- JNCIS-SEC Requirements at a Glance
- The One Hard Prerequisite: Active JNCIA-SEC
- Skills Juniper Expects You to Bring
- Training Is Recommended, Not Required
- What the JN0-336 Exam Actually Covers
- Exam Format and Delivery Requirements
- Registration Changes Coming September 15, 2026
- Retake Rules, Validity and Renewal
- A Domain-Ordered Plan to Qualify
- Frequently Asked Questions
- The formal prerequisite for JNCIS-SEC is an active JNCIA-SEC, not JNCIA-Junos.
- The current exam is JN0-336 (Junos OS 24.4): 65 multiple-choice questions in 90 minutes.
- JN0-336 replaced JN0-335 on September 2, 2025; older 75-question descriptions are outdated.
- The recommended four-day Juniper Security course is optional; no admission course is mandatory.
JNCIS-SEC Requirements at a Glance
The Juniper Networks Certified Specialist, Security (JNCIS-SEC) is the mid-level written credential in Juniper's Security track, sitting above the associate level and below the professional tier. Despite the current HPE Juniper Networking and HPE Networking branding around the program, the credential and its requirements remain those of the Juniper Security Specialist certification, earned by passing a single written exam, JN0-336, based on Junos OS 24.4.
Eligibility is simpler than many candidates expect. There is no minimum number of years of work experience, no mandatory classroom course, and no practical lab. The requirements reduce to a prerequisite certification, a set of expected skills, and the logistics of sitting the exam.
| Requirement | What applies to JNCIS-SEC |
|---|---|
| Prerequisite certification | Active JNCIA-SEC |
| Exam code | JN0-336 (Junos OS 24.4) |
| Format | 65 multiple-choice questions, 90 minutes, English |
| Mandatory training | None; Juniper Security course is recommended |
| Hands-on lab | Not part of this exam; it is a written specialist exam |
| Delivery | Pearson VUE test centers or eligible OnVUE online delivery |
| Credential validity | Three years |
For a broader orientation before you dig into eligibility, see What Is JNCIS-SEC Certification? and the plain-language explainer on what JNCIS-SEC stands for.
The One Hard Prerequisite: Active JNCIA-SEC
The prerequisite that matters is an active JNCIA-SEC, the associate-level Security credential. This is the single most common point of confusion: candidates with only JNCIA-Junos, the general Junos associate certification, assume it satisfies the requirement. It does not. The Security track is gated by the Security associate, and JNCIA-Junos is not a substitute.
If you are weighing the two levels against each other, remember that the associate establishes the foundation (core SRX and security concepts) while the specialist goes deeper into feature-by-feature configuration, monitoring and troubleshooting across seven technology areas. The difficulty gap is covered in How Hard Is the JNCIS-SEC Exam?
Skills Juniper Expects You to Bring
Beyond the certification gate, Juniper expects intermediate Junos and SRX knowledge. That is a practical expectation rather than an enforced requirement, but the exam objectives assume it. In concrete terms, you should already be comfortable with:
- Navigating the Junos CLI, committing and rolling back configuration, and reading operational-mode output
- Security zones, security policies and the flow of a packet through an SRX device
- Basic NAT and interface concepts on SRX Series firewalls
- Reading logs and show commands well enough to diagnose why traffic is or is not passing
Most JNCIS-SEC domains ask for conceptual understanding plus knowledge of configuration, monitoring and troubleshooting. Candidates who learned the associate material only well enough to pass tend to feel the strain here, because the specialist exam rewards operational familiarity, not memorized definitions.
Training Is Recommended, Not Required
Juniper recommends its four-day Juniper Security instructor-led course as preparation, but completing it is not a condition of admission to the exam. You can qualify through self-study, on-the-job experience, lab practice or any mix of these.
The course does carry one useful side benefit: it is explicitly listed as an eligible path for JNCIS-SEC renewal, covered below. For a fuller look at preparation routes, see JNCIS-SEC training options and the planning-focused JNCIS-SEC study guide.
What the JN0-336 Exam Actually Covers
Qualifying means passing an exam with seven objective areas. Juniper's published objectives list these domains without percentage weights, so you cannot assume any domain is smaller than another. The high-level objectives table also does not establish exhaustive command-by-command coverage, so treat the topics below as the published scope rather than a complete command list.
Domain 1: Intrusion Detection and Prevention (IDP)
IDP database management and IDP policies.
- Understand, configure, monitor and troubleshoot signature database updates
- Build and manage IDP policies
Domain 2: IPsec VPN
Tunnel establishment, traffic processing, site-to-site VPNs and Juniper Secure Connect.
- VPN benefits and operation are called out explicitly
- Expect both concepts and configuration, monitoring and troubleshooting
Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
The broadest domain by listed subtopics.
- Supported files and ATP Cloud components
- Security feeds, traffic remediation and workflow
- Encrypted Traffic Insights (ETI)
- DNS and IoT security
- Adaptive threat profiling
Domain 4: High Availability (HA) Clustering
HA features and characteristics, deployment requirements and considerations, chassis-cluster characteristics and operation, and real-time object and state synchronization.
Domain 5: Identity-Aware Security Policies
Juniper Identity Management Service (JIMS), including its ports and protocols and its data flow.
Domain 6: SSL Proxy
SSL Proxy certificates plus client protection and server protection.
Domain 7: Security Director
Junos Space Security Director deployment options, device onboarding and security-policy management.
- Specified at the level of concepts, features and functionality; it does not add a separate troubleshooting objective
Many study resources written for the retired exam stop short of the later domains. Make sure your material covers everything after ATP Cloud: HA clustering, JIMS, SSL Proxy and Security Director are all in scope. For a deeper breakdown of each area, read the complete guide to all seven JNCIS-SEC content areas.
Exam Format and Delivery Requirements
JN0-336 is a written specialist exam: 65 multiple-choice questions, 90 minutes, in English. The split between scored and unscored questions is not established in the published details, so do not rely on claims about it. It is not an expert-level practical lab, and nothing in the exam requires you to configure a live device.
Test center or online
You can sit the exam at a Pearson VUE test center or through eligible OnVUE online delivery. Online delivery requires a compliant, private testing space free of books and notes, and delivery and identity requirements should be checked for your specific appointment. Treat the online room check as part of your eligibility, not an afterthought.
Identification
Matching government-issued photo and signature identification is required. The name on your ID must match the name on your exam registration, so resolve any discrepancy before exam day rather than at the check-in desk.
Results and scoring
Immediate results are provisional. Validated results normally appear in CertMetrics within three business days. The live passing threshold is exam-specific and statistically established; it is not a published universal percentage. A 70% figure associated with the official practice assessment is not necessarily the certification passing score, so do not treat it as the target. See JNCIS-SEC passing score and pass-rate for how to reason about this without inventing numbers.
Registration Changes Coming September 15, 2026
JN0-336 began on September 2, 2025, replacing JN0-335, which retired on September 1, 2025 (the change was announced July 24, 2025). If you are using older materials, check which exam they target; JN0-335 content and its older exam description are not a safe guide to JN0-336.
A second change affects how you register. From September 15, 2026, the program is named the HPE Networking Certification Program, and written exams are scheduled, managed and launched through Alpine CertMetrics using an hpe.com login. These are registration and branding changes only. They do not replace the credential you are pursuing. If you plan to test around or after that date, set up your hpe.com login ahead of time and verify the booking flow so account issues do not delay your appointment. Related scheduling guidance lives on the JNCIS-SEC exam dates page.
Retake Rules, Validity and Renewal
Retakes
- After a first failed attempt: no mandated waiting interval.
- After a second or later failure: wait 14 calendar days, starting the day after the failure.
- After passing: wait at least 18 months before retaking the same exam.
Cancellation
The cancellation policy refers to one business day, with forfeiture inside 24 hours. Do not assume these are equivalent across weekends or holidays; follow the deadline your appointment confirmation states.
Validity and renewal
The certification is active for three years. You can renew before expiry by passing the applicable current exam, earning a higher Security-track certification, or completing an eligible designated same-level or higher-level course; the Juniper Security course explicitly lists JNCIS-SEC renewal. If a credential expires, you restart the track under the published policy. There is no generic CPE-credit quota to accumulate, so ignore advice that assumes one.
Key Takeaway
Put your expiry date on a calendar from the day you pass. Renewing through an eligible course or higher Security-track credential is far easier than restarting the track from the associate level.
A Domain-Ordered Plan to Qualify
Generic scheduling advice matters less than ordering the seven domains sensibly. Because the domains build on shared concepts (certificates, tunnels, policy flow), the sequence below groups related material. Adjust the pace to your experience.
Verify eligibility, then IDP and IPsec VPN
- Confirm your JNCIA-SEC is active
- Work through IDP database management and policies
- Start IPsec tunnel establishment and traffic processing
Finish IPsec, add SSL Proxy
- Site-to-site VPNs and Juniper Secure Connect
- SSL Proxy certificates and client/server protection, which shares certificate concepts with VPN work
ATP Cloud and Identity-Aware policies
- Feeds, remediation, ETI, DNS and IoT security, adaptive threat profiling
- JIMS ports, protocols and data flow
HA clustering, Security Director and review
- Chassis-cluster operation and state synchronization
- Security Director onboarding and policy management
- Timed question sets to check readiness
When you reach the review stage, use independently authored knowledge questions to find weak domains. Be realistic about what they do: they are supplementary preparation for the concepts, configuration, monitoring and troubleshooting knowledge the exam tests, not a hands-on competence assessment and not actual exam questions. You can try our JNCIS-SEC practice tests for domain-by-domain drilling, and keep the JNCIS-SEC cheat sheet handy for last-minute fact review. If you are still deciding whether the effort pays off, the ROI analysis and JNCIS-SEC jobs overview frame the career side without promising a specific outcome.
Frequently Asked Questions
An active JNCIA-SEC is the prerequisite. JNCIA-Junos does not satisfy it. Intermediate Junos and SRX knowledge is also expected, though that is a skills expectation rather than a formal admission check.
No. The four-day Juniper Security course is recommended preparation, not a mandatory admission requirement. It is, however, an eligible path for JNCIS-SEC renewal.
No. JN0-336 is a written specialist exam with 65 multiple-choice questions in 90 minutes. It is not an expert-level practical lab, though questions test configuration, monitoring and troubleshooting knowledge.
It is active for three years. Renew before expiry by passing the applicable current exam, earning a higher Security-track certification, or completing an eligible designated course. An expired credential means restarting the track.
After a first failure there is no mandated wait. After a second or later failure you must wait 14 calendar days, counted from the day after the failure. After passing, wait at least 18 months to retake the same exam.