CHS-CY1 logo
Focused certification exam prep
Start practice

What Is CHS-CY1 Certification?

TL;DR
  • CHS-CY1 is CodeHS Cybersecurity Level 1: a 45-question multiple-choice, online timed exam covering six content domains.
  • CodeHS lists a 90-minute time limit and a 60% passing score for certification exams other than Java.
  • No prerequisites exist, but CodeHS recommends its Fundamentals of Cybersecurity course as preparation.
  • Each attempt requires a new voucher, and the credential expires after 10 years.

What CHS-CY1 Actually Is

CHS-CY1 is the exam code for the CodeHS Cybersecurity Level 1 Certification. It is an entry-level credential issued by CodeHS, the computer science education platform widely used in middle schools, high schools, and introductory college settings. The exam checks whether a learner has absorbed the foundational vocabulary, concepts, and habits of mind that define beginning cybersecurity literacy.

This is not a professional security certification in the vein of vendor or industry-body credentials aimed at working practitioners. It is a Level 1 credential designed around foundational knowledge: what ransomware and phishing are, how a Caesar cipher works, what a DNS hierarchy does, why SQL injection is dangerous, and how to behave responsibly online. That scope is the key to understanding both how to prepare and what to expect from the credential afterward.

If you are looking for shorter definitional explainers, the site also covers What Is CHS-CY1? and What Does CHS-CY1 Stand For?. This article goes deeper into structure, content, and practical decisions.

Who Issues It and What It Signals

CodeHS publishes the exam overview and a general Certifications FAQ on its help center. Those two documents are the authoritative sources for format, scoring, and policy, and they are the basis for every procedural fact in this article. Because CodeHS controls both the curriculum and the exam, the certification is tightly aligned with its own Fundamentals of Cybersecurity course, which CodeHS recommends for preparation.

What does holding the credential signal? Primarily, that you have demonstrated broad foundational awareness across six topic areas under timed conditions. It signals readiness to continue into more advanced study, such as CodeHS Cybersecurity Level 2, and it gives students a concrete, verifiable artifact of their learning. For a deeper look at whether that tradeoff makes sense for you, see Is the CHS-CY1 Certification Worth It?

Scope reminder: This article concerns Cybersecurity Level 1 only. Level 2 topics and the full recommended-course syllabus are separate things. Keep your preparation anchored to the six Level 1 topic headings rather than drifting into advanced material that will not appear on this exam.

Exam Format and Scoring Rules

The format is straightforward, which is part of the appeal for beginners. Here is what CodeHS states:

FeatureCHS-CY1 Detail
Question count45 multiple-choice questions
DeliveryOnline timed exam
Time limit90 minutes (per the CodeHS Certifications FAQ)
Passing score60% (applies to all CodeHS certification exams except Java)
PrerequisitesNone
Credential lifespanExpires after 10 years
Domain weightsNot published; six topic headings only

Two practical implications follow. First, 90 minutes for 45 questions gives you roughly two minutes per question, which is generous for a multiple-choice exam. Time pressure is rarely the main risk; careless reading is. Second, because CodeHS does not publish percentage weights for the six topics, you should treat all six as fair game and avoid betting on a single domain. The detailed scoring math is covered in CHS-CY1 Passing Score 2026.

The Six Content Domains in Detail

CodeHS organizes the exam around six "Topics & Concepts Covered" headings. Below is each one with the specific subtopics a candidate should be ready to explain. For an even more granular walkthrough, read the complete guide to all 6 content areas.

Domain 1: Cybersecurity Essentials

This is the conceptual front door of the exam. Expect questions that test whether you can recognize threats and reason about ethics and law.

  • Ransomware and phishing: know how each attack works and how to recognize or defend against it.
  • Internet of Things: understand why connected everyday devices expand the attack surface.
  • The CIA Triad: be able to map a scenario to confidentiality, integrity, or availability.
  • Cyber ethics, credit and copyright: attribution, licensing, and responsible use of others' work.
  • Legal vs. illegal hacking: distinguish authorized, permission-based testing from unauthorized access.

Domain 2: Cryptography

This domain is the most "hands-on" conceptually, because questions often ask you to reason through a cipher rather than recall a definition.

  • Basic cryptography: the idea of encrypting and decrypting messages.
  • Caesar cipher: a fixed-shift substitution cipher; practice shifting letters by hand.
  • Vigenere cipher: uses a keyword to vary the shift, making it stronger than a single fixed shift.
  • Code breaking, brute force, and frequency analysis: understand why a small key space is weak and how letter frequencies expose simple ciphers.

Domain 3: System Administration

This domain covers the software side of keeping systems usable and safe.

  • Operating systems and browsers: their roles and security-relevant features.
  • Software and software licenses: what different licenses permit and restrict.
  • Application security: basic practices for protecting applications.
  • System administration and the command line: what administrators do and why text-based interfaces matter.

Domain 4: IT Concepts

Networking fundamentals show up here, and they reward conceptual clarity over memorization.

  • Internet addresses, IPv4 and IPv6: why two address formats exist and how they differ in size.
  • DNS hierarchy: how names resolve to addresses through layered servers.
  • Routing, packets, and protocols: how data is broken up, addressed, and moved across networks.

Domain 5: IT Infrastructure

The hardware and networking side of the picture.

  • Internal components and peripheral devices: what lives inside a computer versus what plugs into it.
  • Network devices, network options, and network communication: how devices connect and exchange data.
  • Storage options and network management: choosing and administering storage and connectivity.

Domain 6: Digital Safety and Data Security

This domain blends personal safety with a first taste of data-layer security.

  • Digital footprint, cyberbullying, and internet safety: behavior and awareness topics.
  • Clients and servers: the request-and-response model of the web.
  • SQL queries and SQL injection: understand basic queries and why unsanitized input lets attackers manipulate a database.
  • Developer tools: what browser developer tools reveal about a page.

Key Takeaway

The domains span three very different skill types: conceptual awareness (Domains 1 and 6), procedural reasoning (Domains 2 and 6's SQL), and technical vocabulary (Domains 3, 4, and 5). Study each type differently rather than using one method for everything.

Vouchers, Attempts, and Expiration

CodeHS handles exam access through vouchers. The rule that matters most: each exam attempt requires a new voucher. A failed attempt does not give you an automatic retry; you will need another voucher before sitting the exam again. That makes first-attempt preparation more valuable than it might seem, which is why the CHS-CY1 study guide emphasizes passing on the first try.

CodeHS also states that certification credentials expire after 10 years. For a Level 1 learner, that is a long runway, but it is worth recording the date you earned it.

Specific fee amounts are not covered in the official sources used for this article, so treat any dollar figure you see elsewhere with caution and verify it with CodeHS or your instructor. Our cost breakdown explains how to think about the pricing question, and the exam dates guide covers scheduling considerations. For eligibility questions, see CHS-CY1 Requirements.

Why the voucher rule changes your strategy: Because a retake costs another voucher, do not treat the first sitting as a "practice run." Take a few full-length practice tests under timed conditions first, so the real attempt is your best one.

Who Should Take It

Since there are no prerequisites, the audience is broad. The credential fits best for:

  • High school and middle school students completing a CodeHS cybersecurity pathway who want a verifiable result.
  • Beginners exploring a career path who want a structured, low-stakes introduction to security concepts.
  • Teachers and advisors who need a benchmark for student learning in an introductory cybersecurity course.
  • Self-directed learners who want to confirm they have the basics before moving to Level 2 or other study.

It is a weaker fit for experienced IT professionals seeking a hiring-grade credential, since the exam is deliberately foundational. If you want to gauge how demanding it is relative to your background, read How Hard Is the CHS-CY1 Exam?

What the Credential Does and Does Not Do for Careers

Be realistic here. CHS-CY1 is a foundational, education-oriented credential. It can strengthen a student's portfolio, college applications, or résumé by showing early initiative in a high-demand field. It can help a learner confirm interest before investing in more advanced certifications or degrees.

What it does not do is function as a standalone ticket into a security job. Employers filling security roles typically look for hands-on experience and more advanced credentials. The honest framing is that CHS-CY1 is a starting point, a first documented step. If you are curious about the career landscape, our pages on CHS-CY1 jobs and the salary guide discuss that context qualitatively, without inflating expectations.

Skills the exam builds are still genuinely useful: recognizing phishing, understanding the CIA Triad, reasoning about encryption, and grasping why SQL injection works are all real foundations that carry into later study.

A Domain-by-Domain Preparation Sequence

Rather than a generic schedule, sequence your study by how the topics build on each other. A plausible four-week order:

Week 1

Foundations: Domain 1 and Domain 6 (awareness topics)

  • Define ransomware, phishing, and IoT risk in your own words.
  • Practice mapping scenarios to confidentiality, integrity, and availability.
  • Review digital footprint, cyberbullying, and internet safety.
Week 2

Cryptography: Domain 2 (hands-on reasoning)

  • Encrypt and decrypt short messages with a Caesar cipher by hand.
  • Work through a Vigenere example with a keyword.
  • Explain why brute force and frequency analysis defeat weak ciphers.
Week 3

Systems and networks: Domains 3, 4, and 5

  • Compare operating systems, browsers, and software licenses.
  • Trace how DNS resolves a name and how packets travel via routing.
  • List internal components, peripherals, and network devices.
Week 4

Data security and full review: Domain 6 (SQL) plus practice exams

The reasoning behind this order: awareness topics are the easiest on-ramp, cryptography rewards focused practice while your energy is fresh, the infrastructure domains are vocabulary-heavy and fit together as a block, and SQL injection benefits from coming after you understand clients, servers, and networks. If you want a fuller plan, the study guide expands on this approach, and CHS-CY1 training discusses the recommended course and practice resources.

When you are ready to test yourself, work through realistic questions at chscy1exam.com and review any missed topics against the domain list above.

Frequently Asked Questions

What does CHS-CY1 stand for?

CHS-CY1 is the code for the CodeHS Cybersecurity Level 1 Certification, an entry-level cybersecurity credential issued by CodeHS. It covers six foundational topic areas and is taken as a timed online exam.

How many questions are on the exam and how long do I have?

The exam has 45 multiple-choice questions. According to the CodeHS Certifications FAQ, it is timed at 90 minutes, which leaves roughly two minutes per question.

What score do I need to pass?

CodeHS states the passing score is 60% for all of its certification exams except Java. For a 45-question exam, that means answering a clear majority correctly, but the topic weights are not published, so prepare for all six domains.

Do I need any prerequisites or prior courses?

No. CodeHS states there are no prerequisites. It does recommend the CodeHS Fundamentals of Cybersecurity course as preparation, since that course aligns closely with the exam content.

Can I retake the exam if I do not pass?

Yes, but each exam attempt requires a new voucher. Plan to use timed practice tests beforehand so you are not paying for a second voucher unnecessarily.

How long does the certification last?

CodeHS states that certification credentials expire after 10 years, so earning CHS-CY1 gives you a long validity window as you continue studying toward more advanced topics.

Ready to pass your CHS-CY1 exam?

Put this into practice with free CHS-CY1 questions across every exam domain.