CHS-CY1 logo
Focused certification exam prep
Start practice

What Is A CHS-CY1?

TL;DR
  • CHS-CY1 is the CodeHS Cybersecurity Level 1 certification exam, issued by CodeHS.
  • The exam has 45 multiple-choice questions, is timed at 90 minutes, and requires a 60% to pass.
  • Six content areas run from Cybersecurity Essentials through Digital Safety and Data Security, including SQL injection.
  • No prerequisites exist, and each attempt requires a new voucher.

The Short Answer: What a CHS-CY1 Actually Is

A CHS-CY1 is the CodeHS Cybersecurity Level 1 Certification Exam. It is an online, timed, multiple-choice assessment created by CodeHS to verify that a student or early learner understands the foundational concepts of cybersecurity. If you have seen the code "CHS-CY1" on a class roster, a certification dashboard, or a study resource, this is the credential it refers to.

The exam is built around entry-level knowledge. It does not ask you to run penetration tests or configure enterprise firewalls. Instead, it checks whether you can recognize a phishing attempt, explain the CIA Triad, decode a Caesar cipher, describe how DNS works, tell a client from a server, and spot the pattern behind a SQL injection. That breadth-over-depth design is what makes it a Level 1 credential.

For other angles on the same question, see our companion explainers on what CHS-CY1 is, what CHS-CY1 stands for, and the overall CHS-CY1 certification.

Who Issues It and Where It Fits

The certifying organization is CodeHS, an education technology company best known for computer science and coding curriculum used in middle schools, high schools, and some colleges. CodeHS publishes a family of certification exams, and Cybersecurity Level 1 is its entry-point exam in the cybersecurity track.

Because CodeHS is a curriculum provider as well as a certifier, the exam is designed to align with its own instructional material. CodeHS recommends the Fundamentals of Cybersecurity course as the preparation path. That alignment is one of the most useful facts for candidates: the exam is not an open-ended survey of every cybersecurity subject on the internet. It tests a defined set of topics, and those topics map to a defined set of learning content.

Scope reminder: This article and this site concern Cybersecurity Level 1 only. Level 2 topics and the full syllabus of the recommended course are separate matters. When you study, anchor on the six Level 1 topic headings listed below rather than pulling in advanced material.

What the Exam Looks Like

The format is straightforward, and that predictability is an advantage for anyone preparing.

FeatureCHS-CY1 Detail
IssuerCodeHS
Question count45 multiple-choice questions
DeliveryOnline timed exam
Time limit90 minutes
Passing score60%
PrerequisitesNone
RetakesNew voucher required for each attempt
Credential lifespanExpires after 10 years

Ninety minutes for 45 questions works out to a generous two minutes per question, so pacing is rarely the main obstacle. The harder part is breadth: six distinct content areas, each with its own vocabulary. Candidates who study only one or two areas deeply and skim the rest tend to get caught by questions from the neglected ones. For the exact threshold and what it means in practice, read our guide to the CHS-CY1 passing score.

CodeHS does not publish percentage weights for the six content areas. That means you should not assume any one domain counts for more than another. Treat all six as fair game and prepare evenly, then spend extra time on whichever one your practice results show is weakest.

The Six Content Areas, Explained

CodeHS lists the exam content under six "Topics & Concepts Covered" headings. Here is what each one asks of you. For a deeper walkthrough, see the full CHS-CY1 exam domains guide.

Domain 1: Cybersecurity Essentials

This is the conceptual foundation: the threats, ethics, and principles that frame everything else.

  • Ransomware and phishing: know how each attack works and how a user would recognize or avoid it.
  • Internet of Things: understand why connected everyday devices expand the attack surface.
  • The CIA Triad: be able to define confidentiality, integrity, and availability and match a scenario to the correct principle.
  • Cyber ethics, credit and copyright, and legal vs. illegal hacking: expect scenario questions about what is permitted, what requires authorization, and what constitutes misuse.

Domain 2: Cryptography

The most hands-on, puzzle-like domain, and often where candidates either gain easy points or lose them.

  • Basic cryptography and code breaking: the vocabulary of encryption and decryption.
  • Caesar cipher and Vigenere cipher: know how each shifts letters, how a key changes the result, and why one is stronger than the other.
  • Brute force and frequency analysis: understand how attackers break weak ciphers by trying every key or by studying letter patterns.

Domain 3: System Administration

The day-to-day management of computers and software.

  • Operating systems, browsers, and application security: what they do and how they are kept secure.
  • Software and software licenses: the difference between licensing models and why they matter.
  • Command line system: basic comfort with text-based commands and what they accomplish.

Domain 4: IT Concepts

How information moves across the internet.

  • Internet addresses, IPv4 and IPv6: what an address identifies and how the two versions differ.
  • DNS hierarchy: how a human-readable name resolves to an address.
  • Routing, packets, and protocols: how data is divided, directed, and governed by agreed rules.

Domain 5: IT Infrastructure

The physical and logical building blocks of computing environments.

  • Internal components and peripheral devices: what lives inside a computer and what plugs into it.
  • Network devices, network options, and network communication: the hardware and methods that connect systems.
  • Storage options and network management: where data lives and how networks are overseen.

Domain 6: Digital Safety and Data Security

Personal safety online meets the first taste of application-level security.

  • Digital footprint, cyberbullying, and internet safety: responsible, protective online behavior.
  • Clients and servers: the request-and-response relationship behind most web activity.
  • SQL queries and SQL injection: read a basic query and understand how unsanitized input lets an attacker manipulate a database.
  • Developer tools: what browser-based tools reveal about a page.

Vouchers, Retakes, and Credential Lifespan

CodeHS handles access to the exam through vouchers. A voucher is what authorizes a candidate to sit the exam, and the rule that matters most is that each exam attempt requires a new voucher. In other words, a failed attempt does not come with a free second try built in; a retake needs its own voucher.

There are no prerequisites. You do not need to have completed a prior course, held another certification, or reached a particular age or grade level to be eligible according to CodeHS. That openness is intentional for an entry-level exam. If you want the full eligibility picture, see our breakdown of the CHS-CY1 requirements.

Once earned, the credential is valid for 10 years before it expires. That is a long window compared with many industry certifications, though the field itself will have moved on considerably by then.

About fees and dates: The CodeHS sources we rely on do not publish a fee schedule on the certification overview page, and this site does not guess at one. For cost context, see our article on CHS-CY1 certification cost, and for scheduling information check CHS-CY1 exam dates. Always confirm current details with CodeHS directly.

Who Should Take It (and Who Hires for It)

Honesty matters here. CHS-CY1 is an entry-level, education-oriented credential. Its primary audience is students, particularly those in high school and early college pathways, and the teachers and programs guiding them. It is best understood as a verified, resume-ready signal that a learner has mastered the fundamentals of cybersecurity.

That shapes how you should think about careers. A Level 1 credential from CodeHS is not a substitute for the professional certifications that employers screen for in security analyst or network engineer postings. Instead, it serves as:

  • A concrete, third-party-verified accomplishment for a college application or scholarship essay.
  • Evidence of readiness for more advanced cybersecurity coursework, including CodeHS's Level 2 track.
  • A confidence-building first step before pursuing industry certifications later.
  • A way for schools and CTE programs to demonstrate measurable learning outcomes.

Because no salary or hiring data is published for this specific credential, we avoid quoting numbers. Our pieces on CHS-CY1 jobs, the CHS-CY1 salary guide, and whether the certification is worth it discuss realistic expectations in qualitative terms.

Keeping Scope Straight: Level 1 Only

Two scope boundaries are worth stating plainly.

First, the exam is Cybersecurity Level 1. It does not include Level 2 material. If you find yourself reading about advanced attack frameworks or deep network forensics, you have likely drifted beyond what this exam covers.

Second, the exam's content is defined by the six topic headings above, not by every lesson in the recommended course. The Fundamentals of Cybersecurity course is the suggested preparation route, but the official topic list is your most reliable guide to what appears on the test.

Finally, the "CHS-CY1" label on this site refers only to the CodeHS credential. Other certifications elsewhere may share similar-looking abbreviations, so be careful that any exam facts you collect, such as formats, fees, or passing marks, actually come from CodeHS and not from an unrelated program.

A Domain-by-Domain Prep Sequence

Because the six areas differ so much in style, sequencing helps. Here is one arrangement that builds from concepts to mechanics. It is a suggestion, not an official CodeHS schedule.

Week 1

Cybersecurity Essentials

  • Learn the CIA Triad until you can classify any scenario under it.
  • Distinguish phishing from ransomware by delivery method and goal.
  • Review ethics and legal vs. illegal hacking, since these are reasoning questions.
Week 2

Cryptography

  • Practice encoding and decoding with the Caesar cipher by hand.
  • Work through a Vigenere example to see how a keyword changes the shift.
  • Explain brute force and frequency analysis in your own words.
Week 3

IT Concepts and IT Infrastructure

  • Trace a request from a domain name through DNS to an IP address.
  • Compare IPv4 and IPv6 formats.
  • Sort hardware into internal components, peripherals, and network devices.
Week 4

System Administration, Digital Safety, and Review

  • Review command line basics, licensing models, and application security.
  • Study SQL queries, then see exactly how injection breaks them.
  • Take full practice sets and revisit your weakest domain.

The reasoning behind this order: Essentials gives you the vocabulary everything else leans on, Cryptography rewards hands-on repetition while it is fresh, the two IT domains pair naturally because networking concepts and hardware overlap, and the final week combines the remaining technical topics with timed practice. For a fuller plan, see the CHS-CY1 study guide and the one-page CHS-CY1 cheat sheet.

Key Takeaway

Do not just read about the Caesar and Vigenere ciphers or SQL injection. Work actual examples by hand. These are the topics where understanding the mechanism, not memorizing a definition, turns uncertain guesses into confident answers.

To gauge your readiness before booking an attempt, try the timed questions on our CHS-CY1 practice test, and if you are wondering how much effort to budget, our article on how hard the CHS-CY1 exam is puts the difficulty in perspective. You can also review what is known about the pass rate, though CodeHS does not publish an official figure.

Frequently Asked Questions

What does CHS-CY1 mean?

CHS-CY1 refers to the CodeHS Cybersecurity Level 1 Certification Exam, an online timed assessment of 45 multiple-choice questions covering foundational cybersecurity topics. See also what CHS-CY1 means.

How many questions are on the exam, and how long do I have?

The exam contains 45 multiple-choice questions and is timed at 90 minutes. A score of 60% is required to pass.

Are there prerequisites to take it?

No. CodeHS states there are no prerequisites, though it recommends the Fundamentals of Cybersecurity course as preparation.

What happens if I need to retake the exam?

Each exam attempt requires a new voucher, so a retake means obtaining another voucher before you sit the exam again.

How long does the credential last?

According to CodeHS, certification credentials expire after 10 years from the date earned.

Put simply, a CHS-CY1 is a focused, accessible, and well-defined first credential in cybersecurity. Learn its six content areas, practice the hands-on topics, and you will know exactly what the exam expects. For a related explainer, see what CHS-CY1 certification is, or explore CHS-CY1 training options.

Ready to pass your CHS-CY1 exam?

Put this into practice with free CHS-CY1 questions across every exam domain.