CHS-CY2 logo
Focused certification exam prep
Start practice

CHS-CY2 Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • The CodeHS Cybersecurity Level 2 exam has 45 multiple-choice questions, a 90-minute timer, and a 60% passing score.
  • Official topics are published without percentage weights, so you cannot safely skip any of the five domains.
  • Each voucher code covers exactly one attempt; a retake requires a new voucher.
  • Earned certifications expire after 10 years, and no specific prerequisites are required to sit the exam.

The Number: 60% on 45 Questions

If you are searching for the CHS-CY2 passing score, the answer is short: 60%. The CodeHS Cybersecurity Level 2 Certification exam is an online, timed exam made up of 45 multiple-choice questions with a 90-minute timer. Hit 60% or higher and you pass. Fall short and you can try again with a new voucher.

That is the whole official scoring rule, and it comes directly from the CodeHS Cybersecurity Level 2 certification overview and the CodeHS Certifications FAQ. The rest of this article is about turning that single number into a practical plan: how many questions you can afford to miss, how the five exam domains share the load, how to pace the clock, and what happens if your first attempt does not go your way.

Scope note: This article covers CodeHS Cybersecurity Level 2 (CHS-CY2) only. If you want the broader picture of what the credential is, start with What Is CHS-CY2? and CHS-CY2 Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Doing the Math: How Many Questions You Must Get Right

CodeHS publishes the passing score as a percentage rather than a raw count, but with a fixed 45-question format the arithmetic is straightforward. Sixty percent of 45 is 27. That means a candidate needs roughly 27 correct answers to meet the threshold, which allows for up to about 18 misses.

ItemDetail
Total questions45 multiple-choice
Passing score60%
Approximate correct answers needed27 of 45
Approximate questions you can missUp to 18
Time limit90 minutes
Average time per questionExactly 2 minutes if you use the full timer evenly

Treat the 27-correct figure as a planning estimate derived from the published percentage and question count, not as a separately published CodeHS rule. If you are aiming only for the minimum, you are leaving no margin for a bad stretch of questions. A sensible target is to prepare for a score comfortably above 60% so that a few unfamiliar items do not decide the outcome.

How Scoring Works on the CodeHS Exam

Because the exam is entirely multiple choice, scoring is simple in concept: each question has a defined correct answer, and your result is the share you answer correctly. There are no essay prompts or lab simulations to worry about in the official description, so you are not trying to earn partial credit on a long response. Your job is to recognize the best answer among the options quickly and accurately.

Two practical consequences follow from that format:

  • Every question counts the same way toward the 60% threshold. Do not sink five minutes into one hard cryptography item when two easier questions are waiting behind it.
  • Answer everything. Since the exam is a straight count of correct multiple-choice responses, a blank is simply a missed opportunity. If time is running short, make your best selection and move on.

For a candid look at how demanding the questions feel, see How Hard Is the CHS-CY2 Exam? Complete Difficulty Guide 2026. And if you are wondering what real-world pass rates look like, the honest answer is covered in CHS-CY2 Pass Rate 2026: What the Data Shows; this article does not quote a pass-rate figure because CodeHS does not publish one in the sources used here.

Where Your Points Come From: The Five Domains

CodeHS lists the official exam topics but does not publish percentage weights for them. That detail matters for how you think about the passing score. You cannot calculate, for example, that Domain 1 is worth a fixed slice of the 45 questions and then safely ignore a weaker domain. With no published weighting, the sound strategy is balanced competence across all five areas, with extra practice where you are weakest.

Domain 1: Advanced Cryptography

This is the domain most candidates find the most abstract, so it rewards deliberate practice.

  • Block and transposition ciphers
  • Asymmetric versus symmetric encryption, and when each is used
  • Public key cryptography
  • Hash functions and what they are (and are not) used for
  • Digital certificates

Domain 2: Advanced Networking

The broadest domain by topic count, so expect a wide spread of terminology.

  • Network devices: IDS, IPS, UTM
  • Access control
  • Physical security such as biometrics and mantraps
  • Environmental controls
  • Ports and protocols, including TCP and UDP
  • Wireless protocols such as 802.11ac
  • Private networks: DMZ, VPN, MAC filtering
  • Mobile device security

Domain 3: Cyber Defense

Focus on distinguishing similar-sounding threats from one another.

  • Threats, vulnerabilities, and exploits
  • Malware types and prevention: Trojan, worm, rootkit, and others
  • Network attacks: cross-site scripting, DDoS, botnets
  • Internal attacks: BIOS, UEFI, DLP

Domain 4: Documentation

Less technical, but easy points if you learn the vocabulary precisely.

  • Change management
  • Incident response plans
  • Software licenses
  • Data policy, privacy, and protection

Domain 5: Risk Management

Know the process language, not just the definitions.

  • Types of vulnerabilities
  • Risk assessment
  • Risk response
  • Penetration testing

For a deeper breakdown of each content area, read CHS-CY2 Exam Domains 2026: Complete Guide to All 5 Content Areas.

Why "just clear 60%" is a risky mindset: Because topic weights are not published, a candidate who skips Documentation and Risk Management as "easy" or avoids Cryptography as "hard" has no way to know how many questions that decision exposes. Spreading your preparation across all five domains is the only strategy that protects you against an unevenly distributed question set.

Pacing 45 Questions in 90 Minutes

Ninety minutes for 45 questions averages two minutes per question. For most multiple-choice items on definitions and identification, that is generous. The risk is not running out of time on easy questions; it is losing time on a handful of confusing ones.

A Simple Two-Pass Approach

  1. First pass: Answer everything you recognize immediately. Questions like "which device actively blocks detected intrusions" or "which attack overwhelms a service with traffic from many sources" should take well under a minute once you know IDS vs. IPS and DDoS cold.
  2. Second pass: Return to the items you flagged. Eliminate options that clearly belong to a different concept, then choose the best remaining answer.
  3. Final check: Confirm no question was left unanswered before the timer expires.

Question Styles to Expect

Based on the published topic list, expect the multiple-choice items to test recognition and distinction: matching a term to its definition, choosing the correct control for a scenario, or separating look-alike concepts. Typical confusable pairs worth drilling include symmetric versus asymmetric encryption, IDS versus IPS, a worm versus a Trojan, and risk assessment versus risk response. If you can explain the difference between each pair in one sentence, you are well positioned.

Vouchers, Retakes, and What a Failed Attempt Costs You

The mechanics of attempts matter when you are deciding how aggressively to schedule your exam. According to the CodeHS Certifications FAQ:

  • Each exam attempt requires a voucher.
  • Each voucher code is valid for one attempt.
  • Students can retake the exam as needed, using new vouchers.

In practical terms, a failed attempt is not the end of the road, but it is not free in effort or in voucher use. Because every retake needs a fresh voucher, it is worth treating your first attempt as the one you prepare for properly rather than as a trial run. For the cost side of this, see CHS-CY2 Certification Cost 2026: Complete Pricing Breakdown, and for scheduling logistics see CHS-CY2 Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Key Takeaway

Do not use your first voucher as a practice run. Take full-length timed practice sets beforehand, confirm you are consistently above 60% across all five domains, and only then sit the real exam.

A Domain-Ordered Four-Week Plan

This is the one structured study section in the article, and it is tied directly to the CHS-CY2 domains. The ordering puts the densest, most abstract material early, when your energy is highest, and ends with the most vocabulary-driven domains plus full practice.

Week 1

Advanced Cryptography

  • Contrast block and transposition ciphers
  • Build a clear mental model of symmetric vs. asymmetric encryption and public key cryptography
  • Learn what hash functions do and how digital certificates establish trust
Week 2

Advanced Networking

  • Memorize device roles: IDS, IPS, UTM
  • Review TCP vs. UDP, wireless standards, and private network concepts (DMZ, VPN, MAC filtering)
  • Cover physical and environmental security plus mobile device security
Week 3

Cyber Defense and Documentation

  • Sort malware types and the attacks that go with them
  • Study internal attack topics: BIOS, UEFI, DLP
  • Learn change management, incident response plans, software licenses, and data policy
Week 4

Risk Management and Full Practice

  • Review vulnerability types, risk assessment, risk response, and penetration testing
  • Take timed 45-question practice runs against a 90-minute limit
  • Re-study the domain where your practice scores are lowest

For a fuller walkthrough, the CHS-CY2 Study Guide 2026: How to Pass on Your First Attempt expands on this approach, and the CHS-CY2 Cheat Sheet 2026: One-Page Review of Must-Know Facts is useful for last-day review. You can also run timed drills on the CHS-CY2 practice test site.

Study the Exam Topics, Not Just the Course

CodeHS recommends the Advanced Cybersecurity course as preparation, and there are no specific prerequisites to sit the exam. However, the exam topics are distinct from the recommended course curriculum. That means finishing course modules is helpful but does not guarantee coverage of everything the exam lists. Work from the five domain topic lists above, and do not substitute Level 1 material for Level 2 topics.

After You Pass: Validity and Career Use

Certifications earned through CodeHS expire after 10 years, which is a long runway compared with many industry credentials. For a student, that means a Level 2 result earned in high school or an early college program can remain on a resume well into a first career.

What the credential does for you professionally depends on your goals. It signals foundational knowledge across cryptography, networking, defense, documentation, and risk, which lines up with entry-level and pathway-oriented cybersecurity roles and further study. To evaluate the payoff honestly, read Is the CHS-CY2 Certification Worth It? Complete ROI Analysis 2026, and for earnings context see CHS-CY2 Salary Guide 2026: Complete Earnings Analysis. This article does not quote salary figures, since none are published in the official sources it relies on.

Keep expectations realistic: A 60% on this exam shows you cleared a defined knowledge bar across five domains. It is a solid starting credential, and it pairs best with continued coursework, hands-on practice, and further certifications as your career plans develop.

Frequently Asked Questions

What is the passing score for the CHS-CY2 exam?

The passing score for the CodeHS Cybersecurity Level 2 Certification exam is 60%. The exam has 45 multiple-choice questions and a 90-minute timer, so 60% works out to roughly 27 correct answers.

Are the five domains weighted differently?

CodeHS publishes the official exam topics without percentage weights. Because no breakdown is given, you should prepare across all five domains: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.

Can I retake the exam if I do not reach 60%?

Yes. Students can retake exams as needed, but each attempt requires a voucher and each voucher code is valid for one attempt only, so a retake requires a new voucher.

Are there prerequisites before I can take CHS-CY2?

There are no specific prerequisites. CodeHS recommends the Advanced Cybersecurity course for preparation, but the exam topics are distinct from that course curriculum, so study the published topic list directly. See CHS-CY2 Requirements 2026 for more detail.

How long is the certification valid after I pass?

Certifications earned through CodeHS expire after 10 years. That gives you a long validity window to use the credential on applications, resumes, and portfolios.

Ready to pass your CHS-CY2 exam?

Put this into practice with free CHS-CY2 questions across every exam domain.