- What "CHS-CY1 Training" Actually Means
- Know the Exam You Are Training For
- The Recommended Training Route
- Training Notes for Each of the Six Domains
- Hands-On Practice That Matches the Questions
- A Domain-Ordered Training Schedule
- Vouchers, Attempts, and Training Around Them
- After Training: Where the Credential Fits
- Frequently Asked Questions
- The CHS-CY1 exam is 45 multiple-choice questions, timed at 90 minutes, with a 60% passing score.
- CodeHS recommends its Fundamentals of Cybersecurity course as preparation; there are no formal prerequisites.
- Six content areas are tested, and CodeHS publishes no percentage weights, so train all six evenly.
- Each exam attempt requires a new voucher, so finish training before you redeem one.
What "CHS-CY1 Training" Actually Means
Searching for CHS-CY1 training can be confusing, because the phrase covers two different things: the instructional coursework that teaches cybersecurity fundamentals, and the exam-specific preparation that helps you convert that knowledge into correct answers on test day. This article treats both, but it is written specifically for the CodeHS Cybersecurity Level 1 (CHS-CY1) certification exam issued by CodeHS. It does not apply to any other credential that happens to share a similar acronym.
If you are still orienting yourself, the pages on what CHS-CY1 certification is and the CHS-CY1 requirements cover eligibility and scope. The short version: CodeHS states there are no prerequisites, so anyone can attempt the exam. Training is about readiness, not permission.
Know the Exam You Are Training For
Good training starts with understanding the target. The CodeHS Cybersecurity Level 1 exam is an online, timed exam made up of 45 multiple-choice questions. According to the CodeHS Certifications FAQ, all certification exams are timed at 90 minutes, which works out to two minutes per question. The passing score is 60% for all certification exams except Java, and Cybersecurity Level 1 is not the Java exam. For a deeper look at what that threshold means in practice, see the CHS-CY1 passing score breakdown.
| Exam Feature | CodeHS Cybersecurity Level 1 |
|---|---|
| Issuer | CodeHS |
| Question count | 45 multiple-choice questions |
| Delivery | Online, timed exam |
| Time limit | 90 minutes (per CodeHS FAQ) |
| Passing score | 60% |
| Prerequisites | None stated by CodeHS |
| Retakes | New voucher required for each attempt |
| Credential validity | Expires after 10 years |
Two things follow from this format. First, with 45 questions and a 60% bar, you need a solid majority of answers right, but you do not need perfection. Second, the time allowance is generous for multiple-choice, so your training should emphasize accuracy and conceptual clarity over speed drills. If you want to calibrate your expectations, the difficulty guide discusses what makes certain question types trickier than others.
The Recommended Training Route
CodeHS recommends its Fundamentals of Cybersecurity course as preparation for the Level 1 exam. This is the most direct training path because the course and the certification come from the same issuer, and the exam's topic list is built around the concepts that course introduces. Candidates who work through the coursework in order encounter the exam's vocabulary, scenarios, and tools the way the test writers frame them.
Self-paced learners, classroom students, and adult career-changers can all use the same route. The difference is mostly in structure: a classroom gives you a pacing guide, while independent learners need to build their own. The CHS-CY1 study guide lays out a full first-attempt plan if you want a more detailed framework.
Training Notes for Each of the Six Domains
CodeHS lists six Topics and Concepts Covered headings and publishes no percentage weights. That means you cannot safely skip a domain on the assumption that it counts for little. Plan to be competent in all six. The full breakdown lives in the exam domains guide; here is how to think about training for each one.
Domain 1: Cybersecurity Essentials
This is the conceptual foundation: the threats, principles, and ethics that frame everything else.
- Ransomware and phishing: know how each works, how victims are targeted, and how to recognize and prevent them
- Internet of Things: understand why connected devices expand the attack surface
- The CIA Triad: confidentiality, integrity, and availability, and how to map a scenario to the principle at risk
- Cyber ethics, credit and copyright, and legal vs. illegal hacking: expect scenario questions that test judgment, not just definitions
Domain 2: Cryptography
This domain rewards candidates who actually work through examples rather than only reading definitions.
- Basic cryptography and code breaking concepts
- Brute force attacks and why key length and complexity matter
- Frequency analysis and how it defeats simple substitution ciphers
- Caesar cipher and Vigenere cipher: be able to encrypt and decrypt by hand and explain why Vigenere resists simple frequency analysis better than Caesar
Domain 3: System Administration
Practical, tool-oriented knowledge about how computers and software are managed securely.
- Operating systems, software, and software licenses
- Application security and browser behavior
- System administration responsibilities
- The command line: know common navigation and file commands and what they accomplish
Domain 4: IT Concepts
How data finds its way across networks, which is the backbone of most network security reasoning.
- Internet addresses, IPv4 and IPv6, and how they differ
- The DNS hierarchy and what resolution accomplishes
- Routing and how packets move between networks
- Packets and protocols: what a packet contains and why protocols standardize communication
Domain 5: IT Infrastructure
The physical and logical building blocks of computing environments.
- Internal components and peripheral devices
- Network devices and storage options
- Network options, network communication, and network management
Domain 6: Digital Safety and Data Security
Where personal safety, web architecture, and introductory database security meet.
- Digital footprint, cyberbullying, and internet safety
- Clients and servers: the request and response model
- SQL queries and SQL injection: understand how a query is built and how unsanitized input lets an attacker alter it
- Developer tools: what browser developer tools reveal and why that matters for security
Hands-On Practice That Matches the Questions
Because the exam is multiple choice, it is tempting to train by memorizing definitions. That works for some items and fails on scenario questions. The better approach is to practice the skills underneath the terms, particularly in the three domains where doing beats reading.
Work the Ciphers by Hand
Take a short message, encrypt it with a Caesar shift, then decrypt it without the key by trying shifts. Do the same with a Vigenere keyword. Then take a longer encrypted passage and tally letter frequencies to see why frequency analysis cracks a simple substitution. After doing this once, questions about brute force, frequency analysis, and cipher differences become far easier to reason through.
Use the Command Line Until It Feels Routine
Open a terminal and practice listing directories, changing directories, viewing file contents, and creating or removing files. The goal is to recognize what a given command does when you see it in a question, and to predict its output.
Trace a Request From Client to Server
Pick a website and narrate what happens: the browser asks DNS for an address, the request travels as packets across routed networks, a server responds, and the browser renders the page. Then open your browser's developer tools and look at the network activity. This single exercise ties together Domains 4, 5, and 6.
Once your hands-on work is solid, move to timed practice. The CHS-CY1 practice test on this site lets you rehearse the multiple-choice format, and a second pass through your missed items will show which domains still need attention. The one-page cheat sheet is a useful final review once the underlying concepts make sense.
A Domain-Ordered Training Schedule
If you are self-directing, ordering your training by dependency saves time. Start with the vocabulary that everything else builds on, tackle the hands-on domains while you have energy, and save the integrative material for later weeks. Adjust the pacing to your own calendar; the sequence matters more than the exact duration.
Cybersecurity Essentials
- Learn the threat landscape: ransomware, phishing, IoT risks
- Master the CIA Triad and apply it to sample scenarios
- Review cyber ethics, copyright, and legal vs. illegal hacking
Cryptography
- Encrypt and decrypt with Caesar and Vigenere by hand
- Work a frequency analysis exercise end to end
- Explain brute force and why complexity defends against it
System Administration and IT Concepts
- Practice command line navigation and file operations
- Review operating systems, licenses, browsers, and application security
- Study IPv4 vs. IPv6, DNS hierarchy, routing, packets, and protocols
Infrastructure, Digital Safety, and Full Review
- Cover hardware, storage, network devices, and network management
- Study digital footprint, internet safety, clients and servers, SQL, and developer tools
- Take timed practice sets and revisit weak domains
Why this order? Cybersecurity Essentials gives you the framework for judging risk, so it comes first. Cryptography is the most procedural domain, and early practice builds confidence. System Administration and IT Concepts pair naturally because the command line and networking both involve understanding how machines communicate. Infrastructure and Digital Safety come last because they draw on everything earlier, particularly the client-server model and SQL injection, which depend on networking knowledge.
Vouchers, Attempts, and Training Around Them
One practical rule shapes how you should time your training: CodeHS requires a new voucher for each exam attempt. That means a failed attempt is not a free retry, so you gain real value from finishing your preparation before you redeem a voucher rather than treating the first sitting as a practice run.
CodeHS does not publish pass rates in the sources used for this article, so any claim you see online about how many candidates pass should be treated with caution. The pass rate article explains what is and is not known. Likewise, fee details are not stated in the official overview and FAQ referenced here, so check with CodeHS or your school or program for current voucher arrangements; the certification cost page walks through how to find that information. For scheduling questions, see the exam dates guide.
Key Takeaway
Treat your voucher as a finished-training milestone, not a study tool. Complete the Fundamentals of Cybersecurity course, score comfortably on timed practice across all six domains, and only then redeem your voucher for the official attempt.
After Training: Where the Credential Fits
CodeHS Cybersecurity Level 1 is an entry-level, foundational credential. It demonstrates that you understand core cybersecurity concepts, introductory cryptography, basic system administration, networking fundamentals, infrastructure, and digital safety. That makes it most useful for students and early-career learners who want a verified starting point, and for those exploring whether cybersecurity is a field they want to pursue.
Because it is a foundational credential, it is best understood as a stepping stone rather than a direct ticket to a specific role. If you are weighing whether the effort is justified, the worth-it analysis, the jobs overview, and the salary guide discuss how to think about the credential's value realistically. One practical advantage: CodeHS states that certification credentials expire after 10 years, so you will not face a frequent renewal cycle after earning it.
When you feel ready, run a few full-length sets on the practice exam to confirm you are consistently clearing the 60% line across every domain, not just your strongest ones.
Frequently Asked Questions
CodeHS recommends its Fundamentals of Cybersecurity course as preparation. There are no prerequisites, so you can attempt the exam without completing it, but the course aligns closely with the exam's six topic areas.
The exam contains 45 multiple-choice questions and is timed at 90 minutes. The passing score is 60%, which is the standard for all CodeHS certification exams except Java.
CodeHS lists six Topics and Concepts Covered headings but does not publish percentage weights. Because of that, the safest training plan is to prepare evenly across Cybersecurity Essentials, Cryptography, System Administration, IT Concepts, IT Infrastructure, and Digital Safety and Data Security.
Yes. CodeHS requires a new voucher for each exam attempt. This is a good reason to complete your training and practice fully before redeeming a voucher for your first try.
According to CodeHS, certification credentials expire after 10 years. That is a long validity window compared with credentials that require frequent renewal, though you should confirm current terms directly with CodeHS.