- What the CodeHS Level 2 Exam Actually Is
- Format, Passing Score, and Voucher Mechanics
- Domain 1: Advanced Cryptography
- Domain 2: Advanced Networking
- Domain 3: Cyber Defense
- Domain 4: Documentation
- Domain 5: Risk Management
- A Domain-Ordered Study Schedule
- Where Candidates Lose Points
- After You Pass: Expiry and Career Use
- Frequently Asked Questions
- The exam is online, timed at 90 minutes, with 45 multiple-choice questions and a 60% passing score.
- Five domains are tested: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.
- CodeHS publishes no domain percentage weights, so study all five areas rather than guessing which matters most.
- Every voucher code covers one attempt only; a retake requires a new voucher.
What the CodeHS Level 2 Exam Actually Is
The CodeHS Cybersecurity Level 2 certification (CHS-CY2) is an exam issued by CodeHS, the computer science education platform widely used in high school and early college classrooms. It is built as a step above the Level 1 credential and focuses on more advanced topics: cryptography beyond the basics, deeper networking and physical security concepts, malware and attack categories, organizational documentation, and risk management. If you want the short orientation first, What Is CHS-CY2? covers the credential at a high level, and What Does CHS-CY2 Stand For? clears up the naming.
This guide is about passing on the first try. That means knowing exactly what the exam asks, how the five domains break down, and which topics deserve the most repetition. The goal is not to memorize a vocabulary list. It is to be able to read a short scenario or definition-style question and choose the correct answer out of four plausible ones.
Format, Passing Score, and Voucher Mechanics
Before studying any content, lock in the logistics. They shape how you pace yourself and how you plan around the possibility of a retake.
| Item | What CodeHS Publishes |
|---|---|
| Delivery | Online, timed exam |
| Questions | 45 multiple-choice questions |
| Time limit | 90 minutes |
| Passing score | 60% |
| Prerequisites | None required; Advanced Cybersecurity course recommended |
| Attempts | One attempt per voucher code; retake with a new voucher |
| Certification validity | 10 years from earning |
What the numbers mean for pacing
Ninety minutes for 45 questions works out to two minutes per question, which is generous for multiple-choice items. Time pressure is rarely the main problem. The more common issue is second-guessing: candidates change correct answers after overthinking a distractor. Plan to complete a first pass in roughly 45 to 60 minutes, then use the remaining time to revisit only the questions you flagged.
A 60% passing score on 45 questions means you can miss a meaningful number of items and still pass. For a precise breakdown of what that threshold looks like in practice, see CHS-CY2 Passing Score 2026: Exactly What You Need to Pass. Do not treat 60% as permission to skip a domain, though. With no published domain weights, any single area could contribute a sizable share of your questions.
Vouchers and retakes
Each exam attempt requires a voucher, and each voucher code is valid for one attempt. If you do not pass, you can retake the exam with a new voucher. That rule makes the first attempt worth preparing for properly, since every retry means obtaining another voucher. Costs and how vouchers are typically obtained are covered in CHS-CY2 Certification Cost 2026: Complete Pricing Breakdown, and eligibility details are in CHS-CY2 Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Domain 1: Advanced Cryptography
Cryptography is where many candidates feel least comfortable, because the vocabulary is dense and several terms sound alike. The published topics are block and transposition ciphers, asymmetric and symmetric encryption, public key cryptography, hash functions, and digital certificates.
Advanced Cryptography: What to Master
Be able to classify an algorithm or scenario, not just define a term.
- Block vs. transposition ciphers: block ciphers process fixed-size chunks of data; transposition ciphers rearrange the positions of characters rather than substituting them.
- Symmetric vs. asymmetric: symmetric uses one shared key (fast, but key distribution is the challenge); asymmetric uses a key pair (solves distribution, costs speed).
- Public key cryptography: know which key encrypts for confidentiality, which key signs for authenticity, and who holds each.
- Hash functions: one-way, fixed-length output, used for integrity checking; know why a hash is not encryption.
- Digital certificates: how they bind an identity to a public key and why a trusted authority matters.
Distinctions the exam likes to test
Questions in this area tend to hinge on a single distinction. Can the data be reversed? Encryption is reversible with the right key; hashing is not. Who needs to know the key? Symmetric keys must be shared; in asymmetric systems the private key must stay private. What property is being protected? Confidentiality, integrity, and authenticity map to different tools, and a question will often describe the goal and ask you to pick the mechanism.
Practice by writing a one-line "why" for each term. If you can explain why a hash fits integrity checking but not confidentiality, you are far less likely to be fooled by a distractor.
Domain 2: Advanced Networking
This is the broadest domain by topic count, covering network devices, access control, physical security, environmental controls, ports and protocols, wireless protocols, private networks, and mobile device security. Breadth is the challenge: you need working knowledge of many small topics.
Advanced Networking: Topic Clusters
- Network devices: IDS, IPS, and UTM. Know that an IDS detects and alerts, an IPS can actively block, and a UTM consolidates multiple security functions into one appliance.
- Access control: how systems decide who may reach which resources.
- Physical security: biometrics, mantraps, and similar controls that protect facilities and equipment.
- Environmental controls: protecting hardware from conditions like heat and fire.
- Ports and protocols: TCP versus UDP, including reliability and connection behavior.
- Wireless protocols: standards such as 802.11ac and how they differ.
- Private networks: DMZ, VPN, and MAC filtering, and what each is meant to accomplish.
- Mobile device security: protecting phones and tablets that connect to organizational resources.
Compare, don't just define
Networking questions often present two similar-sounding controls and ask which fits a described situation. A comparison table you build yourself is one of the most effective tools here. For example, line up IDS, IPS, and UTM by what each does when it sees suspicious traffic, then line up DMZ, VPN, and MAC filtering by the problem each solves. The act of building the table forces you to learn the differences the exam relies on.
For a deeper walk through every content area, including this one, the CHS-CY2 Exam Domains 2026: Complete Guide to All 5 Content Areas goes topic by topic.
Domain 3: Cyber Defense
Cyber Defense covers threats, vulnerabilities, and exploits; malware types and prevention; network attacks; and internal attacks. This domain rewards precise vocabulary, since many questions describe behavior and ask you to name the threat.
Cyber Defense: Behavior-to-Name Matching
- Malware types: know how a Trojan, worm, and rootkit differ. A worm spreads on its own, a Trojan disguises itself as legitimate software, and a rootkit hides its presence deep in a system.
- Network attacks: cross-site scripting, DDoS, and botnets. Be able to tell an attack that abuses a web application from one that overwhelms a service with traffic.
- Internal attacks: BIOS and UEFI-level threats, and data loss prevention (DLP) as a defensive control.
- Threat vocabulary: keep threat, vulnerability, and exploit distinct. A vulnerability is a weakness, an exploit takes advantage of it, and a threat is the potential for harm.
A useful drill: write each term on one side of a card and the observable behavior on the other, then shuffle and practice in both directions. Going from behavior to name is exactly what the exam asks. Our CHS-CY2 Cheat Sheet 2026: One-Page Review of Must-Know Facts is a good place to check your recall before test day.
Domain 4: Documentation
Documentation is the domain candidates most often underestimate, because it feels less technical. It covers change management, incident response plans, software licenses, and data policy, privacy, and protection. These are the organizational practices that surround technical security work, and they are fair game for straightforward multiple-choice questions.
Documentation: What to Know
- Change management: why changes to systems are reviewed, approved, tracked, and documented before they are made.
- Incident response plans: the purpose of having a defined plan and the general stages of responding to an incident.
- Software licenses: the difference between licensing models and why compliance matters.
- Data policy, privacy, and protection: how organizations define acceptable handling of sensitive information.
These questions are usually answerable by reasoning about what a responsible organization would do. Even so, learn the standard terminology, because the answer choices will use it. Because this domain is more conceptual, it is a good candidate for quick, low-effort review sessions rather than long study blocks.
Domain 5: Risk Management
The final domain covers types of vulnerabilities, risk assessment, risk response, and penetration testing. It ties the earlier domains together: you identify weaknesses, evaluate how serious they are, decide how to respond, and test your defenses.
Risk Management: Core Ideas
- Types of vulnerabilities: recognize categories of weakness across software, configuration, and people.
- Risk assessment: identifying assets and weighing the likelihood and impact of threats against them.
- Risk response: know the standard ways to handle a risk, such as accepting, avoiding, reducing, or transferring it, and match each to a scenario.
- Penetration testing: authorized, simulated attacks used to find weaknesses before real attackers do.
A Domain-Ordered Study Schedule
Rather than a generic weekly template, order your study by how the domains build on one another and by where candidates tend to need the most repetition. Cryptography is placed first because it is dense and benefits from the longest runway. Documentation and Risk Management go last because they are more conceptual and respond well to short review sessions close to the exam.
Advanced Cryptography
- Build a symmetric vs. asymmetric comparison table
- Write the "why" for hashing, public keys, and certificates
- Do a first set of practice questions on this domain only
Advanced Networking
- Compare IDS, IPS, and UTM, and DMZ, VPN, and MAC filtering
- Review TCP vs. UDP and the wireless standards
- Cover physical and environmental controls and mobile security
Cyber Defense
- Drill malware and attack names from behavior descriptions
- Review internal attacks, BIOS/UEFI, and DLP
- Revisit weak spots from Weeks 1 and 2
Documentation, Risk Management, and Full Practice
- Review change management, incident response, licenses, and data policy
- Match risk response strategies to scenarios and review penetration testing
- Take timed 45-question practice sets and review every miss
If you have more time, stretch each block rather than adding new material. If you have less, compress by prioritizing the domains where your practice scores are lowest. The CHS-CY2 practice tests can show you which areas need attention before you commit to a schedule, and our broader CHS-CY2 training overview covers other preparation options.
Where Candidates Lose Points
Because the exam is multiple-choice, most lost points come from a handful of predictable errors rather than from missing knowledge entirely.
- Confusing similar terms. Worm versus Trojan, IDS versus IPS, hashing versus encryption. Build side-by-side comparisons for every pair that sounds alike.
- Studying Level 1 material. Foundational content will not cover topics like UTM devices, digital certificates, or penetration testing. Study the Level 2 topic list directly.
- Skipping Documentation. It looks easy, so people ignore it, then lose points on change management and incident response terminology.
- Assuming a weighting. With no published percentages, betting on one domain is a gamble. Cover all five.
- Changing correct answers. Flag uncertain questions and revisit them, but do not rewrite answers without a concrete reason.
Key Takeaway
Score your practice results by domain, not just overall. A single overall percentage can hide a weak area; a per-domain view tells you exactly where to spend the next study session.
To calibrate your expectations, How Hard Is the CHS-CY2 Exam? Complete Difficulty Guide 2026 discusses what makes the exam challenging, and CHS-CY2 Pass Rate 2026: What the Data Shows addresses what is and is not publicly known about results.
After You Pass: Expiry and Career Use
Certifications earned through CodeHS expire after 10 years, which is a long validity window compared with many industry credentials. There are no prerequisites to sit the exam, so it is accessible to students and career changers alike. CodeHS recommends its Advanced Cybersecurity course as preparation, but that is a recommendation rather than a requirement.
Realistically, CHS-CY2 is best understood as a credential that demonstrates structured knowledge of intermediate cybersecurity concepts, particularly for students building toward further study or entry-level technical roles. It is not a substitute for experience or for higher-level industry certifications. If you are weighing whether it fits your goals, read Is the CHS-CY2 Certification Worth It? Complete ROI Analysis 2026, and see CHS-CY2 Jobs and the CHS-CY2 Salary Guide 2026: Complete Earnings Analysis for how it relates to career paths. Treat any earnings discussion as context rather than a promise, since outcomes depend on role, location, and experience.
When you are ready to test yourself under realistic conditions, start with a full timed set on the main practice test site and work through your misses domain by domain.
Frequently Asked Questions
The exam has 45 multiple-choice questions and a 90-minute timer. You need a 60% to pass. It is delivered online as a timed exam.
No. There are no specific prerequisites. CodeHS recommends its Advanced Cybersecurity course as preparation, but it is not required to attempt the certification.
You can retake the exam as needed, but each attempt requires a new voucher because every voucher code is valid for only one attempt. Review your weakest domains before retaking.
CodeHS does not publish weights, so all five domains matter. Starting with Advanced Cryptography is sensible because it is dense and benefits from extra repetition, leaving conceptual areas like Documentation for later review.
Not on their own. The Level 2 exam topics are distinct from the recommended course curriculum and should not be replaced by Level 1 content. Study the five Level 2 domains directly, and see the full CHS-CY2 study guide for a structured approach.
Certifications earned through CodeHS expire after 10 years. Check the official CodeHS certifications FAQ for the most current renewal and validity details before you plan around that date.