- JN0-336 is a 65-question, 90-minute, English multiple-choice exam built on Junos OS 24.4, and it replaced JN0-335 on September 2, 2025.
- Seven domains are listed without published weights: IDP, IPsec VPN, ATP Cloud, HA Clustering, Identity-Aware Policies, SSL Proxy, and Security Director.
- Active JNCIA-SEC is the prerequisite, not JNCIA-Junos, and intermediate Junos/SRX knowledge is expected.
- Retakes: no wait after the first failure, 14 calendar days after later failures, and 18 months after a pass.
The JN0-336 Exam at a Glance
This page condenses the facts a Juniper Networks Certified Specialist, Security (JNCIS-SEC) candidate should be able to recite without notes. The exam code is JN0-336, written against Junos OS 24.4. It is the written specialist examination, not a practical lab, so everything you are tested on arrives as a multiple-choice question about concepts, configuration, monitoring and troubleshooting.
| Item | Verified fact |
|---|---|
| Exam code / release | JN0-336, Junos OS 24.4 |
| Format | 65 multiple-choice questions |
| Time | 90 minutes |
| Language | English |
| Scored vs. unscored split | Not established by the issuer |
| Prerequisite | Active JNCIA-SEC (not JNCIA-Junos) |
| Recommended training | Juniper Security course (recommended, not mandatory) |
| Delivery | Pearson VUE test centers or eligible OnVUE online delivery |
| Certification validity | Three years |
For the eligibility angle in more depth, see our breakdown of JNCIS-SEC requirements, prerequisites and how to qualify. If you are new to the credential itself, What Is JNCIS-SEC? covers the basics.
JN0-336 vs. the Retired JN0-335
A large share of the study material floating around the internet was written for the predecessor. JN0-335 retired on September 1, 2025, and JN0-336 began on September 2, 2025, following an announcement published July 24, 2025. Some older descriptions of the exam cite 75 questions; the current JN0-336 is 65 questions in 90 minutes.
When you evaluate a third-party resource, check whether it names JN0-336 and Junos 24.4. Material that mentions only JN0-335 may omit or misrepresent later topics such as JIMS, SSL Proxy and Security Director. Our JNCIS-SEC study guide explains how to build a plan around the current objectives.
Seven-Domain Cheat Sheet
The issuer's objectives table lists seven domain headings and publishes no weights. Do not assume equal weighting, and do not trust any site that quotes percentages for these domains. Domains 1 through 6 call for conceptual understanding plus knowledge of configuration, monitoring and troubleshooting. Domain 7 specifies concepts, features and functionality, with no added troubleshooting objective. The high-level table also does not establish exhaustive command coverage, so learn the technologies, not just a command list.
| Domain | Subtopics from the objectives |
|---|---|
| 1. Intrusion Detection and Prevention (IDP) | IDP database management; IDP policies |
| 2. IPsec VPN | IPsec tunnel establishment; IPsec traffic processing; site-to-site VPNs; Juniper Secure Connect; VPN benefits and operation |
| 3. Juniper Advanced Threat Prevention (ATP) Cloud | Supported files; ATP Cloud components; security feeds; traffic remediation; workflow; Encrypted Traffic Insights (ETI); DNS and IoT security; adaptive threat profiling |
| 4. High Availability (HA) Clustering | HA features and characteristics; deployment requirements and considerations; chassis-cluster characteristics and operation; real-time object and state synchronization |
| 5. Identity-Aware Security Policies | Juniper Identity Management Service (JIMS); ports and protocols; data flow |
| 6. SSL Proxy | Certificates; client protection; server protection |
| 7. Security Director | Junos Space Security Director deployment options; device onboarding; security-policy management |
For a deeper walk through each area, read JNCIS-SEC Exam Domains: Complete Guide to All 7 Content Areas.
IDP and IPsec Must-Knows
Domain 1: Intrusion Detection and Prevention (IDP)
Two themes: keeping the signature database current and building policies that act on what it finds.
- Know how the IDP database is downloaded, updated and installed, and how to verify which version is active.
- Know how IDP policies are structured and how they are applied through security policy so that matching traffic is inspected.
- Be ready to read monitoring output and decide why an attack was or was not detected or blocked.
Domain 2: IPsec VPN
This domain explicitly covers VPN benefits and operation in addition to the usual configuration and troubleshooting.
- Tunnel establishment: understand the negotiation phases that bring a tunnel up and what a failure at each stage looks like.
- Traffic processing: know how traffic is matched, encrypted, encapsulated and decrypted as it traverses the device.
- Site-to-site VPNs: know the building blocks and how a working configuration fits together.
- Juniper Secure Connect: know its role for remote-access style connectivity and how it differs from a classic site-to-site design.
VPN troubleshooting questions tend to reward a methodical order of thinking: is the tunnel negotiating, are the proposals compatible, is the right traffic selected, and is policy permitting it? Practice reasoning from symptoms to cause. Our guide on how hard the JNCIS-SEC exam is discusses where candidates commonly struggle.
ATP Cloud and Chassis Cluster Must-Knows
Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
This is the broadest domain by subtopic count, and its later subtopics are the ones older material skips.
- Know which file types are supported for submission and analysis, and the components that make up ATP Cloud.
- Know the security feeds and how they feed enforcement, plus how traffic remediation works once a threat is identified.
- Understand the workflow from submission through verdict to action.
- Do not skip the four subtopics after the core ATP Cloud material: Encrypted Traffic Insights (ETI), DNS and IoT security, adaptive threat profiling, and the remediation topics. They are part of the published scope.
Domain 4: High Availability (HA) Clustering
Chassis clustering is a core SRX concept, and this domain tests both the design logic and the operational details.
- Know the characteristics and features of HA, and the deployment requirements and considerations that must be satisfied before a cluster forms.
- Know how a chassis cluster operates and what it means for the control and data planes.
- Understand real-time object and state synchronization: what is synchronized so sessions can survive a failover.
- Be able to interpret monitoring output to judge cluster health and diagnose why a node is not behaving as expected.
JIMS, SSL Proxy and Security Director
Domain 5: Identity-Aware Security Policies
- Know what the Juniper Identity Management Service (JIMS) does and the role it plays in giving policy user and device context.
- Memorize the ports and protocols involved in JIMS communication and be able to trace the data flow from identity source to enforcement point.
- Expect configuration, monitoring and troubleshooting framing: for example, why identity information is not reaching the firewall.
Domain 6: SSL Proxy
- Understand the certificate requirements, since certificates are where most SSL Proxy deployments succeed or fail.
- Know the difference between protecting clients (forward-style inspection of outbound sessions) and protecting servers (inspection of inbound sessions to published services).
- Be able to reason about what an end user sees when a certificate is not trusted.
Domain 7: Security Director
- Know the Junos Space Security Director deployment options.
- Know how devices are onboarded to be managed.
- Know how security policy is managed centrally.
- This domain is scoped to concepts, features and functionality; there is no added troubleshooting objective, so prioritize understanding what the platform does and why.
Registration, Scoring and Retake Rules
Delivery and registration
Exams are delivered through Pearson VUE test centers or eligible OnVUE online delivery. From September 15, 2026, the program is named the HPE Networking Certification Program, and written exams are scheduled, managed and launched through Alpine CertMetrics with an hpe.com login. These changes affect registration and branding; they do not change which credential you are pursuing. For scheduling windows, see JNCIS-SEC exam dates and scheduling.
Identity and online-proctoring rules
- Matching government-issued photo and signature identification is required.
- OnVUE requires a compliant private testing space with no books or notes. Check the delivery and identity requirements for your specific appointment before test day.
- Results shown at the end are provisional; validated results normally appear in CertMetrics within three business days.
Passing score and cost: what is and is not known
Read more in JNCIS-SEC passing score: what you need to pass and JNCIS-SEC certification cost breakdown. For the data on outcomes, see JNCIS-SEC pass rate: what the data shows.
Retake and cancellation rules
| Situation | Rule |
|---|---|
| After first failed attempt | No mandated waiting interval |
| After second or later failure | Wait 14 calendar days, starting the day after the failure |
| After passing | Wait at least 18 months before retaking the same exam |
| Cancellation | Policy refers to one business day, with forfeiture inside 24 hours; follow the applicable provider deadline and do not assume weekends or holidays are treated equivalently |
Validity and Renewal
The certification is active for three years. To renew, you can take the applicable current exam, earn a higher Security-track certification, or complete an eligible designated same-level or higher-level course. The Juniper Security course explicitly lists JNCIS-SEC renewal. If a credential expires, you must restart the track under published policy. There is no generic CPE quota to chase, so ignore any claim of one.
If you are weighing whether the investment makes sense, our analyses of whether JNCIS-SEC is worth it and the JNCIS-SEC salary guide separate verified facts from assumptions. Remember that no specific salary increase can be attributed to the credential alone.
Sequencing the Domains in Your Study Plan
Because the domains are unweighted, spread effort sensibly rather than leaning on guessed percentages. One workable order groups related technologies and front-loads the ones that need lab time. Adjust the pace to your own schedule.
IPsec VPN
- Tunnel establishment, traffic processing, site-to-site design, Juniper Secure Connect.
- Do this first: it has the most configuration and troubleshooting depth and builds on JNCIA-SEC knowledge.
IDP and SSL Proxy
- Both inspect traffic; SSL Proxy certificates determine whether IDP can see inside encrypted sessions.
ATP Cloud and HA Clustering
- Cover every ATP subtopic, including ETI, DNS and IoT security, and adaptive threat profiling, then cluster operation and state synchronization.
JIMS, Security Director and review
- Memorize JIMS ports, protocols and data flow, learn Security Director concepts, then run mixed-domain review.
Key Takeaway
Questions on this exam are knowledge-based. Practice questions can sharpen recall of configuration, monitoring and troubleshooting concepts, but they do not replace hands-on time on an SRX. Use both. You can try independently authored practice items on the main JNCIS-SEC practice test site; they are supplementary preparation, not actual exam questions or an official mock exam.
For free and low-cost preparation routes, our JNCIS-SEC training overview compares options, and the practice question bank lets you drill by domain once you have covered the material.
FAQ
The exam has 65 multiple-choice questions and a 90-minute time limit, delivered in English. Older descriptions citing 75 questions refer to outdated information. The scored versus unscored split is not established.
No. The issuer's objectives table lists seven domain headings without weights, so you should not rely on any percentage breakdown. Prepare for all seven: IDP, IPsec VPN, ATP Cloud, HA Clustering, Identity-Aware Security Policies, SSL Proxy and Security Director.
An active JNCIA-SEC is the prerequisite, not JNCIA-Junos. Intermediate Junos and SRX knowledge is expected. Juniper Security training is recommended but is not a mandatory admission course.
The live passing threshold is exam-specific and statistically established rather than a published universal percentage, and the 70% figure on the practice assessment is not necessarily the certification passing score. No current retail fee was verified, so confirm the price at checkout.
The certification is active for three years; renew through the current exam, a higher Security-track certification or an eligible designated course. If you pass, wait at least 18 months to retake the same exam. After a failure, there is no wait after the first, and 14 calendar days after later failures.