- Decoding the Label: CHS, CY, and 2
- What the Credential Actually Is
- The Exam Format in Plain Terms
- The Five Domains Behind the Name
- Why the "2" Matters: Level 2 vs. Level 1
- Vouchers, Retakes, and the 10-Year Validity Window
- Who Takes This Certification and Where It Leads
- Scheduling Your Prep by Domain
- Frequently Asked Questions
- CHS-CY2 is the CodeHS Cybersecurity Level 2 certification, issued by CodeHS, not by any outside standards body.
- The exam has 45 multiple-choice questions, a 90-minute timer, and a 60% passing score.
- Five domains are tested: cryptography, networking, cyber defense, documentation, and risk management.
- Each voucher covers one attempt; retakes need a new voucher, and earned certifications expire after 10 years.
Decoding the Label: CHS, CY, and 2
If you landed here searching for what "CHS-CY2" means, the answer is short: it is the identifier for the CodeHS Cybersecurity Level 2 certification. The prefix points to CodeHS, the computer science education platform that publishes the exam. "CY" signals the cybersecurity pathway, and the "2" marks the second tier of that pathway.
That framing matters because acronyms in the certification world are crowded. Plenty of unrelated credentials, job titles, and internal codes reuse similar letter strings. On this site, CHS-CY2 refers only to the CodeHS exam described in CodeHS's own certification documentation. If you have seen the same letters attached to a different organization's credential, the details below (format, scoring, topics, validity) do not transfer to it, and vice versa.
For related phrasing of the same question, see our explainers on what CHS-CY2 stands for and the CHS-CY2 meaning. This article goes further by connecting the name to what the exam actually tests.
What the Credential Actually Is
CodeHS Cybersecurity Level 2 is a certification exam that lets students demonstrate applied knowledge of intermediate-to-advanced cybersecurity concepts. It is an online, timed assessment that CodeHS administers through its certification program. You earn the certification by passing the exam, and the credential is issued by CodeHS.
A few characteristics define it:
- Issuer: CodeHS, the same organization behind the cybersecurity courses many students take in school.
- Delivery: Online and timed, with a countdown clock running while you answer.
- Content scope: Five published domains, listed without percentage weights.
- Prerequisites: None required, though CodeHS recommends the Advanced Cybersecurity course.
For a deeper walk through eligibility, read CHS-CY2 requirements and how to qualify, and for a general overview, what CHS-CY2 certification is.
The Exam Format in Plain Terms
Knowing the format removes a lot of test-day anxiety. Here is what CodeHS publishes:
| Feature | CHS-CY2 Detail |
|---|---|
| Question count | 45 |
| Question type | Multiple choice |
| Time limit | 90 minutes |
| Passing score | 60% |
| Delivery | Online, timed |
| Attempt access | One voucher code per attempt |
| Certification validity | 10 years |
Do the arithmetic: 90 minutes across 45 questions averages two minutes per question. That is generous for recall items such as identifying a protocol, but tighter for scenario-style questions where you must read a short situation and choose the best response. A 60% passing score on 45 questions means you need roughly 27 correct answers; our dedicated page on the CHS-CY2 passing score unpacks how that plays out in practice.
Because every question is multiple choice, the skill being tested is discrimination: picking the best answer among plausible distractors. Expect options that are all real security terms, where only one fits the scenario. Knowing the difference between an IDS and an IPS, or between symmetric and asymmetric encryption, is more useful than memorizing definitions in isolation. You can gauge your readiness with the free CHS-CY2 practice tests.
The Five Domains Behind the Name
CodeHS publishes five exam domains. Percentage weights are not published, so you should treat all five as fair game and avoid betting on a single area. Here is what each one asks of you.
Domain 1: Advanced Cryptography
The cryptography domain moves beyond basic substitution ciphers into how modern encryption is structured and verified.
- Block and transposition ciphers
- Asymmetric versus symmetric encryption, including when each is appropriate
- Public key cryptography and how key pairs work
- Hash functions and what makes them useful for integrity checking
- Digital certificates and the trust they establish
Domain 2: Advanced Networking
This is the broadest domain by topic count, spanning devices, physical controls, protocols, and mobile security.
- Network devices: IDS, IPS, and UTM
- Access control concepts
- Physical security such as biometrics and mantraps
- Environmental controls
- Ports and protocols, including TCP and UDP
- Wireless protocols such as 802.11ac
- Private networks: DMZ, VPN, and MAC filtering
- Mobile device security
Domain 3: Cyber Defense
Here you identify threats and match them to defenses.
- Threats, vulnerabilities, and exploits, and how they relate
- Malware types and prevention: Trojans, worms, rootkits, and more
- Network attacks such as cross-site scripting, DDoS, and botnets
- Internal attacks, including BIOS, UEFI, and DLP topics
Domain 4: Documentation
The least "hands-on" domain, but one where precise vocabulary earns points.
- Change management
- Incident response plans
- Software licenses
- Data policy, privacy, and protection
Domain 5: Risk Management
Risk management ties the technical material into organizational decision-making.
- Types of vulnerabilities
- Risk assessment
- Risk response
- Penetration testing
For a fuller treatment of each area, including how the topics interlock, see the complete guide to all 5 CHS-CY2 content areas.
Why the "2" Matters: Level 2 vs. Level 1
The numeral is not decoration. Level 2 sits above CodeHS's Level 1 cybersecurity certification, and its published topics reflect that step up. Compare the flavor of the content: Level 2 asks about public key cryptography and digital certificates, DMZs and VPNs, rootkits and cross-site scripting, change management and incident response plans, and penetration testing. These are topics that assume you already understand foundational ideas like what a network is and why passwords matter.
If you are weighing how demanding that jump is, our breakdown of how hard the CHS-CY2 exam is addresses difficulty without inventing numbers, and the pass rate article explains what is and is not publicly known.
Vouchers, Retakes, and the 10-Year Validity Window
Registration mechanics are simple but easy to misunderstand, so here they are clearly:
- You need a voucher. Each exam attempt requires a voucher.
- One voucher, one attempt. Each voucher code is valid for a single attempt. It is not a bundle of tries.
- Retakes are allowed. If you do not pass, you can retake the exam as needed, using a new voucher each time.
- Certification lasts 10 years. Once earned, the certification expires after 10 years.
The one-attempt-per-voucher rule changes how you should prepare. Because a failed attempt consumes a voucher, it makes sense to confirm readiness with timed practice before you redeem one rather than treating the real exam as a diagnostic. Voucher pricing and how schools or districts may handle purchasing are covered in the CHS-CY2 certification cost breakdown, and scheduling considerations appear in the exam dates guide.
Key Takeaway
Treat each voucher as a single, deliberate attempt. Complete at least one full 45-question, 90-minute timed run-through of practice material before redeeming one, so you know whether you are consistently clearing the 60% line.
Who Takes This Certification and Where It Leads
CodeHS certifications are designed around students, so the typical candidate is a high school or early college learner who has worked through CodeHS cybersecurity coursework, or a self-directed learner building a foundation. Because there are no formal prerequisites, curious beginners with solid study habits can also sit the exam.
It helps to be realistic about what the credential is. It is a school-oriented certification that documents applied cybersecurity knowledge; it is not a substitute for experience-based professional credentials. Its practical value tends to show up in a few ways:
- Portfolio evidence: A verifiable credential to list on a resume, college application, or scholarship packet alongside coursework.
- Pathway signaling: Proof that you have worked through the Level 2 topics, which makes entry-level cybersecurity internships, help desk roles, and further certifications feel like natural next steps.
- Skill vocabulary: Fluency in IDS/IPS, encryption, malware categories, incident response, and risk concepts that entry-level security interviews commonly touch on.
We deliberately do not attach salary figures to the credential, because no verified earnings data is tied specifically to it. For an honest look at the economics and employer perspective, see CHS-CY2 jobs, the salary guide, and whether the certification is worth it.
Scheduling Your Prep by Domain
You do not need an elaborate system, but sequencing the domains sensibly helps because some build on others. Because Domain 2 carries the most listed topics, it earns the most time. Here is one way to lay out roughly five weeks:
Advanced Cryptography
- Distinguish symmetric from asymmetric encryption and explain why both exist
- Walk through how public/private key pairs and digital certificates establish trust
- Know what hash functions do and do not provide
Advanced Networking
- Compare IDS, IPS, and UTM side by side
- Memorize how DMZ, VPN, and MAC filtering differ in purpose
- Review TCP versus UDP, wireless standards, physical controls, and mobile security
Cyber Defense
- Sort malware types (Trojan, worm, rootkit) by behavior, not just name
- Match network attacks like XSS, DDoS, and botnets to their defenses
- Cover internal attack surfaces: BIOS, UEFI, and DLP
Documentation and Risk Management, then timed review
- Learn change management, incident response plans, licensing, and data policy terms
- Practice risk assessment versus risk response, and what penetration testing contributes
- Finish with a full timed set of 45 questions in 90 minutes
Cryptography goes first because later topics, such as VPNs and certificates in secure communications, lean on it. Documentation and risk management come last because they are vocabulary-heavy and tie the earlier technical material together. For a more detailed plan, use our CHS-CY2 study guide, reinforce facts with the one-page cheat sheet, and drill questions through the main practice test site. If you are still deciding on a program of study, the CHS-CY2 training overview compares approaches.
Frequently Asked Questions
CHS-CY2 identifies the CodeHS Cybersecurity Level 2 certification. It is an online, timed multiple-choice exam issued by CodeHS that covers advanced cryptography, advanced networking, cyber defense, documentation, and risk management.
The exam contains 45 multiple-choice questions with a 90-minute timer. You need a score of at least 60% to pass.
No specific prerequisites are required. CodeHS recommends its Advanced Cybersecurity course as preparation, but the exam topics are distinct from that curriculum, so focus your review on the five published Level 2 domains.
Yes. Each attempt requires a voucher, and each voucher code is valid for one attempt only. You can retake the exam as needed by using a new voucher.
Certifications earned through CodeHS expire after 10 years, according to the CodeHS Certifications FAQ.