JNCIS-SEC logo
Focused certification exam prep
Start practice

JNCIS-SEC Certification

TL;DR
  • JNCIS-SEC is earned by passing JN0-336: 65 multiple-choice questions in 90 minutes, aligned to Junos OS 24.4.
  • Seven unweighted domains run from IDP and IPsec VPN through ATP Cloud, HA clustering, JIMS, SSL Proxy, and Security Director.
  • Active JNCIA-SEC is the prerequisite, not JNCIA-Junos, and the exam is written, not a practical lab.
  • Do not study from JN0-335 material or old 75-question descriptions; JN0-336 replaced it on September 2, 2025.

What the JNCIS-SEC Credential Actually Is

The Juniper Networks Certified Specialist, Security (JNCIS-SEC) is the specialist-level written credential in Juniper's security track. It validates that a candidate understands, and can reason about configuring, monitoring, and troubleshooting, the security features of Junos OS on SRX Series devices and the surrounding Juniper security ecosystem. It sits above the associate-level JNCIA-SEC and below the expert tier, which is assessed differently. If you are still orienting yourself, our explainers on what JNCIS-SEC is and what JNCIS-SEC stands for cover the naming basics.

A branding note matters here. Juniper Networks is now part of HPE, so you will see "HPE Juniper Networking" and, from September 15, 2026, the "HPE Networking Certification Program" on issuer pages. The credential you are pursuing is still Juniper Networks Certified Specialist, Security (JNCIS-SEC). The naming changes affect where you register and log in, not what the certification is.

Written, not practical: JN0-336 is a multiple-choice specialist examination. It is not an expert-level practical lab. That said, the objectives for most domains expect conceptual understanding plus configuration, monitoring, and troubleshooting knowledge, so hands-on time with SRX devices remains the best way to make the written material stick.

JN0-336 at a Glance

ItemDetail
Exam codeJN0-336
Software basisJunos OS 24.4
Format65 multiple-choice questions
Time limit90 minutes
LanguageEnglish
PrerequisiteActive JNCIA-SEC
DeliveryPearson VUE test centers or eligible OnVUE online proctoring
Certification validityThree years
Scored vs. unscored splitNot established by published sources

With 65 questions in 90 minutes, you have a little under a minute and a half per item on average. That is comfortable for recall questions and tight for questions that ask you to interpret configuration snippets or operational output. Practice reading Junos stanzas quickly so you are not decoding syntax under time pressure. For a candid look at relative difficulty, see how hard the JNCIS-SEC exam is.

The Seven Domains in Detail

The issuer's objectives table lists seven domain headings and does not publish weights for any of them. Treat all seven as fair game and do not assume one is "light." The high-level table also does not establish exhaustive command coverage, so a domain's subtopics are the floor of your preparation, not a complete command list. For a domain-by-domain walkthrough, see our complete guide to all 7 JNCIS-SEC content areas.

Domain 1: Intrusion Detection and Prevention (IDP)

Covers IDP database management and IDP policies, with conceptual, configuration, monitoring, and troubleshooting knowledge expected.

  • How the signature database is downloaded, updated, and installed on the device
  • How IDP policies are built and applied, and how to verify that they are working
  • Reading logs and status output to diagnose why traffic was or was not inspected

Domain 2: IPsec VPN

The broadest-sounding domain, covering IPsec tunnel establishment, IPsec traffic processing, site-to-site VPNs, and Juniper Secure Connect. It also expressly covers VPN benefits and operation.

  • The phases of tunnel establishment and what each negotiates
  • How traffic is matched, encrypted, and forwarded once a tunnel is up
  • Site-to-site design, plus Juniper Secure Connect for remote-access scenarios
  • Monitoring security associations and troubleshooting tunnels that fail to establish

Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud

This domain is wider than its name suggests. The subtopics are supported files, ATP Cloud components, security feeds, traffic remediation, workflow, Encrypted Traffic Insights (ETI), DNS and IoT security, and adaptive threat profiling.

  • What file types can be submitted for analysis and how the submission workflow proceeds
  • How security feeds and remediation actions influence enforcement on the SRX
  • ETI, DNS and IoT security, and adaptive threat profiling are easy to overlook and should not be skipped

Domain 4: High Availability (HA) Clustering

Covers HA features and characteristics, deployment requirements and considerations, chassis-cluster characteristics and operation, and real-time object and state synchronization.

  • What a chassis cluster provides and the requirements to deploy one
  • How the control and data planes behave in a cluster
  • What gets synchronized in real time, and how to verify cluster health

Domain 5: Identity-Aware Security Policies

Centers on Juniper Identity Management Service (JIMS): its ports and protocols, and its data flow.

  • How user and device identity information reaches the SRX
  • Which ports and protocols JIMS uses, and how the data flows between components
  • How identity feeds into security policy decisions, and how to troubleshoot missing identity data

Domain 6: SSL Proxy

Covers SSL Proxy certificates and client and server protection.

  • Certificate handling for forward proxy scenarios and why trust matters to end users
  • The difference between protecting clients that browse out and servers that are accessed in
  • Monitoring and troubleshooting decryption behavior

Domain 7: Security Director

Covers Junos Space Security Director deployment options, device onboarding, and security-policy management. Unlike Domains 1 through 6, this domain specifies concepts, features, and functionality rather than an added troubleshooting objective.

  • Deployment options for the management platform
  • Onboarding SRX devices so they can be centrally managed
  • Managing security policy from the central console

Key Takeaway

Domains 1 through 6 ask you to troubleshoot; Domain 7 asks you to understand concepts and features. Shape your practice accordingly: for the first six, rehearse "what would I check, and what output tells me why?"

JN0-336 vs. the Retired JN0-335

JN0-336 began on September 2, 2025, replacing JN0-335, which retired on September 1, 2025. The change was announced on July 24, 2025. This creates a real trap for self-studiers: older study guides, forum threads, and third-party question sets may describe JN0-335, including a 75-question format that does not match the current 65-question JN0-336. If a resource cites JN0-335, treat its scope and question count as outdated until you have checked them against the current objectives.

AspectJN0-335 (retired)JN0-336 (current)
StatusRetired September 1, 2025Began September 2, 2025
Question countOften described as 75 in older material65 multiple-choice questions
Software basisEarlier Junos releaseJunos OS 24.4
Where to trust scopeDo not use for current prepIssuer objectives table

A second version caution: the recommended Juniper Security course uses Junos 24.2R1, Junos Space/Security Director 23.1R1, and JIMS 1.7.0R2. Those are course lab versions and a four-day duration, not the JN0-336 exam specification. Do not infer the exam's version or timing from the course. Our JNCIS-SEC study guide shows how to build a plan around the current objectives rather than legacy material.

Prerequisites and Training

The prerequisite is an active JNCIA-SEC. It is specifically JNCIA-SEC, not JNCIA-Junos. Beyond the formal requirement, intermediate Junos and SRX knowledge is expected: you should already be comfortable with zones, security policies, NAT, and the Junos CLI. Our JNCIS-SEC requirements guide goes deeper on eligibility.

Juniper's Security training is recommended but not a mandatory admission course. The recommended course runs four days. Juniper also offers Open Learning content and a voucher assessment, plus a separate official practice assessment. Keep these distinct: a free training offer or a voucher assessment does not tell you the retail exam fee or the live passing score, and the practice assessment's 70% threshold should not be assumed to be the certification passing score. For more on structured learning paths, see our page on JNCIS-SEC training.

Supplementary practice has limits: Independent knowledge questions on configuration, monitoring, and troubleshooting are useful reinforcement, but they are not a hands-on competence assessment and are not actual exam questions. Pair question practice with lab time on a virtual or physical SRX.

Registration, Delivery, and Identity Rules

You can sit JN0-336 at a Pearson VUE test center or, where eligible, through OnVUE online proctoring. From September 15, 2026, the program is named the HPE Networking Certification Program, and written exams are scheduled, managed, and launched through Alpine CertMetrics using an hpe.com login. Expect your registration experience to differ depending on when you test, and check the current provider instructions before booking. See also our notes on exam dates and scheduling.

  • OnVUE: requires a compliant, private testing space without books or notes. Verify the delivery and identity requirements for your specific appointment.
  • Identification: matching government-issued photo and signature identification is required.
  • Cancellation: the policy refers to one business day, with forfeiture inside 24 hours. Do not assume these are equivalent across weekends or holidays; follow the deadline stated for your appointment.
  • Results: immediate results are provisional. Validated results normally appear in CertMetrics within three business days.

Scoring and Cost: What Is and Is Not Known

This is where candidates most often encounter unsupported claims, so precision helps.

Passing score. The live passing threshold is exam-specific and statistically established. There is no published universal percentage. The 70% figure attached to the official practice and voucher assessment is not necessarily the certification passing score. For the full discussion, read our passing score breakdown and the companion piece on pass-rate data.

Exam fee. No current retail checkout fee could be verified, because the provider's linked voucher-store page did not yield a usable price. A USD 300 figure appears in a 2021 statement from program staff, but that is historical, not current fee evidence. Check the voucher store at the time of booking. Our certification cost guide separates verified training offers from unverified exam pricing.

Key Takeaway

Budget for the exam as "price to be confirmed at checkout." Do not plan around a 2021 number or a practice-assessment percentage.

Retakes and Renewal

SituationRule
After first failed written attemptNo mandated waiting interval
After second or subsequent failureWait 14 calendar days, starting the day after the failure
After passingWait at least 18 months before retaking the same exam
Certification validityActive for three years

To renew, you can pass the applicable current exam, earn a higher Security-track certification, or complete an eligible designated same-level or higher-level course. The Juniper Security course explicitly lists JNCIS-SEC renewal. If the credential expires, you restart the track under the published policy. There is no generic continuing-education credit quota to track, so do not trust sources that cite one.

If you are weighing whether the investment pays off, our analyses of whether JNCIS-SEC is worth it and the salary picture take a careful look at what can and cannot be attributed to the credential, and our overview of JNCIS-SEC jobs covers the roles where Juniper security skills are valued, typically network and security engineering positions in environments running SRX firewalls.

Sequencing the Domains in Your Study Plan

Because the domains are unweighted, sequence them by dependency and difficulty rather than assumed exam emphasis. A reasonable approach is to build from familiar mechanics toward platform and management topics:

Weeks 1-2

IPsec VPN and IDP

  • Start with Domain 2 because tunnel negotiation and troubleshooting underpin much else
  • Add Domain 1: signature database management, then IDP policies
Weeks 3-4

SSL Proxy and HA Clustering

  • Domain 6 certificates and client/server protection
  • Domain 4 chassis-cluster operation and state synchronization; lab time pays off most here
Weeks 5-6

ATP Cloud, JIMS, and Security Director

  • Domain 3 has the longest subtopic list; give ETI, DNS and IoT security, and adaptive threat profiling explicit time
  • Domain 5 JIMS ports, protocols, and data flow; Domain 7 deployment, onboarding, and policy management

Finish with timed sets of 65 questions in 90 minutes to rehearse pacing. Our one-page cheat sheet is a handy last-week review, and you can pressure-test your recall with the independently authored questions on our JNCIS-SEC practice test site. These are supplementary preparation, not real exam questions.

Frequently Asked Questions

What exam do I take to earn JNCIS-SEC?

JN0-336, the Security, Specialist exam based on Junos OS 24.4. It has 65 multiple-choice questions, a 90-minute time limit, and is delivered in English through Pearson VUE test centers or eligible OnVUE online proctoring.

Do I need JNCIA-Junos or JNCIA-SEC first?

An active JNCIA-SEC is the prerequisite, not JNCIA-Junos. Intermediate Junos and SRX knowledge is also expected, and Juniper's Security training is recommended but not required.

What is the passing score?

The live threshold is exam-specific and statistically established, not a published universal percentage. The 70% on the official practice assessment is not necessarily the certification passing score.

How long is the certification valid, and how do I renew?

It is active for three years. Renew through the applicable current exam, a higher Security-track certification, or an eligible designated same-level or higher-level course. The Juniper Security course lists JNCIS-SEC renewal.

Can I retake the exam right away if I fail?

After a first failure there is no mandated wait. After a second or later failure, you wait 14 calendar days starting the day after. After passing, wait at least 18 months before retaking the same exam.

Ready to pass your JNCIS-SEC exam?

Put this into practice with free JNCIS-SEC questions across every exam domain.