- What the JNCIS-SEC Credential Actually Is
- JN0-336 at a Glance
- The Seven Domains in Detail
- JN0-336 vs. the Retired JN0-335
- Prerequisites and Training
- Registration, Delivery, and Identity Rules
- Scoring and Cost: What Is and Is Not Known
- Retakes and Renewal
- Sequencing the Domains in Your Study Plan
- Frequently Asked Questions
- JNCIS-SEC is earned by passing JN0-336: 65 multiple-choice questions in 90 minutes, aligned to Junos OS 24.4.
- Seven unweighted domains run from IDP and IPsec VPN through ATP Cloud, HA clustering, JIMS, SSL Proxy, and Security Director.
- Active JNCIA-SEC is the prerequisite, not JNCIA-Junos, and the exam is written, not a practical lab.
- Do not study from JN0-335 material or old 75-question descriptions; JN0-336 replaced it on September 2, 2025.
What the JNCIS-SEC Credential Actually Is
The Juniper Networks Certified Specialist, Security (JNCIS-SEC) is the specialist-level written credential in Juniper's security track. It validates that a candidate understands, and can reason about configuring, monitoring, and troubleshooting, the security features of Junos OS on SRX Series devices and the surrounding Juniper security ecosystem. It sits above the associate-level JNCIA-SEC and below the expert tier, which is assessed differently. If you are still orienting yourself, our explainers on what JNCIS-SEC is and what JNCIS-SEC stands for cover the naming basics.
A branding note matters here. Juniper Networks is now part of HPE, so you will see "HPE Juniper Networking" and, from September 15, 2026, the "HPE Networking Certification Program" on issuer pages. The credential you are pursuing is still Juniper Networks Certified Specialist, Security (JNCIS-SEC). The naming changes affect where you register and log in, not what the certification is.
JN0-336 at a Glance
| Item | Detail |
|---|---|
| Exam code | JN0-336 |
| Software basis | Junos OS 24.4 |
| Format | 65 multiple-choice questions |
| Time limit | 90 minutes |
| Language | English |
| Prerequisite | Active JNCIA-SEC |
| Delivery | Pearson VUE test centers or eligible OnVUE online proctoring |
| Certification validity | Three years |
| Scored vs. unscored split | Not established by published sources |
With 65 questions in 90 minutes, you have a little under a minute and a half per item on average. That is comfortable for recall questions and tight for questions that ask you to interpret configuration snippets or operational output. Practice reading Junos stanzas quickly so you are not decoding syntax under time pressure. For a candid look at relative difficulty, see how hard the JNCIS-SEC exam is.
The Seven Domains in Detail
The issuer's objectives table lists seven domain headings and does not publish weights for any of them. Treat all seven as fair game and do not assume one is "light." The high-level table also does not establish exhaustive command coverage, so a domain's subtopics are the floor of your preparation, not a complete command list. For a domain-by-domain walkthrough, see our complete guide to all 7 JNCIS-SEC content areas.
Domain 1: Intrusion Detection and Prevention (IDP)
Covers IDP database management and IDP policies, with conceptual, configuration, monitoring, and troubleshooting knowledge expected.
- How the signature database is downloaded, updated, and installed on the device
- How IDP policies are built and applied, and how to verify that they are working
- Reading logs and status output to diagnose why traffic was or was not inspected
Domain 2: IPsec VPN
The broadest-sounding domain, covering IPsec tunnel establishment, IPsec traffic processing, site-to-site VPNs, and Juniper Secure Connect. It also expressly covers VPN benefits and operation.
- The phases of tunnel establishment and what each negotiates
- How traffic is matched, encrypted, and forwarded once a tunnel is up
- Site-to-site design, plus Juniper Secure Connect for remote-access scenarios
- Monitoring security associations and troubleshooting tunnels that fail to establish
Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
This domain is wider than its name suggests. The subtopics are supported files, ATP Cloud components, security feeds, traffic remediation, workflow, Encrypted Traffic Insights (ETI), DNS and IoT security, and adaptive threat profiling.
- What file types can be submitted for analysis and how the submission workflow proceeds
- How security feeds and remediation actions influence enforcement on the SRX
- ETI, DNS and IoT security, and adaptive threat profiling are easy to overlook and should not be skipped
Domain 4: High Availability (HA) Clustering
Covers HA features and characteristics, deployment requirements and considerations, chassis-cluster characteristics and operation, and real-time object and state synchronization.
- What a chassis cluster provides and the requirements to deploy one
- How the control and data planes behave in a cluster
- What gets synchronized in real time, and how to verify cluster health
Domain 5: Identity-Aware Security Policies
Centers on Juniper Identity Management Service (JIMS): its ports and protocols, and its data flow.
- How user and device identity information reaches the SRX
- Which ports and protocols JIMS uses, and how the data flows between components
- How identity feeds into security policy decisions, and how to troubleshoot missing identity data
Domain 6: SSL Proxy
Covers SSL Proxy certificates and client and server protection.
- Certificate handling for forward proxy scenarios and why trust matters to end users
- The difference between protecting clients that browse out and servers that are accessed in
- Monitoring and troubleshooting decryption behavior
Domain 7: Security Director
Covers Junos Space Security Director deployment options, device onboarding, and security-policy management. Unlike Domains 1 through 6, this domain specifies concepts, features, and functionality rather than an added troubleshooting objective.
- Deployment options for the management platform
- Onboarding SRX devices so they can be centrally managed
- Managing security policy from the central console
Key Takeaway
Domains 1 through 6 ask you to troubleshoot; Domain 7 asks you to understand concepts and features. Shape your practice accordingly: for the first six, rehearse "what would I check, and what output tells me why?"
JN0-336 vs. the Retired JN0-335
JN0-336 began on September 2, 2025, replacing JN0-335, which retired on September 1, 2025. The change was announced on July 24, 2025. This creates a real trap for self-studiers: older study guides, forum threads, and third-party question sets may describe JN0-335, including a 75-question format that does not match the current 65-question JN0-336. If a resource cites JN0-335, treat its scope and question count as outdated until you have checked them against the current objectives.
| Aspect | JN0-335 (retired) | JN0-336 (current) |
|---|---|---|
| Status | Retired September 1, 2025 | Began September 2, 2025 |
| Question count | Often described as 75 in older material | 65 multiple-choice questions |
| Software basis | Earlier Junos release | Junos OS 24.4 |
| Where to trust scope | Do not use for current prep | Issuer objectives table |
A second version caution: the recommended Juniper Security course uses Junos 24.2R1, Junos Space/Security Director 23.1R1, and JIMS 1.7.0R2. Those are course lab versions and a four-day duration, not the JN0-336 exam specification. Do not infer the exam's version or timing from the course. Our JNCIS-SEC study guide shows how to build a plan around the current objectives rather than legacy material.
Prerequisites and Training
The prerequisite is an active JNCIA-SEC. It is specifically JNCIA-SEC, not JNCIA-Junos. Beyond the formal requirement, intermediate Junos and SRX knowledge is expected: you should already be comfortable with zones, security policies, NAT, and the Junos CLI. Our JNCIS-SEC requirements guide goes deeper on eligibility.
Juniper's Security training is recommended but not a mandatory admission course. The recommended course runs four days. Juniper also offers Open Learning content and a voucher assessment, plus a separate official practice assessment. Keep these distinct: a free training offer or a voucher assessment does not tell you the retail exam fee or the live passing score, and the practice assessment's 70% threshold should not be assumed to be the certification passing score. For more on structured learning paths, see our page on JNCIS-SEC training.
Registration, Delivery, and Identity Rules
You can sit JN0-336 at a Pearson VUE test center or, where eligible, through OnVUE online proctoring. From September 15, 2026, the program is named the HPE Networking Certification Program, and written exams are scheduled, managed, and launched through Alpine CertMetrics using an hpe.com login. Expect your registration experience to differ depending on when you test, and check the current provider instructions before booking. See also our notes on exam dates and scheduling.
- OnVUE: requires a compliant, private testing space without books or notes. Verify the delivery and identity requirements for your specific appointment.
- Identification: matching government-issued photo and signature identification is required.
- Cancellation: the policy refers to one business day, with forfeiture inside 24 hours. Do not assume these are equivalent across weekends or holidays; follow the deadline stated for your appointment.
- Results: immediate results are provisional. Validated results normally appear in CertMetrics within three business days.
Scoring and Cost: What Is and Is Not Known
This is where candidates most often encounter unsupported claims, so precision helps.
Passing score. The live passing threshold is exam-specific and statistically established. There is no published universal percentage. The 70% figure attached to the official practice and voucher assessment is not necessarily the certification passing score. For the full discussion, read our passing score breakdown and the companion piece on pass-rate data.
Exam fee. No current retail checkout fee could be verified, because the provider's linked voucher-store page did not yield a usable price. A USD 300 figure appears in a 2021 statement from program staff, but that is historical, not current fee evidence. Check the voucher store at the time of booking. Our certification cost guide separates verified training offers from unverified exam pricing.
Key Takeaway
Budget for the exam as "price to be confirmed at checkout." Do not plan around a 2021 number or a practice-assessment percentage.
Retakes and Renewal
| Situation | Rule |
|---|---|
| After first failed written attempt | No mandated waiting interval |
| After second or subsequent failure | Wait 14 calendar days, starting the day after the failure |
| After passing | Wait at least 18 months before retaking the same exam |
| Certification validity | Active for three years |
To renew, you can pass the applicable current exam, earn a higher Security-track certification, or complete an eligible designated same-level or higher-level course. The Juniper Security course explicitly lists JNCIS-SEC renewal. If the credential expires, you restart the track under the published policy. There is no generic continuing-education credit quota to track, so do not trust sources that cite one.
If you are weighing whether the investment pays off, our analyses of whether JNCIS-SEC is worth it and the salary picture take a careful look at what can and cannot be attributed to the credential, and our overview of JNCIS-SEC jobs covers the roles where Juniper security skills are valued, typically network and security engineering positions in environments running SRX firewalls.
Sequencing the Domains in Your Study Plan
Because the domains are unweighted, sequence them by dependency and difficulty rather than assumed exam emphasis. A reasonable approach is to build from familiar mechanics toward platform and management topics:
IPsec VPN and IDP
- Start with Domain 2 because tunnel negotiation and troubleshooting underpin much else
- Add Domain 1: signature database management, then IDP policies
SSL Proxy and HA Clustering
- Domain 6 certificates and client/server protection
- Domain 4 chassis-cluster operation and state synchronization; lab time pays off most here
ATP Cloud, JIMS, and Security Director
- Domain 3 has the longest subtopic list; give ETI, DNS and IoT security, and adaptive threat profiling explicit time
- Domain 5 JIMS ports, protocols, and data flow; Domain 7 deployment, onboarding, and policy management
Finish with timed sets of 65 questions in 90 minutes to rehearse pacing. Our one-page cheat sheet is a handy last-week review, and you can pressure-test your recall with the independently authored questions on our JNCIS-SEC practice test site. These are supplementary preparation, not real exam questions.
Frequently Asked Questions
JN0-336, the Security, Specialist exam based on Junos OS 24.4. It has 65 multiple-choice questions, a 90-minute time limit, and is delivered in English through Pearson VUE test centers or eligible OnVUE online proctoring.
An active JNCIA-SEC is the prerequisite, not JNCIA-Junos. Intermediate Junos and SRX knowledge is also expected, and Juniper's Security training is recommended but not required.
The live threshold is exam-specific and statistically established, not a published universal percentage. The 70% on the official practice assessment is not necessarily the certification passing score.
It is active for three years. Renew through the applicable current exam, a higher Security-track certification, or an eligible designated same-level or higher-level course. The Juniper Security course lists JNCIS-SEC renewal.
After a first failure there is no mandated wait. After a second or later failure, you wait 14 calendar days starting the day after. After passing, wait at least 18 months before retaking the same exam.