- What the CodeHS Level 2 Cybersecurity Certification Actually Is
- Exam Format, Timing, and Scoring Mechanics
- Vouchers, Attempts, and Expiration
- The Five Exam Domains in Detail
- Advanced Cryptography: What to Master
- Advanced Networking: Devices, Ports, and Physical Controls
- Cyber Defense, Documentation, and Risk Management
- Why Level 1 Content Will Not Carry You
- A Domain-Sequenced Preparation Plan
- Where the Credential Fits in a Career Path
- Frequently Asked Questions
- The exam is online, timed at 90 minutes, and contains 45 multiple-choice questions.
- A score of 60% is required to pass; each attempt needs its own voucher code.
- Five domains are tested: cryptography, networking, cyber defense, documentation, and risk management.
- No prerequisites exist, but CodeHS recommends its Advanced Cybersecurity course as preparation.
What the CodeHS Level 2 Cybersecurity Certification Actually Is
The CHS-CY2 certification is the second-tier cybersecurity credential issued by CodeHS, the computer science education platform widely used in secondary schools and introductory college programs. It validates that a student has moved beyond foundational security vocabulary and can reason about the mechanisms behind encryption, network defense, incident handling, and risk decisions. If you are still sorting out the terminology, our explainer on what CHS-CY2 certification is covers the naming and scope in plain language, and the overview at what CHS-CY2 stands for breaks down the acronym.
Unlike vendor credentials built for working IT staff, this exam is designed around a classroom-to-career pipeline. It is a proctor-light, online, multiple-choice assessment that rewards conceptual precision: knowing the difference between an IDS and an IPS, or why a hash function is not the same thing as encryption, matters far more than memorizing command syntax.
Exam Format, Timing, and Scoring Mechanics
The structure is straightforward, which is part of why preparation should focus on content depth rather than test-day logistics.
| Feature | CHS-CY2 Detail |
|---|---|
| Delivery | Online, timed exam |
| Question count | 45 multiple-choice questions |
| Time limit | 90 minutes |
| Passing score | 60% |
| Prerequisites | None required |
| Recommended preparation | CodeHS Advanced Cybersecurity course |
| Credential validity | 10 years |
What the Time Budget Means
Ninety minutes for 45 questions works out to a generous two minutes per item. That is enough time to read each scenario carefully, eliminate distractors, and flag a handful of uncertain questions for a second pass. Candidates who fail are rarely out of time; they are usually missing a concept. For a deeper look at how the difficulty plays out in practice, see how hard the CHS-CY2 exam really is.
Understanding the 60% Threshold
A 60% passing score means you can miss a meaningful number of questions and still pass, but it also means a weak domain can sink you if you ignore it entirely. Because CodeHS publishes topics without percentage weights, you cannot assume any domain is safe to skip. We unpack the arithmetic and strategy in our guide to the CHS-CY2 passing score.
Vouchers, Attempts, and Expiration
Registration mechanics differ from the typical "pay at a testing center" model. Each exam attempt requires a voucher, and each voucher code is valid for exactly one attempt. If you do not pass, you can retake the exam as needed, but each retake requires a new voucher. Practically, that means you should treat your first attempt as a real attempt rather than a diagnostic, and use practice material beforehand to find your gaps. Cost specifics and how vouchers are typically obtained through schools or programs are covered in our certification cost breakdown.
Once earned, the certification stays valid for 10 years, which is unusually long compared with many industry credentials that require renewal every two or three years. That long validity makes it a durable line item on a resume or college application. For eligibility questions, including the absence of formal prerequisites, see the CHS-CY2 requirements guide, and for scheduling considerations consult the exam dates and scheduling overview.
The Five Exam Domains in Detail
CodeHS organizes the Level 2 exam into five domains. Each is listed below with the exact topics CodeHS names. Our companion piece, the complete guide to all five CHS-CY2 content areas, goes further into each one.
Domain 1: Advanced Cryptography
The mathematics-light but concept-heavy foundation of the exam.
- Block and transposition ciphers
- Asymmetric and symmetric encryption
- Public key cryptography
- Hash functions
- Digital certificates
Domain 2: Advanced Networking
The broadest domain by topic count, mixing infrastructure with physical and mobile security.
- Network devices (IDS, IPS, UTM)
- Access control
- Physical security (biometrics, mantrap, etc.)
- Environmental controls
- Ports and protocols (TCP, UDP)
- Wireless protocols (802.11ac, etc.)
- Private networks (DMZ, VPN, MAC filtering)
- Mobile device security
Domain 3: Cyber Defense
Recognizing threats and matching them to defenses.
- Threats, vulnerabilities, and exploits
- Malware types and prevention (Trojan, worm, rootkit, etc.)
- Network attacks (cross-site scripting, DDoS, botnet, etc.)
- Internal attacks (BIOS, UEFI, DLP)
Domain 4: Documentation
The organizational and policy side of security work.
- Change management
- Incident response plans
- Software licenses
- Data policy, privacy, and protection
Domain 5: Risk Management
Thinking like a security analyst rather than a technician.
- Types of vulnerabilities
- Risk assessment
- Risk response
- Penetration testing
Advanced Cryptography: What to Master
Cryptography is where students most often confuse similar-sounding ideas, so precision is the goal. Start by separating symmetric encryption (one shared key for both encryption and decryption) from asymmetric encryption (a mathematically linked key pair). Then connect each to its typical role: symmetric methods handle bulk data efficiently, while asymmetric methods solve the problem of exchanging keys and proving identity.
Ciphers Beneath the Modern Algorithms
The exam lists block ciphers and transposition ciphers explicitly. A transposition cipher rearranges the positions of characters without changing them, while a substitution approach replaces characters. A block cipher processes fixed-size chunks of data at a time. Expect questions that ask you to identify which category a described method falls into, or to apply a simple transposition to a short message.
Public Keys, Hashes, and Certificates
- Public key cryptography: know which key encrypts for confidentiality and which key signs for authenticity, and why the private key must never be shared.
- Hash functions: remember they are one-way, produce fixed-length output, and are used for integrity checks rather than for hiding data you intend to recover.
- Digital certificates: understand that they bind a public key to an identity and are vouched for by a trusted authority.
Key Takeaway
Build a one-line contrast for each pair you might confuse: symmetric vs. asymmetric, encryption vs. hashing, and signing vs. encrypting. Most cryptography distractors on a multiple-choice exam exploit exactly these mix-ups.
Advanced Networking: Devices, Ports, and Physical Controls
This domain rewards breadth. Because it spans everything from packet-level protocols to the physical layout of a building, plan to review it in short, topic-by-topic passes.
Detection, Prevention, and Unified Defense
A frequent exam theme is distinguishing an intrusion detection system, which observes and alerts, from an intrusion prevention system, which can actively block traffic, and from a unified threat management appliance that bundles multiple protections in one device. Know the passive-versus-active distinction cold.
Ports, Protocols, and Wireless Standards
You should be able to contrast TCP, which is connection-oriented and reliable, with UDP, which is connectionless and faster but offers no delivery guarantee. For wireless, the exam references standards such as 802.11ac, so be comfortable recognizing the 802.11 family and the security trade-offs of different wireless configurations.
Private Networks and Segmentation
DMZ, VPN, and MAC filtering each solve a different problem. A DMZ isolates public-facing services from the internal network, a VPN protects traffic crossing an untrusted network, and MAC filtering restricts which devices may connect, though it is a weak control on its own because addresses can be spoofed.
Physical and Environmental Security
Candidates often underestimate this slice. Biometrics, mantraps, and similar entry controls appear alongside environmental controls, which protect equipment from heat, fire, and humidity. Mobile device security rounds out the domain, so review how portable devices create risks that fixed workstations do not.
Cyber Defense, Documentation, and Risk Management
The last three domains share a theme: moving from individual technologies to organizational decision-making.
Cyber Defense: Name the Threat, Pick the Defense
Learn the behavioral signatures of each malware type. A worm self-replicates across networks, a Trojan disguises itself as legitimate software, and a rootkit hides its presence deep in a system. For network attacks, distinguish a DDoS attack from a botnet (the botnet is often the tool used to carry out the DDoS) and recognize cross-site scripting as an injection of malicious script into a trusted web page. The internal-attack topics, BIOS, UEFI, and DLP, shift focus to firmware-level threats and to data loss prevention controls that stop sensitive information from leaving an organization.
Documentation: The Paper Trail of Security
Change management, incident response plans, software licenses, and data policy may feel less technical, but they generate reliable points because the questions are definitional. Know the purpose of a change management process, the phases an incident response plan covers, why license compliance matters legally, and how data policy and privacy rules govern the handling of personal information.
Risk Management: Assess, Respond, Test
Risk questions test whether you can sequence the logic: identify vulnerabilities, assess likelihood and impact, choose a response, and validate controls through penetration testing. Be ready to distinguish common risk responses such as accepting, mitigating, transferring, or avoiding a risk, and to explain what a penetration test does and does not prove.
Key Takeaway
Documentation and Risk Management questions are usually scenario-based and wording-sensitive. Read the final sentence of each question first so you know whether it asks for the best control, the first step, or the most likely cause.
Why Level 1 Content Will Not Carry You
A common mistake is assuming that strong Level 1 knowledge covers Level 2. CodeHS is explicit that exam topics are distinct from the recommended course curriculum and should not be replaced by Level 1 content. Level 2 expects you to explain how block ciphers and public key systems work, to compare IDS, IPS, and UTM devices, and to reason through risk response decisions, none of which are satisfied by basic definitions alone.
| Approach | Likely Outcome |
|---|---|
| Reviewing only introductory security vocabulary | Gaps in cryptography mechanics and risk reasoning |
| Studying the five Level 2 domains by name | Aligned coverage of the published exam topics |
| Following the Advanced Cybersecurity course plus topic review | Strongest match to CodeHS's own recommendation |
The official published topic list is the best checklist you have. Pair it with a structured walkthrough such as our CHS-CY2 study guide and use the one-page cheat sheet for last-minute review.
A Domain-Sequenced Preparation Plan
Rather than a generic schedule, sequence your weeks by how the domains build on each other. Cryptography vocabulary reappears in networking (VPNs, certificates, wireless security), so it makes sense to start there.
Advanced Cryptography
- Contrast symmetric and asymmetric encryption
- Practice transposition and block cipher identification
- Review hash functions and digital certificates
Advanced Networking
- Compare IDS, IPS, and UTM
- Memorize TCP and UDP behavior and key wireless standards
- Review DMZ, VPN, MAC filtering, and physical controls
Cyber Defense
- Build a malware-type comparison table
- Study XSS, DDoS, and botnet relationships
- Cover BIOS, UEFI, and DLP
Documentation and Risk Management
- Walk through an incident response plan end to end
- Practice risk assessment and response scenarios
- Take timed practice sets covering all five domains
Finish by taking full-length timed sets that mirror the 45-question, 90-minute format. You can work through realistic questions on our CHS-CY2 practice test site, and our resource on CHS-CY2 training options outlines additional ways to structure preparation.
Where the Credential Fits in a Career Path
The CHS-CY2 certification is best understood as an early-career and student-stage signal. It demonstrates structured knowledge of core security concepts, which is valuable for students heading into computer science, information technology, or cybersecurity programs, and for those pursuing entry-level roles such as help desk, junior security analyst support, or IT support positions where security literacy is increasingly expected. It does not replace advanced industry certifications, but it can strengthen a college application or resume and give a candidate a credible foundation to build on.
If you are weighing the investment, our analysis of whether the certification is worth it walks through the trade-offs, and the discussion of CHS-CY2 jobs and the salary guide explain how employers and earnings relate to credentials like this one. We avoid quoting specific salary numbers here because outcomes depend heavily on location, experience, and the role itself.
Frequently Asked Questions
The exam contains 45 multiple-choice questions and is delivered online with a 90-minute timer. You need a score of 60% to pass.
No specific prerequisites are required. CodeHS does recommend its Advanced Cybersecurity course as preparation, and Level 1 content is not a substitute for the Level 2 exam topics.
Yes. Students can retake the exam as needed, but each attempt requires a new voucher because every voucher code is valid for only one attempt.
Certifications earned through CodeHS expire after 10 years, which gives the credential a long useful life on a resume or application.
Most candidates benefit from starting with Advanced Cryptography because its concepts, such as certificates and public key systems, resurface in networking and risk topics. After that, move through networking, cyber defense, documentation, and risk management, then finish with timed practice across all five.