- The CodeHS Cybersecurity Level 2 exam is 45 multiple-choice questions in 90 minutes, with a 60% passing score.
- Five domains: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.
- Official topics are published without percentage weights, so study all five domains rather than betting on one.
- Every attempt needs its own voucher; each voucher code is valid for one attempt only.
The Exam at a Glance
This page condenses the CodeHS Cybersecurity Level 2 certification (CHS-CY2) into one reviewable sheet. It covers the format, the five published domains, the term pairs that trip candidates up, and the voucher mechanics. For a slower, step-by-step approach, pair it with the full CHS-CY2 study guide. When you want to test recall under realistic conditions, use the CHS-CY2 practice tests.
| Item | What to Know |
|---|---|
| Issuer | CodeHS |
| Format | Online, timed, multiple-choice |
| Questions | 45 |
| Time limit | 90 minutes (a 90-minute timer runs during the exam) |
| Passing score | 60% |
| Prerequisites | None required; CodeHS recommends the Advanced Cybersecurity course |
| Access | One voucher per attempt; each code is valid for one attempt |
| Retakes | Allowed as needed, using new vouchers |
| Validity | Certification expires after 10 years |
Ninety minutes for 45 questions gives you two minutes per question on average, which is generous for a multiple-choice exam. The time limit is rarely the problem. The real risk is mixing up similar terms, which is why most of this cheat sheet is organized around distinctions. For a deeper look at the numbers, see the guides on the CHS-CY2 passing score and how hard the exam is.
Domain 1: Advanced Cryptography
Cryptography questions reward candidates who can sort concepts into the right bucket quickly. The published topics are block and transposition ciphers, asymmetric and symmetric encryption, public key cryptography, hash functions, and digital certificates.
Symmetric vs. Asymmetric Encryption
This is the most frequently tested split in the domain.
- Symmetric: one shared secret key encrypts and decrypts. It is fast and suited to bulk data, but the key distribution problem is the weakness.
- Asymmetric: a mathematically linked key pair, public and private. It solves key distribution but is slower, so it often protects the exchange of a symmetric key instead of bulk data.
- Public key cryptography: anyone can encrypt to your public key, and only your private key decrypts. Reverse the roles for digital signatures, where the private key signs and the public key verifies.
Block and Transposition Ciphers
Know what each one does to the plaintext.
- Block cipher: encrypts data in fixed-size chunks (blocks) rather than one character at a time.
- Transposition cipher: rearranges the positions of the characters without changing the characters themselves. Contrast it with a substitution cipher, which swaps characters for other characters.
- If a question describes letters being reordered by a rule, think transposition. If letters are replaced, think substitution.
Hash Functions and Digital Certificates
Hashing is not encryption, and the exam likes to test that boundary.
- Hash: a one-way function producing a fixed-length digest. You cannot reverse it to recover the original, which makes it the right tool for integrity checking and password storage.
- A changed input produces a different digest, so a mismatched hash signals tampering.
- Digital certificate: binds a public key to an identity and is vouched for by a trusted certificate authority. Certificates are how you trust that a public key really belongs to who claims it.
Domain 2: Advanced Networking
This is the broadest domain by topic count, covering network devices, access control, physical security, environmental controls, ports and protocols, wireless, private networks, and mobile device security. Breadth is the challenge here, so learn each item as a one-line definition plus its closest look-alike.
Network Devices: IDS, IPS, and UTM
- IDS (intrusion detection system): monitors and alerts. It watches, but does not block.
- IPS (intrusion prevention system): sits in the traffic path and can actively block or drop malicious traffic.
- UTM (unified threat management): bundles several security functions into one appliance rather than relying on separate boxes.
The classic question gives you a scenario and asks whether the device should only alert or should stop the traffic. Detect means IDS; prevent means IPS.
Access Control and Physical Security
- Access control: decides who or what may reach a resource, and what they may do once there.
- Biometrics: authentication based on a physical trait such as a fingerprint.
- Mantrap: a small vestibule with two interlocking doors, designed to stop tailgating and to hold one person at a time for verification.
- Environmental controls: protect equipment from its surroundings. Think cooling, humidity management, and fire suppression for server rooms.
Ports, Protocols, Wireless and Private Networks
TCP vs. UDP
Expect at least one transport-layer question.
- TCP: connection-oriented, with handshakes, acknowledgments, and reliable ordered delivery.
- UDP: connectionless and lightweight, trading reliability for speed and lower overhead.
Wireless and Private Network Concepts
- 802.11ac: a Wi-Fi standard. Be ready to recognize 802.11 designations as wireless LAN standards.
- DMZ: a buffer network between the internet and the internal network, hosting public-facing services so a compromise does not land directly on the inside.
- VPN: an encrypted tunnel across an untrusted network, extending a private network securely.
- MAC filtering: allows or denies devices by hardware address. It is a basic control and easy to spoof, so do not mistake it for strong security.
- Mobile device security: think screen locks, encryption, remote wipe, and controlling what apps and networks a device can reach.
Domain 3: Cyber Defense
Cyber Defense is about recognizing what you are looking at. The topics are threats, vulnerabilities, and exploits; malware types and prevention; network attacks; and internal attacks.
Threat, Vulnerability, Exploit
- Vulnerability: a weakness in a system, process, or person.
- Threat: something that could take advantage of that weakness.
- Exploit: the actual method or code used to take advantage of a vulnerability.
Malware Types
| Malware | Defining Trait |
|---|---|
| Trojan | Disguised as legitimate software; relies on the user to run it |
| Worm | Self-replicating; spreads across networks without needing a host file or user action |
| Rootkit | Hides its presence and maintains privileged, stealthy access |
Prevention themes recur across all of these: patching, up-to-date endpoint protection, least privilege, and cautious handling of attachments and downloads.
Network and Internal Attacks
- Cross-site scripting (XSS): injecting malicious script into a trusted web page so it runs in other users' browsers.
- DDoS: overwhelming a target with traffic from many sources to deny availability.
- Botnet: a network of compromised machines controlled remotely, commonly used to launch DDoS attacks.
- BIOS/UEFI: firmware-level components. Attacks here are dangerous because they sit below the operating system.
- DLP (data loss prevention): tools and policies that stop sensitive data from leaving the organization.
Domain 4: Documentation
Documentation is the domain candidates most often under-study, because it feels less technical. It is also the most memorizable, so it is a reliable source of points. The topics are change management, incident response plans, software licenses, and data policy, privacy and protection.
What Each Document Does
- Change management: a controlled process for requesting, reviewing, approving, testing, and recording changes, so updates do not introduce unplanned outages or vulnerabilities.
- Incident response plan: a prepared, documented procedure for handling a security incident. Know the general flow of preparing, detecting, containing, eradicating, recovering, and reviewing lessons learned.
- Software licenses: the legal terms for using software. Questions tend to test recognizing license types and the consequences of using software outside its terms.
- Data policy, privacy and protection: rules governing how data is collected, stored, shared, and protected, including handling of personal information.
A useful framing: change management prevents problems, the incident response plan limits damage when problems happen anyway, and data policy defines what must be protected in the first place.
Domain 5: Risk Management
Risk Management ties the exam together. The published topics are types of vulnerabilities, risk assessment, risk response, and penetration testing.
Risk Response Options
Memorize these four and what each one means in plain language.
- Avoid: stop doing the risky activity entirely.
- Mitigate (reduce): apply controls to lower the likelihood or impact.
- Transfer: shift the financial burden to another party, for example through insurance.
- Accept: acknowledge the risk and take no further action, usually when the cost of a control outweighs the exposure.
- Risk assessment: identifying assets, threats, and vulnerabilities, then judging likelihood and impact so you can prioritize.
- Penetration testing: an authorized, simulated attack that actively probes for exploitable weaknesses. The word "authorized" is the key difference between a pen test and an attack.
- Vulnerability types: be able to separate technical weaknesses (unpatched software, misconfiguration) from human and procedural ones (weak passwords, missing policies).
Key Takeaway
Risk questions usually hand you a scenario and ask which response fits. Look for the cost and control clues: insurance means transfer, discontinuing the activity means avoid, adding a safeguard means mitigate, and a documented decision to live with it means accept.
Confusable Pairs That Cost Points
Because the exam is multiple-choice, wrong answers are usually plausible neighbors of the right one. Drill these pairs until the distinction is automatic.
| Pair | The Distinction |
|---|---|
| IDS vs. IPS | Alerts only vs. actively blocks |
| Symmetric vs. asymmetric | One shared key vs. a public/private key pair |
| Hashing vs. encryption | One-way digest vs. reversible with a key |
| Transposition vs. substitution | Characters rearranged vs. characters replaced |
| TCP vs. UDP | Reliable and connection-oriented vs. fast and connectionless |
| Worm vs. trojan | Spreads on its own vs. disguised and user-executed |
| DDoS vs. botnet | The attack vs. the army of compromised machines behind it |
| Threat vs. vulnerability vs. exploit | What could strike vs. the weakness vs. the method used |
| Avoid vs. mitigate vs. transfer vs. accept | Stop it, reduce it, shift it, live with it |
Each of these pairs maps to material covered in more depth in the complete guide to all five CHS-CY2 content areas, which is the best next read if any row above felt shaky.
Vouchers, Retakes and Expiration
The administrative facts are short but worth knowing before you sit down, because they affect how you plan attempts.
- Vouchers: each exam attempt requires a voucher, and each voucher code is valid for one attempt. A used code cannot be reused.
- Retakes: you can retake the exam as needed, but each new attempt needs a new voucher. See the certification cost breakdown for how that affects budgeting.
- Prerequisites: none are required. CodeHS recommends the Advanced Cybersecurity course as preparation, which is guidance rather than a gate. Details are in the CHS-CY2 requirements guide.
- Expiration: earned certifications expire after 10 years.
- Level 1 is not a stand-in: exam topics are distinct from the recommended course curriculum, and Level 1 content should not replace the Level 2 topic list above.
Scheduling the Domains Across Four Weeks
If you want a lightweight plan, sequence the domains by how much each one builds on the last. Cryptography and networking supply vocabulary that the defense and risk domains reuse, so they go first.
Advanced Cryptography
- Lock in symmetric vs. asymmetric, hashing vs. encryption, and transposition vs. substitution
- Learn how digital certificates bind a key to an identity
Advanced Networking
- Build one-line definitions for IDS, IPS, UTM, DMZ, VPN, and MAC filtering
- Cover TCP vs. UDP, 802.11 wireless, physical security, and mobile device security
Cyber Defense and Documentation
- Match malware and attack types to their defining traits
- Memorize the roles of change management, incident response, licensing, and data policy
Risk Management and Mixed Review
- Practice the four risk responses against scenarios and review penetration testing
- Run timed mixed sets across all five domains and revisit misses
Week 4 is where timed practice matters most, since the real exam mixes domains rather than grouping them. Our practice test hub lets you rehearse that mixed, timed format before you spend a voucher.
Frequently Asked Questions
The exam has 45 multiple-choice questions and a 90-minute timer. It is delivered online, and the passing score is 60%. For the full scoring picture, read the passing score guide.
No. CodeHS publishes the exam topics for each of the five domains without percentage weights, so the safest approach is to prepare across Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management rather than favoring one.
There are no specific prerequisites. CodeHS recommends the Advanced Cybersecurity course for preparation, but it is a recommendation rather than a requirement. More on eligibility is in the requirements guide.
You can retake the exam as needed. Each attempt requires a new voucher because every voucher code is valid for one attempt only. Use your missed topics to guide targeted review before the next attempt.
Certifications earned expire after 10 years. If you are weighing whether that is worth the effort, the ROI analysis walks through the trade-offs.