- How the CodeHS Level 2 Exam Is Built
- Domain 1: Advanced Cryptography
- Domain 2: Advanced Networking
- Domain 3: Cyber Defense
- Domain 4: Documentation
- Domain 5: Risk Management
- Comparing the Five Domains Side by Side
- Sequencing Your Prep Around the Domains
- Vouchers, Retakes, and Expiration
- Where the Credential Fits Professionally
- Frequently Asked Questions
- The CodeHS Cybersecurity Level 2 exam has 45 multiple-choice questions, a 90-minute timer, and a 60% passing score.
- Five content areas are tested: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.
- CodeHS publishes the topics without percentage weights, so prepare for all five domains rather than guessing.
- Advanced Networking has the longest topic list, covering devices, physical security, protocols, wireless, private networks, and mobile security.
How the CodeHS Level 2 Exam Is Built
The CodeHS Cybersecurity Level 2 certification (CHS-CY2) is an online, timed exam delivered through CodeHS. You get 45 multiple-choice questions and a 90-minute timer, which works out to a comfortable two minutes per question on average. A score of 60% or higher earns the credential. If you want the exact math on what that means in questions answered correctly, see our breakdown of the CHS-CY2 passing score.
There are no formal prerequisites. CodeHS does recommend its Advanced Cybersecurity course as preparation, and that recommendation matters: the exam topics are distinct from the course curriculum, and the exam is not a rehash of Level 1 material. Candidates who assume that foundational concepts like basic password hygiene will carry them through tend to be surprised by the depth expected in cryptography and networking. For a full eligibility rundown, read CHS-CY2 requirements.
One detail shapes your entire study plan: CodeHS publishes the exam topics without percentage weights. Unlike some industry certifications that tell you exactly what share of questions come from each domain, this exam gives you five named content areas and a list of topics under each. Any site that claims to know the exact question distribution is guessing. The sensible response is to treat all five domains as fair game and to build breadth first, then depth where your practice results show gaps.
If you are still deciding whether the exam is within reach, our guide on how hard the CHS-CY2 exam is covers difficulty in more depth. This article focuses on what is actually tested.
Domain 1: Advanced Cryptography
Advanced Cryptography is the most conceptual domain, and it is where candidates who memorize vocabulary without understanding mechanics lose points. CodeHS lists five topic areas: block and transposition ciphers, asymmetric and symmetric encryption, public key cryptography, hash functions, and digital certificates.
Block and Transposition Ciphers
Expect questions that ask you to distinguish how ciphers transform data, not just what they are called.
- Know that a transposition cipher rearranges the positions of characters rather than substituting them.
- Understand that a block cipher encrypts data in fixed-size chunks, as opposed to a stream approach that processes data continuously.
- Be able to recognize which scenario calls for which style, since scenario-based questions are common in multiple-choice formats.
Symmetric vs. Asymmetric Encryption
This pairing is the backbone of the domain, and questions often test the tradeoffs.
- Symmetric encryption uses one shared key, which makes it fast but creates a key-distribution problem.
- Asymmetric encryption uses a key pair, which solves distribution but is slower for bulk data.
- Know why real systems often combine the two: asymmetric methods to exchange a key, symmetric methods to move the data.
Public Key Cryptography
Go beyond "there is a public key and a private key" and understand how each is used.
- Which key encrypts for confidentiality, and which key signs for authenticity.
- Why the private key must never be shared, and what a compromise of it means.
- How public key systems support secure communication between parties who have never met.
Hash Functions and Digital Certificates
These two topics connect to integrity and trust.
- A hash produces a fixed-length digest from input of any size and is designed to be one-way, not reversible.
- Hashes are used to verify integrity: a changed input produces a different digest.
- A digital certificate binds an identity to a public key and is vouched for by a trusted authority, which is what lets you trust a key you did not generate yourself.
A reliable way to study this domain is to make a comparison grid: for each concept, write what problem it solves, what it does not solve, and what it is commonly confused with. Hashing versus encryption is the classic confusion, since one is reversible with a key and the other is not.
Domain 2: Advanced Networking
Advanced Networking carries the longest topic list of the five domains, with eight distinct areas: network devices (IDS, IPS, UTM), access control, physical security (biometrics, mantrap, and similar), environmental controls, ports and protocols (TCP, UDP), wireless protocols (802.11ac and others), private networks (DMZ, VPN, MAC filtering), and mobile device security. Given the sheer breadth, give this domain more calendar time than any other.
Network Devices and Access Control
The three device acronyms in the official topic list are worth separating cleanly. An intrusion detection system (IDS) monitors and alerts; an intrusion prevention system (IPS) sits in line and can actively block; a unified threat management (UTM) appliance bundles multiple security functions into one device. A common question pattern gives you a scenario ("the device must alert but not interrupt traffic") and asks you to pick the right tool. Pair this with access control concepts, understanding how systems decide who gets in and what they can do once inside.
Physical Security and Environmental Controls
Many candidates expect a cybersecurity exam to be all software, but CodeHS explicitly lists physical security, including biometrics and mantraps, along with environmental controls. A mantrap is a small access-controlled space that admits one person at a time, defeating tailgating. Biometrics authenticate with a physical characteristic. Environmental controls cover the conditions that keep equipment running, such as temperature, humidity, and fire suppression in server spaces. These are lower-effort points if you study them deliberately.
Ports, Protocols, and Wireless
Know the behavioral difference between TCP and UDP: TCP is connection-oriented and reliable, UDP is connectionless and faster with no delivery guarantee. For wireless, the official list names 802.11ac as an example, so be comfortable with the idea that wireless standards differ in capability and that security protocols for Wi-Fi have evolved over time.
Private Networks and Mobile Devices
DMZ, VPN, and MAC filtering are all named explicitly. A DMZ is a buffer zone that exposes public-facing services without exposing the internal network. A VPN creates an encrypted tunnel across an untrusted network. MAC filtering allows or denies devices by hardware address, which is a weak control on its own because addresses can be spoofed. Mobile device security rounds out the domain, so think about the risks that come with devices that leave the building.
Key Takeaway
For every networking device or control, be able to answer three questions: what does it do, where does it sit, and what is its main weakness. That framing converts a long list of acronyms into answerable scenario questions.
Domain 3: Cyber Defense
Cyber Defense is the attacker-and-defender domain. CodeHS lists four areas: threats, vulnerabilities, and exploits; malware types and prevention (Trojan, worm, rootkit, and so on); network attacks (cross-site scripting, DDoS, botnet, and so on); and internal attacks (BIOS, UEFI, DLP).
Threats, Vulnerabilities, and Exploits
Learn the relationship among the three terms precisely, because exam writers like to test it.
- A vulnerability is a weakness.
- A threat is something that could take advantage of it.
- An exploit is the method or tool that actually takes advantage.
Malware Types and Prevention
The key skill is telling malware categories apart by behavior.
- A Trojan disguises itself as legitimate software.
- A worm self-replicates across networks without needing a host file.
- A rootkit hides its presence and maintains privileged access.
- For each type, pair it with a prevention measure so you can answer both "what is it" and "how do you stop it."
Network Attacks
Match each attack to its mechanism and its target.
- Cross-site scripting injects malicious script into pages that other users view.
- A DDoS attack overwhelms a service with traffic from many sources, often a botnet of compromised machines.
- Know the difference between attacks on availability and attacks on confidentiality or integrity.
Internal Attacks
This is the least intuitive group because it covers threats from inside or below the operating system.
- BIOS and UEFI are firmware layers, and attacks there are especially persistent because they run before the operating system loads.
- DLP, or data loss prevention, is a defensive control aimed at stopping sensitive data from leaving the organization.
Cyber Defense rewards pattern recognition. When you read a scenario describing symptoms, practice naming the attack category before you look at the answer choices. Our CHS-CY2 cheat sheet condenses many of these definitions into a quick-reference format for last-minute review.
Domain 4: Documentation
Documentation is the domain candidates most often underestimate. It covers four areas: change management, incident response plans, software licenses, and data policy, privacy, and protection. It feels less technical than cryptography or networking, but it is a core part of how real security teams operate, and the questions are usually answerable if you know the vocabulary and the logic of each process.
- Change management: The structured process for requesting, reviewing, approving, testing, and recording changes to systems. The point is to prevent unplanned changes from causing outages or opening vulnerabilities.
- Incident response plans: The documented procedure for what a team does when a security event occurs. Know that the plan exists to make response orderly and repeatable rather than improvised, and be familiar with the general phases: preparation, detection, containment, eradication, recovery, and review.
- Software licenses: Understand that software use is governed by license terms, and that violating them has legal and financial consequences. Be able to distinguish broad categories such as proprietary and open-source licensing.
- Data policy, privacy, and protection: The rules governing how data is collected, stored, shared, and protected, and why handling personal information carefully matters to both individuals and organizations.
Domain 5: Risk Management
The final domain ties the others together by asking how organizations decide what to protect and how. CodeHS lists four areas: types of vulnerabilities, risk assessment, risk response, and penetration testing.
Vulnerabilities and Risk Assessment
Know that vulnerabilities come in different kinds, including technical, physical, and human or procedural, and that risk assessment is the process of identifying assets, threats, and vulnerabilities and estimating the likelihood and impact of something going wrong. The central idea is that risk is not just "a bad thing could happen" but a combination of how likely it is and how much damage it would do.
Risk Response
Once a risk is assessed, an organization chooses how to respond. Be able to recognize the standard strategies: reducing (mitigating) the risk with controls, transferring it, for example through insurance or a third party, accepting it when the cost of action outweighs the exposure, and avoiding it by eliminating the activity that creates it. Scenario questions will describe a decision and ask you to name the strategy.
Penetration Testing
A penetration test is an authorized, simulated attack used to find weaknesses before real attackers do. Understand how it differs from a passive vulnerability scan: a pen test attempts to exploit weaknesses, while a scan identifies them. Authorization and scope are central. Testing without permission is not a pen test.
Key Takeaway
Risk Management is where the exam checks whether you can apply the other four domains to a decision. When you study a control from Networking or Cyber Defense, ask yourself which risk response it represents. That cross-linking makes this domain much easier.
Comparing the Five Domains Side by Side
Because no weights are published, this table is organized by what each domain asks of you, not by question counts.
| Domain | Topic Breadth | Main Skill Tested | Common Trap |
|---|---|---|---|
| Advanced Cryptography | 5 topic areas | Understanding how and why each method works | Confusing hashing with encryption |
| Advanced Networking | 8 topic areas | Matching devices, protocols, and controls to scenarios | Mixing up IDS, IPS, and UTM roles |
| Cyber Defense | 4 topic areas | Identifying attacks and malware by behavior | Treating worm, Trojan, and rootkit as interchangeable |
| Documentation | 4 topic areas | Knowing process order and purpose | Skipping it as "too easy" |
| Risk Management | 4 topic areas | Applying concepts to decisions | Confusing vulnerability scans with penetration tests |
Note that topic-area counts reflect how CodeHS lists the material, not how many exam questions each domain contributes. Use them as a rough guide to how much content you need to learn, not as a prediction of question distribution.
Sequencing Your Prep Around the Domains
The single most useful planning idea is to order domains by how much they depend on each other. Cryptography and Networking give you the vocabulary that Cyber Defense and Risk Management reuse, so they come first. Documentation is a good mid-plan confidence builder. A sample five-week sequence looks like this; adjust it to your own timeline using the broader advice in our CHS-CY2 study guide.
Advanced Cryptography
- Build the symmetric versus asymmetric comparison grid.
- Practice explaining hashes and certificates in your own words.
Advanced Networking
- Spend two weeks here because it has eight topic areas.
- Cover devices and access control first, then physical, ports, wireless, and private networks, then mobile security.
Cyber Defense and Documentation
- Pair each malware and attack type with its prevention.
- Learn the incident response phases and change management flow.
Risk Management and Full Review
- Practice the four risk responses on scenarios drawn from earlier domains.
- Take timed practice sets with 45 questions in 90 minutes to rehearse pacing.
When you reach the review stage, use the CHS-CY2 practice tests to find which domains still produce wrong answers, then return to those domains rather than re-reading everything equally. Practice under the real constraints matters, since the 90-minute window is generous but not unlimited when you are second-guessing scenarios.
Vouchers, Retakes, and Expiration
Knowing the domains is half the preparation; the other half is understanding how the attempt itself works. Each exam attempt requires a voucher, and each voucher code is valid for a single attempt. If you do not pass, you can retake the exam as many times as needed, but each retake requires a new voucher. Plan your first attempt accordingly: treating it as a free trial run is an expensive habit. For the financial side, see the CHS-CY2 certification cost breakdown, and for scheduling considerations, see CHS-CY2 exam dates.
Once earned, the certification is valid for 10 years before it expires. That long window means the credential is a durable line item on a resume or portfolio rather than something you need to renew every year or two.
Where the Credential Fits Professionally
CHS-CY2 is a CodeHS credential aimed primarily at students and early learners in cybersecurity pathways, not a replacement for the industry certifications that employers screen for in experienced hires. Its realistic value is as evidence of structured, verified knowledge across cryptography, networking, defense, documentation, and risk, which can strengthen applications for internships, school programs, and entry-level pathways, and can serve as a stepping stone toward broader credentials. Before investing time, weigh the tradeoffs in our ROI analysis of the CHS-CY2 certification, and for role-oriented context see CHS-CY2 jobs.
Because the credential's recognition varies by audience, avoid assuming it carries the same weight as long-established professional certifications. Present it honestly: it demonstrates that you mastered a defined set of five domains and passed a proctored-style assessment with a 60% threshold.
Frequently Asked Questions
There are five: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management. CodeHS lists specific topics under each but does not publish percentage weights.
The exam is online and timed, with 45 multiple-choice questions and a 90-minute timer. You need 60% to pass.
Advanced Networking has the longest topic list, with eight areas, so it usually deserves the most calendar time. However, since weights are unpublished, you should cover all five domains and let practice results guide where you add depth.
There are no specific prerequisites. CodeHS recommends its Advanced Cybersecurity course for preparation, and the exam topics are distinct from that course's curriculum, so study the listed domains directly.
Yes. You can retake the exam as needed, but each attempt requires a new voucher because each voucher code is valid for one attempt only. Earned certifications expire after 10 years.