- CHS-CY1 is CodeHS Cybersecurity Level 1: a 45-question multiple-choice, online timed exam covering six content domains.
- CodeHS lists a 90-minute time limit and a 60% passing score for certification exams other than Java.
- No prerequisites exist, but CodeHS recommends its Fundamentals of Cybersecurity course as preparation.
- Each attempt requires a new voucher, and the credential expires after 10 years.
What CHS-CY1 Actually Is
CHS-CY1 is the exam code for the CodeHS Cybersecurity Level 1 Certification. It is an entry-level credential issued by CodeHS, the computer science education platform widely used in middle schools, high schools, and introductory college settings. The exam checks whether a learner has absorbed the foundational vocabulary, concepts, and habits of mind that define beginning cybersecurity literacy.
This is not a professional security certification in the vein of vendor or industry-body credentials aimed at working practitioners. It is a Level 1 credential designed around foundational knowledge: what ransomware and phishing are, how a Caesar cipher works, what a DNS hierarchy does, why SQL injection is dangerous, and how to behave responsibly online. That scope is the key to understanding both how to prepare and what to expect from the credential afterward.
If you are looking for shorter definitional explainers, the site also covers What Is CHS-CY1? and What Does CHS-CY1 Stand For?. This article goes deeper into structure, content, and practical decisions.
Who Issues It and What It Signals
CodeHS publishes the exam overview and a general Certifications FAQ on its help center. Those two documents are the authoritative sources for format, scoring, and policy, and they are the basis for every procedural fact in this article. Because CodeHS controls both the curriculum and the exam, the certification is tightly aligned with its own Fundamentals of Cybersecurity course, which CodeHS recommends for preparation.
What does holding the credential signal? Primarily, that you have demonstrated broad foundational awareness across six topic areas under timed conditions. It signals readiness to continue into more advanced study, such as CodeHS Cybersecurity Level 2, and it gives students a concrete, verifiable artifact of their learning. For a deeper look at whether that tradeoff makes sense for you, see Is the CHS-CY1 Certification Worth It?
Exam Format and Scoring Rules
The format is straightforward, which is part of the appeal for beginners. Here is what CodeHS states:
| Feature | CHS-CY1 Detail |
|---|---|
| Question count | 45 multiple-choice questions |
| Delivery | Online timed exam |
| Time limit | 90 minutes (per the CodeHS Certifications FAQ) |
| Passing score | 60% (applies to all CodeHS certification exams except Java) |
| Prerequisites | None |
| Credential lifespan | Expires after 10 years |
| Domain weights | Not published; six topic headings only |
Two practical implications follow. First, 90 minutes for 45 questions gives you roughly two minutes per question, which is generous for a multiple-choice exam. Time pressure is rarely the main risk; careless reading is. Second, because CodeHS does not publish percentage weights for the six topics, you should treat all six as fair game and avoid betting on a single domain. The detailed scoring math is covered in CHS-CY1 Passing Score 2026.
The Six Content Domains in Detail
CodeHS organizes the exam around six "Topics & Concepts Covered" headings. Below is each one with the specific subtopics a candidate should be ready to explain. For an even more granular walkthrough, read the complete guide to all 6 content areas.
Domain 1: Cybersecurity Essentials
This is the conceptual front door of the exam. Expect questions that test whether you can recognize threats and reason about ethics and law.
- Ransomware and phishing: know how each attack works and how to recognize or defend against it.
- Internet of Things: understand why connected everyday devices expand the attack surface.
- The CIA Triad: be able to map a scenario to confidentiality, integrity, or availability.
- Cyber ethics, credit and copyright: attribution, licensing, and responsible use of others' work.
- Legal vs. illegal hacking: distinguish authorized, permission-based testing from unauthorized access.
Domain 2: Cryptography
This domain is the most "hands-on" conceptually, because questions often ask you to reason through a cipher rather than recall a definition.
- Basic cryptography: the idea of encrypting and decrypting messages.
- Caesar cipher: a fixed-shift substitution cipher; practice shifting letters by hand.
- Vigenere cipher: uses a keyword to vary the shift, making it stronger than a single fixed shift.
- Code breaking, brute force, and frequency analysis: understand why a small key space is weak and how letter frequencies expose simple ciphers.
Domain 3: System Administration
This domain covers the software side of keeping systems usable and safe.
- Operating systems and browsers: their roles and security-relevant features.
- Software and software licenses: what different licenses permit and restrict.
- Application security: basic practices for protecting applications.
- System administration and the command line: what administrators do and why text-based interfaces matter.
Domain 4: IT Concepts
Networking fundamentals show up here, and they reward conceptual clarity over memorization.
- Internet addresses, IPv4 and IPv6: why two address formats exist and how they differ in size.
- DNS hierarchy: how names resolve to addresses through layered servers.
- Routing, packets, and protocols: how data is broken up, addressed, and moved across networks.
Domain 5: IT Infrastructure
The hardware and networking side of the picture.
- Internal components and peripheral devices: what lives inside a computer versus what plugs into it.
- Network devices, network options, and network communication: how devices connect and exchange data.
- Storage options and network management: choosing and administering storage and connectivity.
Domain 6: Digital Safety and Data Security
This domain blends personal safety with a first taste of data-layer security.
- Digital footprint, cyberbullying, and internet safety: behavior and awareness topics.
- Clients and servers: the request-and-response model of the web.
- SQL queries and SQL injection: understand basic queries and why unsanitized input lets attackers manipulate a database.
- Developer tools: what browser developer tools reveal about a page.
Key Takeaway
The domains span three very different skill types: conceptual awareness (Domains 1 and 6), procedural reasoning (Domains 2 and 6's SQL), and technical vocabulary (Domains 3, 4, and 5). Study each type differently rather than using one method for everything.
Vouchers, Attempts, and Expiration
CodeHS handles exam access through vouchers. The rule that matters most: each exam attempt requires a new voucher. A failed attempt does not give you an automatic retry; you will need another voucher before sitting the exam again. That makes first-attempt preparation more valuable than it might seem, which is why the CHS-CY1 study guide emphasizes passing on the first try.
CodeHS also states that certification credentials expire after 10 years. For a Level 1 learner, that is a long runway, but it is worth recording the date you earned it.
Specific fee amounts are not covered in the official sources used for this article, so treat any dollar figure you see elsewhere with caution and verify it with CodeHS or your instructor. Our cost breakdown explains how to think about the pricing question, and the exam dates guide covers scheduling considerations. For eligibility questions, see CHS-CY1 Requirements.
Who Should Take It
Since there are no prerequisites, the audience is broad. The credential fits best for:
- High school and middle school students completing a CodeHS cybersecurity pathway who want a verifiable result.
- Beginners exploring a career path who want a structured, low-stakes introduction to security concepts.
- Teachers and advisors who need a benchmark for student learning in an introductory cybersecurity course.
- Self-directed learners who want to confirm they have the basics before moving to Level 2 or other study.
It is a weaker fit for experienced IT professionals seeking a hiring-grade credential, since the exam is deliberately foundational. If you want to gauge how demanding it is relative to your background, read How Hard Is the CHS-CY1 Exam?
What the Credential Does and Does Not Do for Careers
Be realistic here. CHS-CY1 is a foundational, education-oriented credential. It can strengthen a student's portfolio, college applications, or résumé by showing early initiative in a high-demand field. It can help a learner confirm interest before investing in more advanced certifications or degrees.
What it does not do is function as a standalone ticket into a security job. Employers filling security roles typically look for hands-on experience and more advanced credentials. The honest framing is that CHS-CY1 is a starting point, a first documented step. If you are curious about the career landscape, our pages on CHS-CY1 jobs and the salary guide discuss that context qualitatively, without inflating expectations.
Skills the exam builds are still genuinely useful: recognizing phishing, understanding the CIA Triad, reasoning about encryption, and grasping why SQL injection works are all real foundations that carry into later study.
A Domain-by-Domain Preparation Sequence
Rather than a generic schedule, sequence your study by how the topics build on each other. A plausible four-week order:
Foundations: Domain 1 and Domain 6 (awareness topics)
- Define ransomware, phishing, and IoT risk in your own words.
- Practice mapping scenarios to confidentiality, integrity, and availability.
- Review digital footprint, cyberbullying, and internet safety.
Cryptography: Domain 2 (hands-on reasoning)
- Encrypt and decrypt short messages with a Caesar cipher by hand.
- Work through a Vigenere example with a keyword.
- Explain why brute force and frequency analysis defeat weak ciphers.
Systems and networks: Domains 3, 4, and 5
- Compare operating systems, browsers, and software licenses.
- Trace how DNS resolves a name and how packets travel via routing.
- List internal components, peripherals, and network devices.
Data security and full review: Domain 6 (SQL) plus practice exams
- Read simple SQL queries and spot how injection alters them.
- Take timed practice tests on the main practice test site.
- Revisit weak domains, then use the one-page cheat sheet for a final pass.
The reasoning behind this order: awareness topics are the easiest on-ramp, cryptography rewards focused practice while your energy is fresh, the infrastructure domains are vocabulary-heavy and fit together as a block, and SQL injection benefits from coming after you understand clients, servers, and networks. If you want a fuller plan, the study guide expands on this approach, and CHS-CY1 training discusses the recommended course and practice resources.
When you are ready to test yourself, work through realistic questions at chscy1exam.com and review any missed topics against the domain list above.
Frequently Asked Questions
CHS-CY1 is the code for the CodeHS Cybersecurity Level 1 Certification, an entry-level cybersecurity credential issued by CodeHS. It covers six foundational topic areas and is taken as a timed online exam.
The exam has 45 multiple-choice questions. According to the CodeHS Certifications FAQ, it is timed at 90 minutes, which leaves roughly two minutes per question.
CodeHS states the passing score is 60% for all of its certification exams except Java. For a 45-question exam, that means answering a clear majority correctly, but the topic weights are not published, so prepare for all six domains.
No. CodeHS states there are no prerequisites. It does recommend the CodeHS Fundamentals of Cybersecurity course as preparation, since that course aligns closely with the exam content.
Yes, but each exam attempt requires a new voucher. Plan to use timed practice tests beforehand so you are not paying for a second voucher unnecessarily.
CodeHS states that certification credentials expire after 10 years, so earning CHS-CY1 gives you a long validity window as you continue studying toward more advanced topics.