CHS-CY2 logo
Focused certification exam prep
Start practice

What Is A CHS-CY2?

TL;DR
  • CHS-CY2 is the CodeHS Cybersecurity Level 2 certification exam, issued by CodeHS.
  • The exam has 45 multiple-choice questions, a 90-minute timer, and a 60% passing score.
  • Five domains: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management.
  • Each voucher code covers exactly one attempt; retakes require a new voucher.

What a CHS-CY2 Actually Is

CHS-CY2 is the shorthand for the CodeHS Cybersecurity Level 2 certification. It is an online, timed exam that measures whether a student can apply intermediate-to-advanced cybersecurity concepts: how encryption and hashing work, how networks are defended, how attacks are classified, how organizations document their security practices, and how risk is assessed and answered.

The name is easy to confuse with other credentials that happen to share a similar acronym. This article is about one thing only: the certification published by CodeHS for students working through its cybersecurity pathway. If you have landed here searching for the meaning of the code, the short version is that "CHS" points to CodeHS, "CY" to Cybersecurity, and "2" to the second certification level. For other phrasings of the same question, see What Does CHS-CY2 Stand For? and CHS-CY2 Meaning.

Who Issues It and Where It Fits

The exam is issued by CodeHS, an education technology company known for computer science and cybersecurity curriculum used in classrooms. The certification is documented on the CodeHS help center in the Cybersecurity Level 2 Certification article and the Certifications FAQ, which are the official references for the exam overview and policies.

Within the CodeHS ecosystem, the Level 2 exam sits above the Level 1 cybersecurity certification. CodeHS recommends its Advanced Cybersecurity course as preparation, but it does not make that course a gate. The exam topics are published separately from the course curriculum, which matters: the exam is defined by its own topic list, not by whatever happens to appear in a particular lesson sequence.

Why the issuer matters: This is a CodeHS-issued credential, not a vendor certification from a major industry body. Treat it as a structured, school-friendly proof of advanced foundational knowledge, and describe it accurately on a resume or portfolio. For a frank look at how it is perceived, read Is the CHS-CY2 Certification Worth It?

Exam Format at a Glance

The structure of the exam is simple and fixed, which makes pacing easy to plan. The table below summarizes the published format.

AttributeDetail
IssuerCodeHS
DeliveryOnline, timed exam
Questions45 multiple-choice
Time limit90 minutes
Passing score60%
PrerequisitesNone required
Attempt accessOne voucher code per attempt
Certification validity10 years

With 45 questions in 90 minutes, you have roughly two minutes per question on average. That is a comfortable pace for multiple-choice items, which means the real challenge is breadth of knowledge, not speed. For the exact scoring mechanics, see CHS-CY2 Passing Score 2026.

The Five Content Domains

CodeHS publishes the exam topics grouped into five domains. Importantly, the official sources do not publish percentage weights for these domains, so you should not assume any one area is heavier than another. Prepare all five. A detailed walkthrough lives in CHS-CY2 Exam Domains 2026: Complete Guide to All 5 Content Areas; here is the overview.

Domain 1: Advanced Cryptography

The cryptography domain moves beyond "what is encryption" into how different families of techniques work and when each applies.

  • Block ciphers and transposition ciphers
  • Asymmetric versus symmetric encryption
  • Public key cryptography
  • Hash functions
  • Digital certificates

Domain 2: Advanced Networking

This is the broadest domain by topic count, covering both the technology of networks and the physical and mobile environment around them.

  • Network devices such as IDS, IPS, and UTM
  • Access control
  • Physical security, including biometrics and mantraps
  • Environmental controls
  • Ports and protocols, including TCP and UDP
  • Wireless protocols such as 802.11ac
  • Private networks: DMZ, VPN, and MAC filtering
  • Mobile device security

Domain 3: Cyber Defense

Here the focus is on recognizing what attackers do and how defenders respond.

  • Threats, vulnerabilities, and exploits
  • Malware types and prevention, such as Trojans, worms, and rootkits
  • Network attacks, including cross-site scripting, DDoS, and botnets
  • Internal attacks, including BIOS, UEFI, and DLP topics

Domain 4: Documentation

The least "technical" domain in the narrow sense, but one that rewards candidates who understand how security works inside organizations.

  • Change management
  • Incident response plans
  • Software licenses
  • Data policy, privacy, and protection

Domain 5: Risk Management

This domain ties the other four together by asking how an organization decides what to protect and how.

  • Types of vulnerabilities
  • Risk assessment
  • Risk response
  • Penetration testing

What the Questions Actually Test

Because the exam is entirely multiple-choice, questions tend to test discrimination between similar concepts rather than recall of a single definition. Expect scenarios and comparisons built around the topic list above. A few patterns are worth preparing for:

  • Pick the right tool. You may be asked which device or technique fits a described situation, such as the difference between a system that detects suspicious traffic and one that actively blocks it (IDS versus IPS), or when a DMZ makes more sense than a VPN.
  • Match the cryptographic approach to the goal. Distinguishing symmetric from asymmetric encryption, knowing what a hash function is for, and understanding the role of a digital certificate in public key cryptography are core skills.
  • Classify the threat. Telling a worm from a Trojan from a rootkit, or a DDoS attack from a botnet-driven campaign, depends on knowing the defining behavior of each.
  • Identify the right process. Documentation and risk questions often ask what step comes next in change management or incident response, or how a risk should be treated once assessed.
  • Connect physical and logical security. Biometrics, mantraps, and environmental controls sit in the networking domain, so do not skip them just because they are not "hacking" topics.
Watch for near-synonyms: Many wrong answers on a multiple-choice security exam are real terms used in the wrong context. When two options both sound plausible, ask which one matches the specific function described, not which one sounds more advanced.

For a candid look at where candidates struggle, see How Hard Is the CHS-CY2 Exam? and the discussion of outcomes in CHS-CY2 Pass Rate 2026: What the Data Shows.

Vouchers, Retakes, and Expiration

Access to the exam works through vouchers. Each exam attempt requires a voucher, and each voucher code is valid for one attempt only. If you do not pass, you are free to try again, but you will need a new voucher for every additional attempt. There is no separate "retake policy" that blocks you from trying again; the practical constraint is simply obtaining another voucher.

Once earned, the certification is valid for 10 years, which is notably long for a technical credential. That said, cybersecurity changes quickly, so a certification that does not expire is not the same as knowledge that stays current. Pricing and how vouchers are typically obtained are covered in CHS-CY2 Certification Cost 2026, and scheduling considerations are in CHS-CY2 Exam Dates 2026. Because voucher availability often depends on your school or program, confirm the process with your instructor or through the official CodeHS help articles before planning an attempt.

Key Takeaway

Treat every voucher as a single, deliberate attempt. Use practice questions first so you are not spending a voucher to find out what you do not know. You can drill domain-by-domain on the CHS-CY2 practice test.

Who Should Take It

There are no specific prerequisites for CHS-CY2, so formally anyone can register and sit for it. In practice, the exam is best suited to:

  • High school and early college students who have completed or are completing an advanced cybersecurity course
  • Students who already hold the Level 1 certification and want a deeper, more technical credential
  • Career explorers who want a structured way to demonstrate cryptography, networking, and risk-management fundamentals
  • Teachers and program leaders looking for a clear benchmark of student attainment

Eligibility details and how to qualify are spelled out further in CHS-CY2 Requirements 2026. The key point is that the absence of a prerequisite does not mean the exam is trivial; the recommended preparation is the Advanced Cybersecurity course for a reason.

Where the Credential Leads

It is worth being precise about what this certification does and does not do for a career. CHS-CY2 demonstrates that you have studied the five domains above at an advanced foundational level. It is a strong signal for students pursuing entry-level pathways and for admissions, scholarship, or internship applications where a verifiable cybersecurity credential helps you stand out from peers with no formal evidence of skill.

The topics it covers map to the kind of work found in entry-level security-adjacent roles: help desk and IT support with a security focus, junior security analyst pathways, network administration, and compliance or policy support. Those roles lean on the same ideas the exam tests, including access control, malware recognition, incident response documentation, and risk assessment. Because this is a CodeHS credential rather than a widely recognized industry certification, employers are more likely to treat it as evidence of initiative and baseline knowledge than as a standalone hiring requirement. See CHS-CY2 Jobs and CHS-CY2 Salary Guide 2026 for a qualitative look at how the credential relates to work and pay.

Sequencing Your Preparation by Domain

You do not need an elaborate method, but order matters because the domains build on one another. Cryptography concepts such as hashing, certificates, and public key systems resurface in networking topics like VPNs and in risk discussions, so starting there pays off. Risk management works best last, because it is easier to reason about risk response once you know the threats and controls involved.

Week 1

Advanced Cryptography

  • Compare symmetric and asymmetric encryption side by side
  • Explain what a hash function does and does not provide
  • Trace how a digital certificate supports public key cryptography
Week 2

Advanced Networking

  • Separate IDS, IPS, and UTM by function
  • Review TCP versus UDP and common wireless standards
  • Cover DMZ, VPN, MAC filtering, physical security, and mobile device security
Week 3

Cyber Defense and Documentation

  • Classify malware by behavior and prevention method
  • Learn the network and internal attacks named in the topic list
  • Memorize the purpose of change management and incident response plans
Week 4

Risk Management and Full Review

  • Walk through assessment, response, and penetration testing
  • Take timed 45-question practice sets within 90 minutes
  • Revisit any domain where you miss more than a couple of questions

This is only a scaffold. For a fuller plan including resource suggestions, use the CHS-CY2 Study Guide 2026, and keep the CHS-CY2 Cheat Sheet handy for last-minute review of must-know facts.

Level 2 Is Not Level 1 With a New Label

A common mistake is to assume Level 2 is simply a slightly harder version of Level 1 and to prepare using Level 1 material. The official guidance is clear that Level 2 exam topics are distinct from the recommended course curriculum and should not be replaced by Level 1 content. In other words, reviewing introductory cybersecurity notes will not cover what Level 2 asks.

Preparation choiceWhy it helps or hurts
Studying the five published Level 2 domainsMatches what the exam actually tests
Taking the recommended Advanced Cybersecurity courseRecommended by CodeHS, but not required
Reusing Level 1 notes as your main sourceLeaves gaps in cryptography, networking, and risk topics
Practicing with timed multiple-choice questionsBuilds familiarity with the 45-question, 90-minute format

To go deeper on the general topic from several angles, you can also read What Is CHS-CY2?, CHS-CY2 Certification, and CHS-CY2 Training.

Frequently Asked Questions

What is a CHS-CY2?

CHS-CY2 is the CodeHS Cybersecurity Level 2 certification exam. It is an online, timed test with 45 multiple-choice questions and a 90-minute limit, covering advanced cryptography, networking, cyber defense, documentation, and risk management.

What score do I need to pass?

The passing score is 60%. Because the exam has 45 questions, that means you need to answer a little over half correctly with some margin; confirm the exact scoring treatment in the official CodeHS exam overview.

Do I need to complete a course first?

No. There are no specific prerequisites. CodeHS recommends its Advanced Cybersecurity course as preparation, but it is not required to register for the exam.

Can I retake the exam if I do not pass?

Yes. Students can retake the exam as needed, but each attempt requires a new voucher because each voucher code is valid for only one attempt.

How long does the certification last?

Certifications earned through CodeHS expire after 10 years, so a Level 2 certification remains valid for a decade from the date it is earned.

Ready to pass your CHS-CY2 exam?

Put this into practice with free CHS-CY2 questions across every exam domain.