- What the JN0-336 Blueprint Actually Is
- Exam Format and Question Style
- Domain 1: Intrusion Detection and Prevention (IDP)
- Domain 2: IPsec VPN
- Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
- Domain 4: High Availability (HA) Clustering
- Domain 5: Identity-Aware Security Policies
- Domain 6: SSL Proxy
- Domain 7: Security Director
- Sequencing the Seven Domains
- Registration, Scoring and Retake Facts
- Frequently Asked Questions
- JN0-336 (Junos OS 24.4) lists seven domains, and the issuer table publishes no weights for any of them.
- Domains 1 through 6 expect concepts plus configuration, monitoring and troubleshooting knowledge; Domain 7 specifies concepts, features and functionality.
- The exam is 65 multiple-choice questions in 90 minutes, written in English, with an active JNCIA-SEC as the prerequisite.
- JIMS, SSL Proxy and Security Director are real exam domains, not afterthoughts; do not skip them after finishing ATP Cloud.
What the JN0-336 Blueprint Actually Is
The Juniper Networks Certified Specialist, Security (JNCIS-SEC) is validated by the written exam JN0-336, aligned to Junos OS 24.4. Its objectives are published by Juniper as seven top-level domains. This guide walks through every one of them using the issuer's own subtopic list, so you can build a study plan around what is actually listed rather than around forum rumor.
Two cautions shape how you should read the blueprint. First, the issuer's high-level table does not assign percentage weights to any domain, so any site that quotes domain percentages is supplying numbers the objectives table does not establish. Second, a high-level objectives table does not enumerate every command or output you might be asked about. Treat the domain list as the scope boundary and use hands-on lab time to fill in the detail.
If you are new to the credential itself, start with What Is JNCIS-SEC? and then return here. For a full preparation roadmap that builds on this domain breakdown, see the JNCIS-SEC Study Guide 2026.
Exam Format and Question Style
JN0-336 is a written specialist exam, not a practical lab. You answer 65 multiple-choice questions in 90 minutes, in English. The scored versus unscored split is not established in the published details, so do not assume every question counts or that some are removable. Pace yourself at roughly 80 seconds per question to leave a review buffer.
The question style tests whether you understand a feature well enough to configure it, read its monitoring output and reason about why it is failing. Because Domains 1 through 6 expressly pair conceptual understanding with configuration, monitoring and troubleshooting knowledge, expect scenarios such as interpreting a status output, spotting a mismatched parameter, or choosing the correct sequence of events. That is knowledge of those tasks, not a hands-on performance test, but candidates who have actually typed the commands on an SRX tend to read these questions faster.
Prerequisites matter too: an active JNCIA-SEC is required, and intermediate Junos and SRX knowledge is expected. Details are covered in JNCIS-SEC Requirements 2026. If you want a sense of difficulty before committing, read How Hard Is the JNCIS-SEC Exam?
Domain 1: Intrusion Detection and Prevention (IDP)
Intrusion Detection and Prevention (IDP)
The issuer maps this domain to two subtopics: IDP database management and IDP policies. You need the concepts plus configuration, monitoring and troubleshooting knowledge for each.
- IDP database management: how the signature database is obtained, updated and kept current on the device, and how to verify what version is installed.
- IDP policies: how policies are structured, how rules match traffic and apply actions, and how a policy is activated and monitored.
The trap in this domain is treating IDP as a pure feature checklist. Questions tend to reward understanding of the workflow: a database that never updated explains why a policy "does nothing," and a policy that exists but is not applied to the relevant traffic explains missing detections. Practice reading status and attack-event output so that you can tell a configuration gap from a content gap.
Domain 2: IPsec VPN
IPsec VPN
This domain is the broadest of the networking-focused areas. The issuer lists IPsec tunnel establishment, IPsec traffic processing, site-to-site VPNs, and Juniper Secure Connect. It also expressly covers VPN benefits and operation, alongside the usual concepts, configuration, monitoring and troubleshooting.
- Tunnel establishment: the negotiation phases, what each side must agree on, and where a mismatch breaks the tunnel.
- Traffic processing: how traffic is matched to a tunnel, encrypted, encapsulated and decrypted on the receiving end.
- Site-to-site VPNs: the configuration building blocks and the checks you run when a tunnel is up but traffic does not flow.
- Juniper Secure Connect: the remote-access VPN solution, its purpose and how it differs from a site-to-site design.
Troubleshooting questions here usually hinge on a single mismatched value or a missing policy and route. Learn to distinguish "tunnel will not establish" symptoms from "tunnel established but no traffic passes" symptoms, because the fix lives in different parts of the configuration.
Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
Juniper Advanced Threat Prevention (ATP) Cloud
This is the domain with the most listed subtopics, which is why it deserves a dedicated block of study time. The issuer lists:
- Supported files
- ATP Cloud components
- Security feeds
- Traffic remediation
- Workflow
- Encrypted Traffic Insights (ETI)
- DNS and IoT security
- Adaptive threat profiling
Candidates frequently stop at file-based malware analysis and miss the later topics. ETI, DNS and IoT security, and adaptive threat profiling are explicitly in scope, so you should be able to explain what each one does, what problem it addresses and how it fits into the overall ATP Cloud workflow. Understand how a file moves from the firewall to the cloud, what verdicts come back, and how remediation is applied to traffic and hosts.
For additional context on how this and the other domains fit together in a review plan, the JNCIS-SEC Cheat Sheet is a useful one-page refresher once you have worked through the detail.
Domain 4: High Availability (HA) Clustering
High Availability (HA) Clustering
The issuer lists HA features and characteristics, deployment requirements and considerations, chassis-cluster characteristics and operation, and real-time object and state synchronization.
- HA features and characteristics: what high availability provides and the properties that distinguish a cluster design.
- Deployment requirements and considerations: what must be true of the hardware, software and connectivity before a cluster will form and behave correctly.
- Chassis-cluster characteristics and operation: how nodes behave, how roles and redundancy are determined, and how failover is observed.
- Real-time object and state synchronization: what state is shared between nodes so sessions can survive a failover.
Exam scenarios in this area often present a cluster symptom and ask you to reason about cause: a node that will not join, an unexpected failover, or state that did not carry over. Knowing what is synchronized in real time, and what is not, lets you predict what a user would experience during a failover.
Domain 5: Identity-Aware Security Policies
Identity-Aware Security Policies
This domain centers on Juniper Identity Management Service (JIMS), with the issuer listing JIMS itself, its ports and protocols, and its data flow.
- JIMS: what the service does and why identity information is brought into security policy decisions.
- Ports and protocols: the communication paths involved, which is a common source of fact-recall questions and of real-world connectivity faults.
- Data flow: how identity information travels from its source to the firewall so that policies can use it.
Because the listed subtopics are narrow, this can be one of the more efficient domains to master. Draw the data flow from memory: who collects identity events, who consumes them, and over what protocols. If you can sketch that and explain where a break would appear, you are well prepared.
Domain 6: SSL Proxy
SSL Proxy
The issuer lists SSL Proxy certificates and client and server protection, again with concepts plus configuration, monitoring and troubleshooting knowledge.
- Certificates: the role certificates play in inspection, how they are used and the trust issues that arise when they are not deployed correctly.
- Client and server protection: the two directions of SSL Proxy and the differences in how each is configured and what each protects.
The conceptual distinction between protecting clients and protecting servers is a favorite topic for scenario questions. Be ready to explain which mode applies when internal users browse external sites versus when external users connect to an internal service, and what certificate arrangement each requires.
Domain 7: Security Director
Security Director
The issuer lists Junos Space Security Director deployment options, device onboarding, and security-policy management. Note the wording difference: this domain specifies concepts, features and functionality rather than an added troubleshooting objective.
- Deployment options: the ways Security Director can be deployed and the considerations behind each.
- Device onboarding: how managed devices are brought under central management.
- Security-policy management: how policy is created, organized and pushed through the management platform.
Because this is the last domain on the list, it is the one most often rushed. Do not let that happen: it is a full domain in the objectives table and appears under its own heading.
Sequencing the Seven Domains
Since the blueprint gives no weights, the sensible approach is to sequence by dependency and by lab effort rather than by guessed importance. Here is one workable order tied to the domain content above.
IPsec VPN
- Build and break a site-to-site tunnel; learn establishment versus traffic-processing failures.
- Read up on Juniper Secure Connect and how it differs from site-to-site.
HA Clustering and IDP
- Study cluster requirements, operation and real-time synchronization.
- Cover IDP database management and policies.
ATP Cloud
- Work through all eight listed subtopics, especially ETI, DNS and IoT security, and adaptive threat profiling.
JIMS, SSL Proxy, Security Director and review
- Sketch the JIMS data flow, rehearse SSL Proxy client versus server protection, and review Security Director onboarding and policy management.
- Finish with mixed-domain practice questions and weak-area review.
Adjust the pace to your own experience. A candidate who already administers clusters daily can compress Week 2; someone who has never touched ATP Cloud should expand Week 3. The recommended Juniper Security course is four days and is recommended rather than mandatory, so it is a helpful accelerator if your employer or budget allows. More on training options appears in JNCIS-SEC Training.
Key Takeaway
Because no domain weights are published, do not skip any of the seven. The four headings after ATP Cloud (HA Clustering, Identity-Aware Security Policies, SSL Proxy and Security Director) are each full domains, and a balanced plan beats an over-investment in the first three.
Registration, Scoring and Retake Facts
Several practical details affect how you plan around the domains. The exam is delivered through Pearson VUE test centers or eligible OnVUE online delivery. From September 15, 2026, the program is named the HPE Networking Certification Program, and written exams are scheduled, managed and launched through Alpine CertMetrics using an hpe.com login. These branding and registration changes do not change which credential you are pursuing.
| Topic | What is established |
|---|---|
| Exam code and version | JN0-336, Junos OS 24.4 |
| Format | 65 multiple-choice questions, 90 minutes, English |
| Prerequisite | Active JNCIA-SEC (not JNCIA-Junos) |
| Passing threshold | Exam-specific and statistically established; no universal published percentage |
| Retail exam fee | No current checkout price was verified; an older USD 300 figure is historical only |
| Retakes | No mandated wait after a first failure; 14 calendar days after the second or later failure; at least 18 months after passing before retaking the same exam |
| Validity | Active for three years; renew via the current exam, a higher Security-track certification or an eligible designated course |
On scoring, be careful with numbers you find online. The 70% threshold on the official practice or voucher assessment is not necessarily the certification passing score, so do not treat it as your target for the live exam. See JNCIS-SEC Passing Score 2026 for the full discussion, and JNCIS-SEC Certification Cost 2026 for how verified training offers differ from the unverified retail exam price.
For online delivery, you need a compliant private testing space without books or notes, and matching government-issued photo and signature identification. Immediate results are provisional; validated results normally appear in CertMetrics within three business days. Confirm current scheduling windows in JNCIS-SEC Exam Dates 2026.
Frequently Asked Questions
The JN0-336 objectives list seven domains: IDP, IPsec VPN, ATP Cloud, HA Clustering, Identity-Aware Security Policies, SSL Proxy and Security Director. The issuer's table does not publish percentage weights for any of them.
No. JN0-336 began September 2, 2025, replacing JN0-335 after its September 1, 2025 retirement. JN0-336 is aligned to Junos OS 24.4 and has 65 questions, so material written for the retired exam may not match.
Domains 1 through 6 expect concepts plus configuration, monitoring and troubleshooting knowledge. Domain 7, Security Director, specifies concepts, features and functionality rather than an added troubleshooting objective. This is knowledge tested through multiple-choice questions, not a hands-on lab.
An active JNCIA-SEC is the prerequisite, not JNCIA-Junos, and intermediate Junos and SRX knowledge is expected. The Juniper Security training course is recommended but not required for admission.
Our JNCIS-SEC practice tests offer independently authored supplementary questions organized around these seven domains. They are knowledge preparation, not actual exam questions or a measure of hands-on competence, and they work best alongside lab practice and the official objectives.
With the seven domains mapped, your next step is a realistic plan: confirm your prerequisite status, schedule lab time for IPsec, HA and ATP Cloud, and give JIMS, SSL Proxy and Security Director the same attention you give the headline features. You can then check your readiness with the JNCIS-SEC practice question bank and compare your timeline against the full study guide.