- CHS-CY1 is CodeHS Cybersecurity Level 1: a 45-question multiple-choice online timed exam.
- The exam is timed at 90 minutes, and the passing score is 60%.
- Six topic areas are tested, from Cybersecurity Essentials to Digital Safety and Data Security.
- There are no prerequisites, but CodeHS recommends its Fundamentals of Cybersecurity course.
What CHS-CY1 Actually Is
CHS-CY1 is the exam code for the CodeHS Cybersecurity Level 1 Certification, issued by CodeHS. It is an entry-level credential designed to verify that a student understands the foundations of cybersecurity: how threats like phishing and ransomware work, how basic encryption functions, how computers and networks are organized, and how to stay safe online.
The name matters because the acronym is easy to confuse with unrelated credentials. This article is about one thing only: the CodeHS exam taken through the CodeHS certification program. If you are looking for a quick definition of the code itself, our explainers on what CHS-CY1 stands for and the meaning of CHS-CY1 cover the naming in more detail.
Exam Format and Rules at a Glance
The structure of the exam is simple, which is one of its strengths for first-time certification candidates. Everything below comes from the official CodeHS certification overview and the CodeHS Certifications FAQ.
| Feature | CHS-CY1 Detail |
|---|---|
| Issuer | CodeHS |
| Question count | 45 multiple-choice questions |
| Delivery | Online timed exam |
| Time limit | 90 minutes |
| Passing score | 60% |
| Prerequisites | None |
| Recommended preparation | CodeHS Fundamentals of Cybersecurity course |
| Retakes | A new voucher is required for each attempt |
| Credential validity | Expires after 10 years |
With 45 questions in 90 minutes, you have roughly two minutes per question. That is generous for a multiple-choice exam, so pacing is rarely the problem. The real challenge is breadth: six different topic areas, each with its own vocabulary. For the exact cutoff and how it translates to question counts, see our breakdown of the CHS-CY1 passing score.
The Six Content Areas Explained
CodeHS publishes six "Topics & Concepts Covered" headings for the exam. It does not publish percentage weights for them, so you should treat all six as fair game and avoid betting on any single area. Here is what each one contains, using the official topic names.
Domain 1: Cybersecurity Essentials
The conceptual foundation of the whole exam. Expect questions that ask you to identify a threat or apply a principle.
- Ransomware and phishing: how each attack works and how to recognize it
- Internet of Things security concerns
- The CIA Triad: confidentiality, integrity, and availability
- Cyber ethics, credit and copyright, and legal vs. illegal hacking
Domain 2: Cryptography
The most hands-on conceptual area. You should be able to reason through simple ciphers, not just define them.
- Basic cryptography and code breaking
- Brute force attacks and frequency analysis
- The Caesar cipher and the Vigenere cipher, including why one is easier to break than the other
Domain 3: System Administration
How operating systems and software are managed and protected.
- Operating systems, software, and software licenses
- Application security and browsers
- System administration responsibilities and the command line
Domain 4: IT Concepts
The networking fundamentals that explain how data moves across the internet.
- Internet addresses, IPv4 and IPv6
- The DNS hierarchy
- Routing, packets, and protocols
Domain 5: IT Infrastructure
The physical and logical building blocks of computer systems and networks.
- Internal components and peripheral devices
- Network devices and network options
- Storage options, network communication, and network management
Domain 6: Digital Safety and Data Security
Personal safety online combined with an introduction to protecting data in applications.
- Digital footprint, cyberbullying, and internet safety
- Clients and servers
- SQL queries and SQL injection
- Developer tools
For a deeper walk through every sub-topic, read our complete guide to the six CHS-CY1 exam domains.
What the Questions Feel Like
Because every question is multiple choice, the exam rewards recognition and reasoning rather than recall of long definitions. The distinctive feature of this exam, compared with a purely vocabulary-based test, is that several topics invite you to apply a concept to a short scenario.
Scenario-style thinking
In Cybersecurity Essentials, you may be asked to match a described situation to a threat or to a CIA Triad property. A message that tricks a user into clicking a link points to phishing; a situation where data is altered without authorization is an integrity problem. Practice mapping scenarios to labels instead of memorizing definitions in isolation.
Working through a cipher
In Cryptography, expect to reason about how a Caesar shift or a Vigenere keyword transforms text, and why frequency analysis defeats simple substitution but struggles more against Vigenere. If you can explain in one sentence why a longer key makes brute force harder, you are in good shape.
Reading a query
In Digital Safety and Data Security, SQL appears at an introductory level. You should be able to read a basic SQL query and recognize how SQL injection abuses unvalidated input to change what a query does.
Wondering how demanding all of this is in practice? We cover that honestly in how hard the CHS-CY1 exam is.
Who Should Take It
CodeHS positions this certification as accessible: there are no prerequisites. That makes it a natural fit for several groups.
- Students in a CodeHS cybersecurity course who want a verifiable credential at the end of the class.
- Beginners exploring a technical career path who want a structured first milestone before attempting harder certifications.
- Teachers and programs that use certification as a measurable outcome for a cybersecurity curriculum.
If you are weighing whether to commit, our look at CHS-CY1 requirements explains eligibility in detail, and the worth-it analysis helps you decide whether the credential matches your goals.
Vouchers, Attempts, and Expiry
CodeHS handles access to certification exams through vouchers. The key rules from the official sources are:
- A voucher is required for each exam attempt. If you do not pass and want to try again, you will need a new voucher rather than reusing the first one.
- The exam is online and timed. Once you begin, the 90-minute clock governs your session, so start only when you can give it your full attention.
- The credential lasts 10 years. After that period, it expires.
Specific fees are not published in the official sources used for this article, so we will not quote a price here. Ask your teacher or program administrator how vouchers are distributed in your setting, and see our page on CHS-CY1 certification cost for how to think about the expense. For scheduling questions, our guide to CHS-CY1 exam dates covers what to check.
Key Takeaway
Because every retake needs a fresh voucher, treat your first attempt as the real one. Finish a full timed practice run before you redeem a voucher, and only schedule the exam once you are consistently clearing the 60% line in practice.
Where the Credential Fits in a Career
It is worth being realistic. CHS-CY1 is a foundational, entry-level certification. It signals that you have learned the core vocabulary and concepts of cybersecurity, which is valuable as a first credential on a resume, in a school or college application, or as evidence of initiative when pursuing internships and entry-level IT exposure.
It is not a substitute for the professional certifications that employers commonly require for dedicated security roles, and we will not pretend it carries a specific salary. Because no compensation data is published by CodeHS for this credential, we avoid quoting figures. If you want the nuanced picture, our articles on CHS-CY1 jobs and the CHS-CY1 salary guide discuss how entry-level credentials like this one contribute to a larger career path.
The practical value is in the skills you build while preparing: recognizing phishing, understanding how encryption and networks work, reading basic SQL, and thinking about digital footprint. Those carry forward into any technology path.
A Domain-Ordered Prep Plan
Since CodeHS publishes no weights, a balanced plan that gives every domain attention is the safest approach. The sequence below orders the domains so that earlier concepts support later ones: ethics and threats first, then the technical mechanics, then networking, then infrastructure, then the applied safety and SQL material.
Cybersecurity Essentials
- Learn the CIA Triad and map each attack type to the property it violates
- Review ransomware, phishing, and IoT risks
- Cover cyber ethics, copyright, and legal vs. illegal hacking
Cryptography
- Encrypt and decrypt by hand with the Caesar and Vigenere ciphers
- Explain brute force and frequency analysis in your own words
System Administration and IT Concepts
- Practice common command line tasks and review software licenses
- Trace a web request through DNS, IP addressing, routing, and packets
IT Infrastructure, Digital Safety, and Review
- Review hardware, storage, and network devices
- Study digital footprint, SQL queries, and SQL injection
- Finish with full timed practice exams under 90-minute conditions
You can compress or stretch this to fit your schedule. For a full method, see the CHS-CY1 study guide, and keep the CHS-CY1 cheat sheet handy for last-minute review. When you are ready to test yourself, try the CHS-CY1 practice tests to simulate the real format, and return to them after each week to confirm that the material is sticking.
Frequently Asked Questions
CHS-CY1 refers to the CodeHS Cybersecurity Level 1 Certification exam, issued by CodeHS. It covers foundational cybersecurity concepts across six topic areas.
The exam has 45 multiple-choice questions and is delivered as an online timed exam. According to the CodeHS FAQ, it is timed at 90 minutes.
The passing score is 60%. CodeHS applies this threshold to all of its certification exams except Java. Our passing score guide explains what that means in practice.
No. CodeHS states there are no prerequisites. It does recommend the CodeHS Fundamentals of Cybersecurity course as preparation, which aligns closely with the exam topics.
You can try again, but a new voucher is required for each exam attempt. Because of that, it is wise to complete several full timed practice exams before using your first voucher.
CodeHS states that certification credentials expire after 10 years, so the credential you earn remains valid for a decade.