CHS-CY2 logo
Focused certification exam prep
Start practice

CHS-CY2 Certification

TL;DR
  • The exam is online, timed at 90 minutes, and contains 45 multiple-choice questions.
  • A score of 60% is required to pass; each attempt needs its own voucher code.
  • Five domains are tested: cryptography, networking, cyber defense, documentation, and risk management.
  • No prerequisites exist, but CodeHS recommends its Advanced Cybersecurity course as preparation.

What the CodeHS Level 2 Cybersecurity Certification Actually Is

The CHS-CY2 certification is the second-tier cybersecurity credential issued by CodeHS, the computer science education platform widely used in secondary schools and introductory college programs. It validates that a student has moved beyond foundational security vocabulary and can reason about the mechanisms behind encryption, network defense, incident handling, and risk decisions. If you are still sorting out the terminology, our explainer on what CHS-CY2 certification is covers the naming and scope in plain language, and the overview at what CHS-CY2 stands for breaks down the acronym.

Unlike vendor credentials built for working IT staff, this exam is designed around a classroom-to-career pipeline. It is a proctor-light, online, multiple-choice assessment that rewards conceptual precision: knowing the difference between an IDS and an IPS, or why a hash function is not the same thing as encryption, matters far more than memorizing command syntax.

Scope reminder: This article concerns the CodeHS Cybersecurity Level 2 certification only. Details such as exam length, passing score, voucher rules, and expiration all come from CodeHS's published certification documentation and FAQ, which are the authoritative references for the exam.

Exam Format, Timing, and Scoring Mechanics

The structure is straightforward, which is part of why preparation should focus on content depth rather than test-day logistics.

FeatureCHS-CY2 Detail
DeliveryOnline, timed exam
Question count45 multiple-choice questions
Time limit90 minutes
Passing score60%
PrerequisitesNone required
Recommended preparationCodeHS Advanced Cybersecurity course
Credential validity10 years

What the Time Budget Means

Ninety minutes for 45 questions works out to a generous two minutes per item. That is enough time to read each scenario carefully, eliminate distractors, and flag a handful of uncertain questions for a second pass. Candidates who fail are rarely out of time; they are usually missing a concept. For a deeper look at how the difficulty plays out in practice, see how hard the CHS-CY2 exam really is.

Understanding the 60% Threshold

A 60% passing score means you can miss a meaningful number of questions and still pass, but it also means a weak domain can sink you if you ignore it entirely. Because CodeHS publishes topics without percentage weights, you cannot assume any domain is safe to skip. We unpack the arithmetic and strategy in our guide to the CHS-CY2 passing score.

No published weights: CodeHS lists the exam topics but does not attach percentage weights to them. Treat all five domains as fair game and balance your study time accordingly rather than betting on a favorite area.

Vouchers, Attempts, and Expiration

Registration mechanics differ from the typical "pay at a testing center" model. Each exam attempt requires a voucher, and each voucher code is valid for exactly one attempt. If you do not pass, you can retake the exam as needed, but each retake requires a new voucher. Practically, that means you should treat your first attempt as a real attempt rather than a diagnostic, and use practice material beforehand to find your gaps. Cost specifics and how vouchers are typically obtained through schools or programs are covered in our certification cost breakdown.

Once earned, the certification stays valid for 10 years, which is unusually long compared with many industry credentials that require renewal every two or three years. That long validity makes it a durable line item on a resume or college application. For eligibility questions, including the absence of formal prerequisites, see the CHS-CY2 requirements guide, and for scheduling considerations consult the exam dates and scheduling overview.

The Five Exam Domains in Detail

CodeHS organizes the Level 2 exam into five domains. Each is listed below with the exact topics CodeHS names. Our companion piece, the complete guide to all five CHS-CY2 content areas, goes further into each one.

Domain 1: Advanced Cryptography

The mathematics-light but concept-heavy foundation of the exam.

  • Block and transposition ciphers
  • Asymmetric and symmetric encryption
  • Public key cryptography
  • Hash functions
  • Digital certificates

Domain 2: Advanced Networking

The broadest domain by topic count, mixing infrastructure with physical and mobile security.

  • Network devices (IDS, IPS, UTM)
  • Access control
  • Physical security (biometrics, mantrap, etc.)
  • Environmental controls
  • Ports and protocols (TCP, UDP)
  • Wireless protocols (802.11ac, etc.)
  • Private networks (DMZ, VPN, MAC filtering)
  • Mobile device security

Domain 3: Cyber Defense

Recognizing threats and matching them to defenses.

  • Threats, vulnerabilities, and exploits
  • Malware types and prevention (Trojan, worm, rootkit, etc.)
  • Network attacks (cross-site scripting, DDoS, botnet, etc.)
  • Internal attacks (BIOS, UEFI, DLP)

Domain 4: Documentation

The organizational and policy side of security work.

  • Change management
  • Incident response plans
  • Software licenses
  • Data policy, privacy, and protection

Domain 5: Risk Management

Thinking like a security analyst rather than a technician.

  • Types of vulnerabilities
  • Risk assessment
  • Risk response
  • Penetration testing

Advanced Cryptography: What to Master

Cryptography is where students most often confuse similar-sounding ideas, so precision is the goal. Start by separating symmetric encryption (one shared key for both encryption and decryption) from asymmetric encryption (a mathematically linked key pair). Then connect each to its typical role: symmetric methods handle bulk data efficiently, while asymmetric methods solve the problem of exchanging keys and proving identity.

Ciphers Beneath the Modern Algorithms

The exam lists block ciphers and transposition ciphers explicitly. A transposition cipher rearranges the positions of characters without changing them, while a substitution approach replaces characters. A block cipher processes fixed-size chunks of data at a time. Expect questions that ask you to identify which category a described method falls into, or to apply a simple transposition to a short message.

Public Keys, Hashes, and Certificates

  • Public key cryptography: know which key encrypts for confidentiality and which key signs for authenticity, and why the private key must never be shared.
  • Hash functions: remember they are one-way, produce fixed-length output, and are used for integrity checks rather than for hiding data you intend to recover.
  • Digital certificates: understand that they bind a public key to an identity and are vouched for by a trusted authority.

Key Takeaway

Build a one-line contrast for each pair you might confuse: symmetric vs. asymmetric, encryption vs. hashing, and signing vs. encrypting. Most cryptography distractors on a multiple-choice exam exploit exactly these mix-ups.

Advanced Networking: Devices, Ports, and Physical Controls

This domain rewards breadth. Because it spans everything from packet-level protocols to the physical layout of a building, plan to review it in short, topic-by-topic passes.

Detection, Prevention, and Unified Defense

A frequent exam theme is distinguishing an intrusion detection system, which observes and alerts, from an intrusion prevention system, which can actively block traffic, and from a unified threat management appliance that bundles multiple protections in one device. Know the passive-versus-active distinction cold.

Ports, Protocols, and Wireless Standards

You should be able to contrast TCP, which is connection-oriented and reliable, with UDP, which is connectionless and faster but offers no delivery guarantee. For wireless, the exam references standards such as 802.11ac, so be comfortable recognizing the 802.11 family and the security trade-offs of different wireless configurations.

Private Networks and Segmentation

DMZ, VPN, and MAC filtering each solve a different problem. A DMZ isolates public-facing services from the internal network, a VPN protects traffic crossing an untrusted network, and MAC filtering restricts which devices may connect, though it is a weak control on its own because addresses can be spoofed.

Physical and Environmental Security

Candidates often underestimate this slice. Biometrics, mantraps, and similar entry controls appear alongside environmental controls, which protect equipment from heat, fire, and humidity. Mobile device security rounds out the domain, so review how portable devices create risks that fixed workstations do not.

Study angle: For every device or control in this domain, ask two questions: what threat does it stop, and what threat does it leave open? Exam distractors usually describe a real control applied to the wrong problem.

Cyber Defense, Documentation, and Risk Management

The last three domains share a theme: moving from individual technologies to organizational decision-making.

Cyber Defense: Name the Threat, Pick the Defense

Learn the behavioral signatures of each malware type. A worm self-replicates across networks, a Trojan disguises itself as legitimate software, and a rootkit hides its presence deep in a system. For network attacks, distinguish a DDoS attack from a botnet (the botnet is often the tool used to carry out the DDoS) and recognize cross-site scripting as an injection of malicious script into a trusted web page. The internal-attack topics, BIOS, UEFI, and DLP, shift focus to firmware-level threats and to data loss prevention controls that stop sensitive information from leaving an organization.

Documentation: The Paper Trail of Security

Change management, incident response plans, software licenses, and data policy may feel less technical, but they generate reliable points because the questions are definitional. Know the purpose of a change management process, the phases an incident response plan covers, why license compliance matters legally, and how data policy and privacy rules govern the handling of personal information.

Risk Management: Assess, Respond, Test

Risk questions test whether you can sequence the logic: identify vulnerabilities, assess likelihood and impact, choose a response, and validate controls through penetration testing. Be ready to distinguish common risk responses such as accepting, mitigating, transferring, or avoiding a risk, and to explain what a penetration test does and does not prove.

Key Takeaway

Documentation and Risk Management questions are usually scenario-based and wording-sensitive. Read the final sentence of each question first so you know whether it asks for the best control, the first step, or the most likely cause.

Why Level 1 Content Will Not Carry You

A common mistake is assuming that strong Level 1 knowledge covers Level 2. CodeHS is explicit that exam topics are distinct from the recommended course curriculum and should not be replaced by Level 1 content. Level 2 expects you to explain how block ciphers and public key systems work, to compare IDS, IPS, and UTM devices, and to reason through risk response decisions, none of which are satisfied by basic definitions alone.

ApproachLikely Outcome
Reviewing only introductory security vocabularyGaps in cryptography mechanics and risk reasoning
Studying the five Level 2 domains by nameAligned coverage of the published exam topics
Following the Advanced Cybersecurity course plus topic reviewStrongest match to CodeHS's own recommendation

The official published topic list is the best checklist you have. Pair it with a structured walkthrough such as our CHS-CY2 study guide and use the one-page cheat sheet for last-minute review.

A Domain-Sequenced Preparation Plan

Rather than a generic schedule, sequence your weeks by how the domains build on each other. Cryptography vocabulary reappears in networking (VPNs, certificates, wireless security), so it makes sense to start there.

Week 1

Advanced Cryptography

  • Contrast symmetric and asymmetric encryption
  • Practice transposition and block cipher identification
  • Review hash functions and digital certificates
Week 2

Advanced Networking

  • Compare IDS, IPS, and UTM
  • Memorize TCP and UDP behavior and key wireless standards
  • Review DMZ, VPN, MAC filtering, and physical controls
Week 3

Cyber Defense

  • Build a malware-type comparison table
  • Study XSS, DDoS, and botnet relationships
  • Cover BIOS, UEFI, and DLP
Week 4

Documentation and Risk Management

  • Walk through an incident response plan end to end
  • Practice risk assessment and response scenarios
  • Take timed practice sets covering all five domains

Finish by taking full-length timed sets that mirror the 45-question, 90-minute format. You can work through realistic questions on our CHS-CY2 practice test site, and our resource on CHS-CY2 training options outlines additional ways to structure preparation.

Where the Credential Fits in a Career Path

The CHS-CY2 certification is best understood as an early-career and student-stage signal. It demonstrates structured knowledge of core security concepts, which is valuable for students heading into computer science, information technology, or cybersecurity programs, and for those pursuing entry-level roles such as help desk, junior security analyst support, or IT support positions where security literacy is increasingly expected. It does not replace advanced industry certifications, but it can strengthen a college application or resume and give a candidate a credible foundation to build on.

If you are weighing the investment, our analysis of whether the certification is worth it walks through the trade-offs, and the discussion of CHS-CY2 jobs and the salary guide explain how employers and earnings relate to credentials like this one. We avoid quoting specific salary numbers here because outcomes depend heavily on location, experience, and the role itself.

Frequently Asked Questions

How many questions are on the CodeHS Cybersecurity Level 2 exam?

The exam contains 45 multiple-choice questions and is delivered online with a 90-minute timer. You need a score of 60% to pass.

Are there prerequisites for taking the exam?

No specific prerequisites are required. CodeHS does recommend its Advanced Cybersecurity course as preparation, and Level 1 content is not a substitute for the Level 2 exam topics.

Can I retake the exam if I do not pass?

Yes. Students can retake the exam as needed, but each attempt requires a new voucher because every voucher code is valid for only one attempt.

How long does the certification last?

Certifications earned through CodeHS expire after 10 years, which gives the credential a long useful life on a resume or application.

Which domain should I study first?

Most candidates benefit from starting with Advanced Cryptography because its concepts, such as certificates and public key systems, resurface in networking and risk topics. After that, move through networking, cyber defense, documentation, and risk management, then finish with timed practice across all five.

Ready to pass your CHS-CY2 exam?

Put this into practice with free CHS-CY2 questions across every exam domain.