have landed on this page while searching for a different credential that happens to share the abbreviation, this guide covers only the CodeHS exam. For a broader orientation, see What Is CHS-CY1? and What Does CHS-CY1 Stand For?.

The certification is a foundational, entry-level credential. It validates that you understand the core vocabulary and concepts of cybersecurity, from ransomware and phishing to cryptography, networking basics, and SQL injection. It is not a deep technical certification, and it does not require prior experience. Understanding that framing shapes how you should study: the exam rewards breadth and conceptual clarity far more than deep tool-specific expertise.

CodeHS lists no formal prerequisites. The company does recommend its Fundamentals of Cybersecurity course as preparation, and that recommendation is worth taking seriously because the exam topics map to the kind of material that course introduces. You can read more about eligibility in CHS-CY1 Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Format, Timing, Passing Score, and Voucher Rules

Knowing the mechanics removes a layer of uncertainty before you ever sit down to test. Here is what the official CodeHS sources state:

Exam DetailWhat CodeHS States
Question count45 multiple-choice questions
DeliveryOnline, timed exam
Time limit90 minutes
Passing score60% (applies to all CodeHS certification exams except Java)
PrerequisitesNone required; Fundamentals of Cybersecurity course recommended
RetakesA new voucher is required for each exam attempt
Credential validityCertification credentials expire after 10 years

A 60% threshold on 45 questions means you need to answer at least 27 correctly. That is a meaningful buffer, but not a license to skip an entire content area. Since the exam draws from six distinct domains, ignoring even one can cost you a large cluster of questions. Our dedicated breakdown, CHS-CY1 Passing Score 2026: Exactly What You Need to Pass, walks through the arithmetic in more detail.

Voucher mechanics matter: CodeHS requires a new voucher for every exam attempt. That means each try carries its own access step, so treat your first attempt as the one that counts and use practice material beforehand to avoid needing a second. Fee amounts are not published in the sources this guide relies on, so check the official CodeHS certification page or see CHS-CY1 Certification Cost 2026: Complete Pricing Breakdown for guidance on where to confirm current pricing.

One more point on timing: 90 minutes for 45 questions averages out to two minutes per question. For a multiple-choice exam at this level, that is generous. Pacing is rarely the problem; careless reading is.

The Six Content Areas You Must Master

The official exam overview lists six "Topics & Concepts Covered" headings. CodeHS does not publish percentage weights for them, so the safest strategy is balanced preparation with extra time on whichever area feels weakest. For an extended walkthrough, see CHS-CY1 Exam Domains 2026: Complete Guide to All 6 Content Areas. Below is a working summary of each.

Domain 1: Cybersecurity Essentials

This is the conceptual foundation. Expect questions on how threats work and on the ethical and legal frame around security work.

  • Ransomware and phishing: how each attack operates and how users and organizations defend against them
  • Internet of Things: why connected devices expand the attack surface
  • The CIA Triad: confidentiality, integrity, and availability, and how to identify which principle a scenario violates
  • Cyber ethics, credit and copyright, and the difference between legal and illegal hacking

Domain 2: Cryptography

The most hands-on conceptual area. You should be able to reason through a cipher, not just define it.

  • Basic cryptography and code breaking
  • Brute force and frequency analysis as attack approaches
  • Caesar cipher and Vigenere cipher mechanics

Domain 3: System Administration

Everyday computing environments viewed through a security lens.

  • Operating systems, software, and software licenses
  • Application security and browsers
  • System administration tasks and command line basics

Domain 4: IT Concepts

How data finds its way across networks.

  • Internet addresses, IPv4 and IPv6
  • DNS hierarchy and routing
  • Packets and protocols

Domain 5: IT Infrastructure

The physical and logical building blocks of a computing environment.

  • Internal components and peripheral devices
  • Network devices, network options, and network communication
  • Storage options and network management

Domain 6: Digital Safety and Data Security

Personal safety online combined with a first look at web-application security.

  • Digital footprint, cyberbullying, and internet safety
  • Clients and servers
  • SQL queries and SQL injection
  • Developer tools

Why Cryptography Deserves Extra Hands-On Practice

Most of the exam can be handled by reading and recall, but the cryptography domain rewards actually working a cipher by hand. Candidates who only memorize definitions tend to stumble when a question presents ciphertext and asks what a shift or key would produce.

Caesar cipher

The Caesar cipher shifts every letter by a fixed number of positions. Practice encrypting a short word with a shift of 3, then decrypting it by shifting back. Because the keyspace is tiny, brute force defeats it almost instantly: an attacker simply tries every possible shift. Be ready to explain why that weakness exists.

Vigenere cipher

The Vigenere cipher uses a repeating keyword, so different letters are shifted by different amounts. That defeats the simplest frequency analysis, because the same plaintext letter no longer always maps to the same ciphertext letter. Understand why it is stronger than Caesar, and why it is still breakable with enough ciphertext.

Frequency analysis and brute force

Frequency analysis exploits the fact that certain letters appear more often in natural language. Brute force simply tries every possibility. Know which cipher each technique is best suited to attack and why.

Practice habit: Spend ten minutes encrypting and decrypting by hand with both ciphers. Muscle memory from doing it yourself makes the exam's cipher questions feel routine rather than puzzling.

Networking and Infrastructure: Connecting the Dots

Domains 4 and 5 are best studied together because they describe the same system from two angles: IT Concepts covers how data moves, while IT Infrastructure covers the hardware and options that carry it.

Addressing and name resolution

Know the difference between IPv4 and IPv6, including why IPv6 exists. Be able to describe how DNS translates human-readable names into addresses and how its hierarchy is organized. Think of the trace of a single web request: name lookup, routing across networks, delivery in packets governed by protocols.

Hardware and network choices

For infrastructure, focus on what each component does and when you would choose it. Distinguish internal components from peripherals, compare storage options, and recognize the role of different network devices and network options. Questions here tend to be scenario-based: given a need, identify the appropriate component or approach.

Key Takeaway

Draw a single diagram that follows one web request from your browser to a server and back. Label the address, DNS lookup, routing hops, packets, and devices involved. If you can narrate that diagram, you have covered most of Domains 4 and 5.

SQL, Injection, and Digital Safety Questions

Domain 6 pairs two very different themes. The personal-safety half (digital footprint, cyberbullying, internet safety) is largely about recognizing good judgment. The technical half is where points are easier to lose.

SQL queries and SQL injection

You should be able to read a simple SQL query and understand what data it retrieves. From there, SQL injection becomes intuitive: it occurs when untrusted input is inserted into a query in a way that changes the query's meaning. Understand the basic idea of why this is dangerous and the general principle behind preventing it, namely treating user input as data rather than as part of the command.

Clients, servers, and developer tools

Be clear on the roles of clients and servers and how they exchange requests and responses. Developer tools in a browser let you inspect a page's behavior, and the exam expects you to recognize what they reveal and why that matters for both building and securing web content.

A Six-Week Plan Built Around the Domains

Because there is no published weighting, a plan that gives each domain its own focus week is a sensible default. The ordering below puts conceptual foundations first, then technical material, and saves integration for last. Adjust the pacing if you already know some areas well.

Week 1

Cybersecurity Essentials

  • Learn ransomware, phishing, and IoT risks with a real-world example for each
  • Master the CIA Triad by classifying sample incidents
  • Review ethics, copyright, and legal versus illegal hacking
Week 2

Cryptography

  • Work Caesar and Vigenere examples by hand
  • Compare brute force with frequency analysis
Week 3

System Administration

  • Review operating systems, licenses, and browsers
  • Practice basic command line navigation
Week 4

IT Concepts and IT Infrastructure

  • Trace a request through DNS, routing, and packets
  • Match devices, storage, and network options to scenarios
Week 5

Digital Safety and Data Security

  • Read and explain simple SQL queries
  • Walk through how SQL injection works and how it is prevented
Week 6

Integration and Practice Testing

  • Take timed practice sets covering all six areas
  • Revisit every domain where you missed questions

For a one-page recap to use alongside this schedule, try the CHS-CY1 Cheat Sheet 2026: One-Page Review of Must-Know Facts. When you reach Week 6, the CHS-CY1 practice tests are a convenient way to simulate the multiple-choice format under time pressure.

Where Candidates Lose Points

On a foundational exam, mistakes usually come from imprecision rather than lack of knowledge. Watch for these patterns:

  • Confusing the CIA Triad components. Confidentiality is about preventing unauthorized disclosure, integrity about preventing unauthorized change, and availability about keeping systems accessible. Scenario questions often hinge on picking the right one.
  • Mixing up Caesar and Vigenere. One uses a single fixed shift; the other uses a repeating keyword. Know which weakness applies to which.
  • Blurring IPv4 and IPv6. Be able to state what distinguishes them and why the newer version was introduced.
  • Treating phishing and ransomware as interchangeable. Phishing is a deception technique often used to deliver or enable other attacks; ransomware is malware that holds data hostage.
  • Skimming the legal-versus-illegal hacking material. These questions turn on authorization and intent, so read the scenario for who gave permission.
  • Underestimating the SQL material. Candidates with no database exposure sometimes skip it. A small amount of practice here is a cheap way to secure points.
Difficulty in perspective: The exam is introductory, but breadth is the real challenge, since six distinct areas are tested without published weights. For an honest look at how candidates experience it, read How Hard Is the CHS-CY1 Exam? Complete Difficulty Guide 2026. Pass-rate figures are not published in the sources this guide uses, so the article on CHS-CY1 Pass Rate 2026: What the Data Shows is best read for context on what is and is not known.

Exam-Day Approach for 45 Questions in 90 Minutes

With roughly two minutes available per question, you can afford to read carefully. A simple approach works well for a multiple-choice exam of this size:

  1. Do a fast first pass. Answer what you know immediately and mark anything that needs more thought.
  2. Eliminate before choosing. On multiple-choice items, ruling out clearly wrong options often leaves two plausible answers, improving your odds on harder questions.
  3. Re-read scenario questions. Words such as "authorized," "integrity," or "client" can flip the correct answer.
  4. Use leftover time to revisit marked questions, not to second-guess answers you were confident about.

Since the test is delivered online and timed, confirm your technical setup ahead of time and plan a quiet block of uninterrupted time. Scheduling details and testing windows are covered in CHS-CY1 Exam Dates 2026: Testing Windows, Deadlines & Scheduling, and the official CodeHS certification page remains the authority for current availability.

Who Benefits From This Credential

CHS-CY1 is positioned as a foundational certification, which makes it a natural fit for students beginning a cybersecurity pathway, educators looking to validate their classroom content, and career changers who want a structured first milestone. It signals familiarity with core security concepts rather than job-ready specialization, so it is best viewed as a starting point and a way to demonstrate initiative.

Credentials issued through CodeHS expire after 10 years, so the certification holds its value over a long horizon. If you are weighing whether the time investment makes sense for your goals, Is the CHS-CY1 Certification Worth It? Complete ROI Analysis 2026 lays out the considerations, and CHS-CY1 Jobs discusses where the credential fits in early-career paths. Because salary figures are not published for this credential, treat any specific earnings claims you encounter with caution and see CHS-CY1 Salary Guide 2026: Complete Earnings Analysis for a grounded discussion.

Finally, this guide scopes itself to Level 1 only. Cybersecurity Level 2 topics are a separate certification and are not part of what you need to learn here, so avoid spending study time on advanced material that will not appear on this exam.

Frequently Asked Questions

How many questions are on the CHS-CY1 exam and how long do I have?

The exam contains 45 multiple-choice questions, and CodeHS states it is timed at 90 minutes. It is delivered online as a timed exam.

What score do I need to pass?

CodeHS states the passing score is 60% for all of its certification exams except Java. On a 45-question exam, that means answering at least 27 questions correctly.

Are there prerequisites for CodeHS Cybersecurity Level 1?

No prerequisites are required. CodeHS does recommend its Fundamentals of Cybersecurity course as preparation, since it aligns closely with the topics the exam covers.

What happens if I need to retake the exam?

CodeHS requires a new voucher for each exam attempt, so a retake means obtaining another voucher. Because of this, thorough preparation before your first attempt is worthwhile.

Which domain should I study first?

Start with Cybersecurity Essentials, since concepts like the CIA Triad and common attacks underpin the other five areas. CodeHS publishes no domain weights, so give all six areas meaningful attention rather than skipping any.

Ready to pass your CHS-CY1 exam?

Put this into practice with free CHS-CY1 questions across every exam domain.