- The Short Answer: What the Letters Mean
- Decoding the Name Piece by Piece
- What the Exam Actually Is
- The Five Domains Behind the Label
- Why "Level 2" Matters
- Vouchers, Attempts, and Expiration
- Who Takes This Certification
- Avoiding Name Confusion When You Search
- A Domain-Ordered Study Sequence
- Frequently Asked Questions
- CHS-CY2 is the CodeHS Cybersecurity Level 2 certification exam, issued by CodeHS.
- The exam has 45 multiple-choice questions and a 90-minute timer; passing requires 60%.
- Five domains: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.
- Each voucher covers one attempt; retakes need a new voucher, and certifications expire after 10 years.
The Short Answer: What the Letters Mean
If you landed here wondering what CHS-CY2 stands for, here is the direct answer: it is the shorthand for the CodeHS Cybersecurity Level 2 certification. "CHS" points to CodeHS, the company that issues the credential. "CY" signals cybersecurity. The "2" marks it as the Level 2 exam in the CodeHS cybersecurity certification track.
That is the whole identity of this credential. It is a CodeHS-issued, online, timed exam that tests intermediate cybersecurity knowledge across five defined content areas. For the bigger picture on the credential itself, see our overview on what CHS-CY2 is and the dedicated page on CHS-CY2 certification.
Decoding the Name Piece by Piece
CHS: CodeHS
CodeHS is an education platform best known for computer science and cybersecurity coursework in schools. It issues its own certifications, and the CodeHS Certifications FAQ explains how those exams are structured, how vouchers work, and how long a certification stays valid. The exam belongs to that ecosystem, which is why its content tracks CodeHS curriculum themes rather than a vendor-neutral industry body of knowledge.
CY: Cybersecurity
The "CY" portion identifies the subject area. CodeHS offers certifications in other topics as well, so the cybersecurity label keeps this exam distinct from those programming-focused credentials.
2: Level 2
The numeral tells you where the exam sits in the progression. Level 2 goes deeper than an introductory exam, covering topics such as asymmetric encryption, intrusion detection and prevention devices, incident response plans, and penetration testing. We cover that distinction further in the section on Level 2 versus Level 1 below.
What the Exam Actually Is
Knowing the name is only useful if you also know what you are signing up for. The published format is straightforward:
| Feature | CHS-CY2 Detail |
|---|---|
| Issuer | CodeHS |
| Delivery | Online, timed exam |
| Number of questions | 45 multiple-choice |
| Time limit | 90 minutes |
| Passing score | 60% |
| Prerequisites | None required; Advanced Cybersecurity course recommended |
| Attempts | One attempt per voucher code |
| Certification validity | 10 years |
With 45 questions in 90 minutes, you have roughly two minutes per question. That is a comfortable pace for most candidates, so the exam is less about speed and more about recognizing the correct concept when several answer choices look plausible. Our passing score breakdown explains what 60% means in practical question counts, and our difficulty guide discusses where candidates tend to lose points.
The Five Domains Behind the Label
CodeHS publishes the exam topics without percentage weights, so you cannot assume one domain counts more than another. Treat all five as fair game. For a deeper walkthrough, read the complete guide to all 5 content areas.
Domain 1: Advanced Cryptography
This domain moves beyond basic ciphers into the mechanics of modern encryption.
- Block and transposition ciphers
- Asymmetric versus symmetric encryption and when each is used
- Public key cryptography
- Hash functions
- Digital certificates
Domain 2: Advanced Networking
The broadest domain by topic count, mixing network hardware, physical controls, and wireless concerns.
- Network devices: IDS, IPS, and UTM
- Access control
- Physical security such as biometrics and mantraps
- Environmental controls
- Ports and protocols, including TCP and UDP
- Wireless protocols such as 802.11ac
- Private networks: DMZ, VPN, and MAC filtering
- Mobile device security
Domain 3: Cyber Defense
Recognizing threats and matching them to the right defensive response.
- Threats, vulnerabilities, and exploits
- Malware types and prevention: Trojan, worm, rootkit, and others
- Network attacks: cross-site scripting, DDoS, botnets
- Internal attacks involving BIOS, UEFI, and DLP
Domain 4: Documentation
The policy and process side of security, often underestimated by candidates who prefer technical topics.
- Change management
- Incident response plans
- Software licenses
- Data policy, privacy, and protection
Domain 5: Risk Management
How organizations identify, rank, and respond to security exposure.
- Types of vulnerabilities
- Risk assessment
- Risk response
- Penetration testing
Why "Level 2" Matters
The "2" in the name is not decoration. CodeHS states that exam topics are distinct from the recommended course curriculum, and that Level 2 preparation should not be replaced by Level 1 content. In practical terms, reviewing only introductory material will leave gaps.
Here is how to think about the progression:
- Foundational concepts belong to the earlier level: the basic ideas of confidentiality, integrity, and availability, and simple encryption.
- Level 2 concepts require you to distinguish between related technologies. For example, knowing the difference between an IDS and an IPS, or between symmetric and asymmetric encryption, and choosing the right control for a described scenario.
- Applied thinking shows up in the Risk Management and Documentation domains, where you reason about assessment, response, and process rather than recall a single definition.
CodeHS recommends its Advanced Cybersecurity course as preparation, which is a helpful signal about the depth expected. Our study guide for first-attempt success shows how to map that course material onto the five domains.
Vouchers, Attempts, and Expiration
The "how do I actually take it" mechanics are tied directly to the name of the certification, so they are worth understanding up front.
Vouchers control access
Each exam attempt requires a voucher, and each voucher code is valid for one attempt. If you do not pass, you can retake the exam as needed, but you will need a new voucher each time. This is different from exams that sell you a fixed bundle of attempts. For the money side of this, our pricing breakdown goes through what to expect.
Eligibility is open
There are no specific prerequisites. You do not need to hold a lower-level credential first, although completing the recommended Advanced Cybersecurity course makes a real difference in readiness. See the full requirements and eligibility guide for details.
The credential has a long shelf life
Certifications earned expire after 10 years. That is a generous window compared with many industry credentials, so it makes sense to put real preparation time in once rather than rushing an attempt.
Key Takeaway
Because every attempt consumes a voucher, treat practice as the place to make mistakes. Use timed practice sets to find your weak domains before you redeem a voucher on the real exam.
Who Takes This Certification
The exam is built within an educational platform, so its typical candidates are students working through CodeHS cybersecurity coursework and educators who want a credentialed benchmark for those students. It also suits self-directed learners who want a structured, defined set of five domains to organize their study of intermediate security topics.
Because the credential is a school-oriented certification rather than a long-established vendor-neutral industry designation, it is best viewed as a verified demonstration of skill and a stepping stone, not a substitute for professional certifications that employers commonly list in job postings. To weigh that honestly, read the ROI analysis, the overview of related jobs, and the salary guide. Those pages discuss how the certification fits alongside other credentials and experience.
Avoiding Name Confusion When You Search
Searching for exam information can be messy because letter-and-number codes get reused across the certification world. To make sure you are reading about the right exam, check for these markers:
- The issuer is CodeHS. If a page names a different certifying organization, it is about something else.
- The format is 45 multiple-choice questions in 90 minutes with a 60% passing score.
- The five domains match: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.
- Access runs through vouchers, with one attempt per code.
If all four match, you are looking at the right credential. Related explainer pages on this site cover the same ground from slightly different angles: what CHS-CY2 stands for, CHS-CY2 meaning, what CHS-CY2 means, and what the certification is.
A Domain-Ordered Study Sequence
Since the topics carry no published weights, a sensible plan gives each domain real attention and orders them so concepts build on each other. Here is one way to sequence a four-week approach, using the domains themselves as the structure.
Advanced Cryptography
- Contrast symmetric and asymmetric encryption, and block versus transposition ciphers
- Learn how public keys, hash functions, and digital certificates work together
- Why first: later domains (VPNs, certificates, data protection) assume you understand encryption
Advanced Networking
- Separate IDS, IPS, and UTM functions
- Memorize TCP versus UDP behavior and the purpose of DMZ, VPN, and MAC filtering
- Cover physical and environmental controls and mobile device security
- Why second: it is the largest topic list, so it earns the most time
Cyber Defense and Documentation
- Match malware types (Trojan, worm, rootkit) and attacks (XSS, DDoS, botnet) to their defenses
- Review change management, incident response plans, software licenses, and data policy
- Why together: both are scenario-driven and reward careful reading
Risk Management and full review
- Work through vulnerability types, risk assessment, risk response, and penetration testing
- Take timed 45-question practice sets in 90 minutes
- Revisit your lowest-scoring domain before redeeming a voucher
For a compact refresher in the final days, the one-page cheat sheet is handy, and you can check exam dates and scheduling and our training overview to line up your timeline. When you are ready to test yourself, head to the CHS-CY2 practice tests and run a full timed set that mirrors the real format.
Frequently Asked Questions
CHS-CY2 is shorthand for CodeHS Cybersecurity Level 2. "CHS" refers to CodeHS, "CY" to cybersecurity, and "2" to the second level of the CodeHS cybersecurity certification track.
The exam has 45 multiple-choice questions and a 90-minute timer. It is delivered online as a timed exam, and you need 60% to pass.
No specific prerequisites are required. CodeHS does recommend its Advanced Cybersecurity course as preparation, and the exam topics are separate from, and go beyond, Level 1 content.
Yes. Students can retake exams as needed, but each attempt requires a new voucher because every voucher code is valid for only one attempt.
Certifications earned through CodeHS expire after 10 years, giving you a long validity window once you pass.