- What the CodeHS CHS-CY1 Exam Actually Is
- Format, Timing, Passing Score, and Voucher Rules
- The Six Content Areas You Must Master
- Why Cryptography Deserves Extra Hands-On Practice
- Networking and Infrastructure: Connecting the Dots
- SQL, Injection, and Digital Safety Questions
- A Six-Week Plan Built Around the Domains
- Where Candidates Lose Points
- Exam-Day Approach for 45 Questions in 90 Minutes
- Who Benefits From This Credential
- Frequently Asked Questions
- The exam has 45 multiple-choice questions, a 90-minute limit, and a 60% passing score per the CodeHS FAQ.
- Six content areas are tested, but CodeHS publishes no percentage weights, so prepare evenly across all six.
- Each attempt requires a new voucher, so a failed try means obtaining another one before retesting.
- Hands-on practice with Caesar and Vigenere ciphers, IP addressing, and SQL injection pays off on exam day.
What the CodeHS CHS-CY1 Exam Actually Is
CHS-CY1 is the CodeHS Cybersecurity Level 1 certification exam. It is issued by CodeHS, the education technology company behind a widely used library of computer science and cybersecurity courses for schools and independent learners. If you have landed on this page while searching for a different credential that happens to share the abbreviation, this guide covers only the CodeHS exam. For a broader orientation, see What Is CHS-CY1? and What Does CHS-CY1 Stand For?.
The certification is a foundational, entry-level credential. It validates that you understand the core vocabulary and concepts of cybersecurity, from ransomware and phishing to cryptography, networking basics, and SQL injection. It is not a deep technical certification, and it does not require prior experience. Understanding that framing shapes how you should study: the exam rewards breadth and conceptual clarity far more than deep tool-specific expertise.
CodeHS lists no formal prerequisites. The company does recommend its Fundamentals of Cybersecurity course as preparation, and that recommendation is worth taking seriously because the exam topics map to the kind of material that course introduces. You can read more about eligibility in CHS-CY1 Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Format, Timing, Passing Score, and Voucher Rules
Knowing the mechanics removes a layer of uncertainty before you ever sit down to test. Here is what the official CodeHS sources state:
| Exam Detail | What CodeHS States |
|---|---|
| Question count | 45 multiple-choice questions |
| Delivery | Online, timed exam |
| Time limit | 90 minutes |
| Passing score | 60% (applies to all CodeHS certification exams except Java) |
| Prerequisites | None required; Fundamentals of Cybersecurity course recommended |
| Retakes | A new voucher is required for each exam attempt |
| Credential validity | Certification credentials expire after 10 years |
A 60% threshold on 45 questions means you need to answer at least 27 correctly. That is a meaningful buffer, but not a license to skip an entire content area. Since the exam draws from six distinct domains, ignoring even one can cost you a large cluster of questions. Our dedicated breakdown, CHS-CY1 Passing Score 2026: Exactly What You Need to Pass, walks through the arithmetic in more detail.
One more point on timing: 90 minutes for 45 questions averages out to two minutes per question. For a multiple-choice exam at this level, that is generous. Pacing is rarely the problem; careless reading is.
The Six Content Areas You Must Master
The official exam overview lists six "Topics & Concepts Covered" headings. CodeHS does not publish percentage weights for them, so the safest strategy is balanced preparation with extra time on whichever area feels weakest. For an extended walkthrough, see CHS-CY1 Exam Domains 2026: Complete Guide to All 6 Content Areas. Below is a working summary of each.
Domain 1: Cybersecurity Essentials
This is the conceptual foundation. Expect questions on how threats work and on the ethical and legal frame around security work.
- Ransomware and phishing: how each attack operates and how users and organizations defend against them
- Internet of Things: why connected devices expand the attack surface
- The CIA Triad: confidentiality, integrity, and availability, and how to identify which principle a scenario violates
- Cyber ethics, credit and copyright, and the difference between legal and illegal hacking
Domain 2: Cryptography
The most hands-on conceptual area. You should be able to reason through a cipher, not just define it.
- Basic cryptography and code breaking
- Brute force and frequency analysis as attack approaches
- Caesar cipher and Vigenere cipher mechanics
Domain 3: System Administration
Everyday computing environments viewed through a security lens.
- Operating systems, software, and software licenses
- Application security and browsers
- System administration tasks and command line basics
Domain 4: IT Concepts
How data finds its way across networks.
- Internet addresses, IPv4 and IPv6
- DNS hierarchy and routing
- Packets and protocols
Domain 5: IT Infrastructure
The physical and logical building blocks of a computing environment.
- Internal components and peripheral devices
- Network devices, network options, and network communication
- Storage options and network management
Domain 6: Digital Safety and Data Security
Personal safety online combined with a first look at web-application security.
- Digital footprint, cyberbullying, and internet safety
- Clients and servers
- SQL queries and SQL injection
- Developer tools
Why Cryptography Deserves Extra Hands-On Practice
Most of the exam can be handled by reading and recall, but the cryptography domain rewards actually working a cipher by hand. Candidates who only memorize definitions tend to stumble when a question presents ciphertext and asks what a shift or key would produce.
Caesar cipher
The Caesar cipher shifts every letter by a fixed number of positions. Practice encrypting a short word with a shift of 3, then decrypting it by shifting back. Because the keyspace is tiny, brute force defeats it almost instantly: an attacker simply tries every possible shift. Be ready to explain why that weakness exists.
Vigenere cipher
The Vigenere cipher uses a repeating keyword, so different letters are shifted by different amounts. That defeats the simplest frequency analysis, because the same plaintext letter no longer always maps to the same ciphertext letter. Understand why it is stronger than Caesar, and why it is still breakable with enough ciphertext.
Frequency analysis and brute force
Frequency analysis exploits the fact that certain letters appear more often in natural language. Brute force simply tries every possibility. Know which cipher each technique is best suited to attack and why.
Networking and Infrastructure: Connecting the Dots
Domains 4 and 5 are best studied together because they describe the same system from two angles: IT Concepts covers how data moves, while IT Infrastructure covers the hardware and options that carry it.
Addressing and name resolution
Know the difference between IPv4 and IPv6, including why IPv6 exists. Be able to describe how DNS translates human-readable names into addresses and how its hierarchy is organized. Think of the trace of a single web request: name lookup, routing across networks, delivery in packets governed by protocols.
Hardware and network choices
For infrastructure, focus on what each component does and when you would choose it. Distinguish internal components from peripherals, compare storage options, and recognize the role of different network devices and network options. Questions here tend to be scenario-based: given a need, identify the appropriate component or approach.
Key Takeaway
Draw a single diagram that follows one web request from your browser to a server and back. Label the address, DNS lookup, routing hops, packets, and devices involved. If you can narrate that diagram, you have covered most of Domains 4 and 5.
SQL, Injection, and Digital Safety Questions
Domain 6 pairs two very different themes. The personal-safety half (digital footprint, cyberbullying, internet safety) is largely about recognizing good judgment. The technical half is where points are easier to lose.
SQL queries and SQL injection
You should be able to read a simple SQL query and understand what data it retrieves. From there, SQL injection becomes intuitive: it occurs when untrusted input is inserted into a query in a way that changes the query's meaning. Understand the basic idea of why this is dangerous and the general principle behind preventing it, namely treating user input as data rather than as part of the command.
Clients, servers, and developer tools
Be clear on the roles of clients and servers and how they exchange requests and responses. Developer tools in a browser let you inspect a page's behavior, and the exam expects you to recognize what they reveal and why that matters for both building and securing web content.
A Six-Week Plan Built Around the Domains
Because there is no published weighting, a plan that gives each domain its own focus week is a sensible default. The ordering below puts conceptual foundations first, then technical material, and saves integration for last. Adjust the pacing if you already know some areas well.
Cybersecurity Essentials
- Learn ransomware, phishing, and IoT risks with a real-world example for each
- Master the CIA Triad by classifying sample incidents
- Review ethics, copyright, and legal versus illegal hacking
Cryptography
- Work Caesar and Vigenere examples by hand
- Compare brute force with frequency analysis
System Administration
- Review operating systems, licenses, and browsers
- Practice basic command line navigation
IT Concepts and IT Infrastructure
- Trace a request through DNS, routing, and packets
- Match devices, storage, and network options to scenarios
Digital Safety and Data Security
- Read and explain simple SQL queries
- Walk through how SQL injection works and how it is prevented
Integration and Practice Testing
- Take timed practice sets covering all six areas
- Revisit every domain where you missed questions
For a one-page recap to use alongside this schedule, try the CHS-CY1 Cheat Sheet 2026: One-Page Review of Must-Know Facts. When you reach Week 6, the CHS-CY1 practice tests are a convenient way to simulate the multiple-choice format under time pressure.
Where Candidates Lose Points
On a foundational exam, mistakes usually come from imprecision rather than lack of knowledge. Watch for these patterns:
- Confusing the CIA Triad components. Confidentiality is about preventing unauthorized disclosure, integrity about preventing unauthorized change, and availability about keeping systems accessible. Scenario questions often hinge on picking the right one.
- Mixing up Caesar and Vigenere. One uses a single fixed shift; the other uses a repeating keyword. Know which weakness applies to which.
- Blurring IPv4 and IPv6. Be able to state what distinguishes them and why the newer version was introduced.
- Treating phishing and ransomware as interchangeable. Phishing is a deception technique often used to deliver or enable other attacks; ransomware is malware that holds data hostage.
- Skimming the legal-versus-illegal hacking material. These questions turn on authorization and intent, so read the scenario for who gave permission.
- Underestimating the SQL material. Candidates with no database exposure sometimes skip it. A small amount of practice here is a cheap way to secure points.
Exam-Day Approach for 45 Questions in 90 Minutes
With roughly two minutes available per question, you can afford to read carefully. A simple approach works well for a multiple-choice exam of this size:
- Do a fast first pass. Answer what you know immediately and mark anything that needs more thought.
- Eliminate before choosing. On multiple-choice items, ruling out clearly wrong options often leaves two plausible answers, improving your odds on harder questions.
- Re-read scenario questions. Words such as "authorized," "integrity," or "client" can flip the correct answer.
- Use leftover time to revisit marked questions, not to second-guess answers you were confident about.
Since the test is delivered online and timed, confirm your technical setup ahead of time and plan a quiet block of uninterrupted time. Scheduling details and testing windows are covered in CHS-CY1 Exam Dates 2026: Testing Windows, Deadlines & Scheduling, and the official CodeHS certification page remains the authority for current availability.
Who Benefits From This Credential
CHS-CY1 is positioned as a foundational certification, which makes it a natural fit for students beginning a cybersecurity pathway, educators looking to validate their classroom content, and career changers who want a structured first milestone. It signals familiarity with core security concepts rather than job-ready specialization, so it is best viewed as a starting point and a way to demonstrate initiative.
Credentials issued through CodeHS expire after 10 years, so the certification holds its value over a long horizon. If you are weighing whether the time investment makes sense for your goals, Is the CHS-CY1 Certification Worth It? Complete ROI Analysis 2026 lays out the considerations, and CHS-CY1 Jobs discusses where the credential fits in early-career paths. Because salary figures are not published for this credential, treat any specific earnings claims you encounter with caution and see CHS-CY1 Salary Guide 2026: Complete Earnings Analysis for a grounded discussion.
Finally, this guide scopes itself to Level 1 only. Cybersecurity Level 2 topics are a separate certification and are not part of what you need to learn here, so avoid spending study time on advanced material that will not appear on this exam.
Frequently Asked Questions
The exam contains 45 multiple-choice questions, and CodeHS states it is timed at 90 minutes. It is delivered online as a timed exam.
CodeHS states the passing score is 60% for all of its certification exams except Java. On a 45-question exam, that means answering at least 27 questions correctly.
No prerequisites are required. CodeHS does recommend its Fundamentals of Cybersecurity course as preparation, since it aligns closely with the topics the exam covers.
CodeHS requires a new voucher for each exam attempt, so a retake means obtaining another voucher. Because of this, thorough preparation before your first attempt is worthwhile.
Start with Cybersecurity Essentials, since concepts like the CIA Triad and common attacks underpin the other five areas. CodeHS publishes no domain weights, so give all six areas meaningful attention rather than skipping any.