CHS-CY2 logo
Focused certification exam prep
Start practice

What Is CHS-CY2 Certification?

TL;DR
  • CHS-CY2 is CodeHS Cybersecurity Level 2: 45 multiple-choice questions in 90 minutes, online and timed.
  • The passing score is 60%, and the exam covers five domains published without percentage weights.
  • No prerequisites exist, but CodeHS recommends its Advanced Cybersecurity course as preparation.
  • Every attempt needs a voucher valid for one try; retakes require a new voucher.

What the CHS-CY2 Certification Actually Is

CHS-CY2 stands for CodeHS Cybersecurity Level 2, a certification exam issued by CodeHS for students who have studied intermediate-to-advanced cybersecurity concepts. It sits above the Level 1 cybersecurity certification and tests a wider, more technical set of topics: cryptographic algorithms, network defense devices, malware classification, organizational documentation, and formal risk management.

This is a school-oriented credential rather than a vendor-neutral industry license. It is built around the CodeHS ecosystem, which is widely used in high school and early college computer science and cybersecurity programs. That context shapes everything about it, from the exam length to the way the topics are phrased. If you want the shortest possible definition, our companion pages on what CHS-CY2 is and what CHS-CY2 stands for cover the basics, while this article goes deeper into how the exam is built and how to approach it.

Who Issues It and Where the Official Details Live

CodeHS publishes the authoritative exam information in its help center. Two pages matter most: the Cybersecurity Level 2 Certification overview, which lists the exam topics and format, and the Certifications FAQ, which explains vouchers, retakes, and expiration across all CodeHS certifications. The facts in this article are drawn from those pages, and you should always check them for any change before you register, since exam logistics can be updated.

Why the source matters: Several unrelated credentials in the wider industry abbreviate to similar-looking codes. Fees, domain weights, and pass rates for those exams do not apply here. For CodeHS Cybersecurity Level 2, rely only on CodeHS documentation and on material written specifically for this exam, including the practice questions on our CHS-CY2 practice test site.

Exam Format at a Glance

The exam is straightforward in structure, which is part of why candidates sometimes underestimate it. Here is what CodeHS specifies:

FeatureCHS-CY2 Detail
IssuerCodeHS
DeliveryOnline, timed exam
Question count45 multiple-choice questions
Time limit90 minutes
Passing score60%
PrerequisitesNone required
Recommended preparationCodeHS Advanced Cybersecurity course
Access requirementOne voucher per attempt
Credential lifespan10 years

Ninety minutes for 45 questions works out to two minutes per question, which is generous for recall-style items but tighter for scenario-based ones where you must read a short situation and select the best control, protocol, or response. A 60% threshold means you need to answer at least 27 of the 45 questions correctly. For a deeper look at the cut score and what it means for your margin of error, see our guide to the CHS-CY2 passing score.

The Five Exam Domains

CodeHS publishes the topics for each domain but does not publish percentage weights. That means you cannot safely assume one domain is lighter than another, and you should prepare all five. The full breakdown lives in our complete guide to all five CHS-CY2 content areas; here is the working summary.

Domain 1: Advanced Cryptography

This domain moves past "what is encryption" into how different cipher families and key systems actually work and where each is appropriate.

  • Block ciphers and transposition ciphers, and how they differ from simple substitution
  • Symmetric versus asymmetric encryption, including the speed-versus-key-distribution tradeoff
  • Public key cryptography: public and private key roles in encrypting and signing
  • Hash functions and what makes them useful for integrity checking rather than confidentiality
  • Digital certificates and how they bind an identity to a public key

Domain 2: Advanced Networking

The broadest domain by topic count. It blends network defense hardware, physical security, wireless standards, and mobile device concerns.

  • Network devices: intrusion detection systems (IDS), intrusion prevention systems (IPS), and unified threat management (UTM)
  • Access control models and how permissions are enforced
  • Physical security, including biometrics and mantraps
  • Environmental controls that protect equipment
  • Ports and protocols, with attention to TCP versus UDP behavior
  • Wireless protocols such as 802.11ac
  • Private network constructs: DMZ, VPN, and MAC filtering
  • Mobile device security

Domain 3: Cyber Defense

Here the exam shifts from infrastructure to adversaries and their methods.

  • Threats, vulnerabilities, and exploits, and the distinction between the three terms
  • Malware types and prevention: Trojans, worms, rootkits, and how each spreads or hides
  • Network attacks such as cross-site scripting, DDoS, and botnets
  • Internal attacks and protections involving BIOS, UEFI, and data loss prevention (DLP)

Domain 4: Documentation

This is the least technical domain and the one technically minded candidates most often skim, which is a mistake because the questions reward precise vocabulary.

  • Change management processes
  • Incident response plans and their stages
  • Software licenses and the obligations each type creates
  • Data policy, privacy, and protection

Domain 5: Risk Management

The capstone domain, tying vulnerabilities to business decisions.

  • Types of vulnerabilities
  • Risk assessment: identifying and evaluating risk
  • Risk response strategies
  • Penetration testing and its role in validating defenses

How the Domains Connect

The domains are not isolated silos, and the exam often rewards you for seeing the links. A question about a DMZ (Domain 2) may implicitly test your understanding of why you would isolate public-facing servers after a threat assessment (Domain 5). A question about digital certificates (Domain 1) may touch on VPN authentication (Domain 2). When you study, build small bridges between topics rather than memorizing each bullet in isolation.

Vouchers, Retakes, and Expiration

The registration mechanics are one of the more distinctive features of CodeHS certifications. Instead of paying a testing center at the door, candidates use a voucher. Each voucher code is valid for exactly one exam attempt. If you do not pass, you can retake the exam as many times as you need, but each new attempt requires a new voucher. There is no stated waiting-period rule in the sources we rely on, so confirm current policy in the CodeHS help center before planning back-to-back attempts.

Once earned, the certification is valid for 10 years before it expires, which is a long window compared with many industry credentials that must be renewed every few years. For pricing and how schools or students typically obtain vouchers, see our breakdown of CHS-CY2 certification cost, and for timing and scheduling, our guide to CHS-CY2 exam dates.

Plan around the voucher: Because every attempt consumes a voucher, treat your first sitting as a real attempt rather than a diagnostic. Use practice questions to find weak domains beforehand, so the voucher is spent on a well-prepared attempt rather than on discovering what you do not know.

Who Should Sit for This Exam

CodeHS lists no specific prerequisites, so there is no formal gate to pass through before registering. In practice, the exam is best matched to a particular kind of candidate:

  • Students finishing an Advanced Cybersecurity course. This is the intended audience. The course is CodeHS's recommended preparation, and its content maps closely to the five domains.
  • Students who completed Level 1 and want a stronger credential. Level 2 is the natural next step and demonstrates a deeper command of cryptography, networking, and risk.
  • Self-directed learners with a solid grounding in networking fundamentals who want a structured benchmark.
  • Career explorers weighing whether cybersecurity is a fit before committing to larger industry certifications.

If you are unsure whether you qualify or need to understand the eligibility picture in more detail, our page on CHS-CY2 requirements walks through it step by step.

Why Level 1 Content Is Not Enough

A common trap is assuming that a candidate who earned the Level 1 certification can coast into Level 2 on the same knowledge. CodeHS is explicit that the exam topics are distinct from the recommended course curriculum and should not be replaced by Level 1 content. Level 1 establishes foundations; Level 2 expects you to distinguish between related technologies and pick the right one.

Consider the difference in depth. At an introductory level, you might learn that encryption scrambles data. At Level 2, you need to explain why a system would use asymmetric key exchange to share a symmetric session key, what a digital certificate proves, and why a hash is the right tool for verifying file integrity but the wrong tool for protecting confidentiality. Likewise, you move from knowing that a firewall exists to separating what an IDS does (detects and alerts) from what an IPS does (detects and blocks), and where a UTM appliance consolidates multiple functions.

Key Takeaway

Study the Level 2 topic list directly, not a refreshed copy of Level 1 notes. When two terms sound similar, such as IDS and IPS, or virus and worm, write down the one-sentence distinction. Level 2 questions frequently hinge on exactly that distinction.

What the Credential Is Worth

It helps to be realistic. CHS-CY2 is an educational certification issued by a curriculum provider, not an employer-mandated industry license, and it should not be marketed to yourself as a direct ticket to a specific job title or salary. Its value is more practical and more modest:

  • Verified knowledge. It documents that you mastered a defined set of cybersecurity topics under timed, proctor-style conditions.
  • A stepping stone. The vocabulary and concepts, from public key cryptography to incident response plans, overlap heavily with entry-level industry certifications and with the first year of many cybersecurity degree programs.
  • Portfolio and application material. For students, it strengthens college applications, scholarship essays, internship applications, and entry-level resumes when paired with projects or competitions.
  • Long shelf life. A 10-year validity window means the credential will not lapse while you are still in school or early in your career.

Employers in security-adjacent roles, such as IT help desk, junior security analyst pipelines, managed service providers, and school district technology teams, tend to value demonstrated fundamentals alongside hands-on experience. For a fuller look at the economic side, read our analysis of whether the CHS-CY2 certification is worth it, and for earnings context see the CHS-CY2 salary guide. We deliberately avoid quoting specific pay figures here, since none are published for this credential by CodeHS.

Sequencing Your Preparation by Domain

Because no weights are published, the smartest scheduling logic is about dependency and difficulty rather than percentages. A sensible order is below. It assumes roughly one domain per week with a final review week, but compress or stretch it to fit your calendar.

Week 1

Advanced Cryptography

  • Start here because certificates, VPNs, and secure protocols in later domains all depend on it
  • Build a comparison sheet for symmetric versus asymmetric encryption
  • Practice explaining what each hash function property guarantees
Week 2

Advanced Networking, Part 1

  • Cover IDS, IPS, UTM, DMZ, VPN, and MAC filtering
  • Memorize TCP versus UDP behavior and common port associations
Week 3

Advanced Networking, Part 2

  • Cover physical security (biometrics, mantraps), environmental controls, wireless standards, and mobile device security
  • This domain has the most topics, so the extra week prevents shallow coverage
Week 4

Cyber Defense

  • Classify malware by behavior: Trojan, worm, rootkit
  • Match network attacks like XSS and DDoS to their defenses
  • Review BIOS, UEFI, and DLP as internal-threat topics
Week 5

Documentation and Risk Management

  • Learn the vocabulary of change management, incident response, licenses, and data policy
  • Study risk assessment, risk response, and penetration testing together since they form one workflow
  • Finish with full-length timed practice sets

The reasoning is simple: cryptography underpins networking security, networking underpins attack and defense, and the documentation and risk domains tie everything into organizational practice. For a deeper methodology and a more detailed plan, see the CHS-CY2 study guide, and keep the CHS-CY2 cheat sheet handy for last-day review. When you are ready to test yourself under realistic conditions, the question sets on the main practice test site mirror the multiple-choice, timed format.

Difficulty Expectations

Candidates often ask how demanding the exam is. The honest answer is that the format is forgiving, with 45 multiple-choice questions and a 60% bar, but the content breadth is real. Five domains with dozens of named topics means gaps are easy to hide until exam day. If you want a frank assessment, our article on how hard the CHS-CY2 exam is addresses it, and since CodeHS does not publish pass-rate data, our pass rate discussion explains what can and cannot be said responsibly.

Frequently Asked Questions

What does CHS-CY2 certify?

It certifies knowledge of CodeHS Cybersecurity Level 2 topics across five domains: Advanced Cryptography, Advanced Networking, Cyber Defense, Documentation, and Risk Management. It is issued by CodeHS and delivered as an online timed exam.

How many questions are on the exam and how long do I have?

The exam has 45 multiple-choice questions and a 90-minute timer. You need a score of 60% or higher to pass, which equates to at least 27 correct answers.

Do I need to take Level 1 or another course first?

No specific prerequisites are required. CodeHS does recommend the Advanced Cybersecurity course as preparation, and the exam topics are separate from Level 1 content, so Level 1 knowledge alone will not cover everything tested.

Can I retake the exam if I fail?

Yes. Students can retake the exam as needed, but each attempt requires a new voucher because every voucher code is valid for only one attempt.

How long does the certification last?

Certifications earned through CodeHS expire after 10 years. Always verify the current policy in the CodeHS help center and Certifications FAQ, since program details can be updated.

Ready to pass your CHS-CY2 exam?

Put this into practice with free CHS-CY2 questions across every exam domain.