10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free CHS-CY2 questions are organized by exam domain, so you can see how each part of the CodeHS Cybersecurity Level 2 (CHS-CY2) blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Advanced Cryptography - Topics & Concepts Covered: Block and Transposition Ciphers; Asymmetric and Symmetric Encryption; Public Key Cryptography; Hash Functions; Digital Certificates.
Question 1
A security engineer needs to protect stored database passwords so that the original values cannot be recovered even if the password file is exposed. Which cryptographic technique is most appropriate for this purpose?
Show answer & explanation
Correct answer: A - Hashing with a one-way function
Question 2
A company wants employees to securely exchange information with external partners without distributing a shared secret key to every partner. Which approach best supports this requirement?
Show answer & explanation
Correct answer: B - Use public key cryptography with asymmetric keys
A network administrator wants a security device that can detect suspicious traffic patterns and also automatically block malicious activity. Which technology best matches this requirement?
Show answer & explanation
Correct answer: A - An intrusion prevention system (IPS)
Question 4
A company places a public-facing web server in a network segment separated from its internal employee network. What is the primary purpose of this design?
Show answer & explanation
Correct answer: B - To create a DMZ that limits exposure of internal systems
Question 5
A company requires a physical access control point where one door must close before another door opens to prevent unauthorized entry into a secure area. Which control should be implemented?
An attacker injects malicious script into a website comment field so that other visitors execute the script when viewing the page. What type of attack is occurring?
Show answer & explanation
Correct answer: A - Cross-site scripting (XSS)
Question 7
A user installs a free utility application that secretly provides an attacker with unauthorized remote access while appearing legitimate. Which malware category best describes this software?
Show answer & explanation
Correct answer: C - Trojan
Question 8
During an investigation, an organization discovers that sensitive files are being copied to unauthorized external devices. Which security control directly addresses preventing this data loss?
Show answer & explanation
Correct answer: B - Data loss prevention (DLP)
Question 9
A security analyst discovers a previously unknown software flaw that attackers are actively exploiting before a vendor patch exists. This situation is best classified as which type of security issue?
Show answer & explanation
Correct answer: A - A vulnerability being exploited as a zero-day threat
Domain 4: Documentation - Topics & Concepts Covered: Change Management; Incident Response Plans; Software Licenses; Data Policy, Privacy and Protection.
Question 10
A company plans to move a business application to production. Before deployment, the team documents approvals, testing results, rollback procedures, and affected systems. Which practice is being followed?