JNCIS-SEC logo
Focused certification exam prep
Start practice

JNCIS-SEC Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • The exam is JN0-336 on Junos OS 24.4: 65 multiple-choice questions in 90 minutes, English, written format.
  • Active JNCIA-SEC is the prerequisite, and intermediate Junos/SRX knowledge is expected from day one.
  • All seven domains are unweighted in the objectives table, so study each one rather than gambling on favorites.
  • Do not trust old 75-question descriptions or JN0-335 notes; JN0-336 replaced that exam in September 2025.

What You Are Actually Studying For

The Juniper Networks Certified Specialist, Security (JNCIS-SEC) credential validates intermediate-level knowledge of Juniper security platforms running Junos OS. The exam you sit is JN0-336, built against Junos OS 24.4. It is a written, multiple-choice specialist examination, not a practical lab. That distinction shapes everything about how you prepare: you need to recognize correct configurations, interpret monitoring output, and reason through troubleshooting scenarios, but nobody will ask you to build a tunnel live on a box.

Branding has shifted around the credential. Juniper Networks certifications now sit under HPE Juniper Networking and, from September 15, 2026, the HPE Networking Certification Program. The credential itself is unchanged by those naming and registration updates. If you are new to the terminology, our explainers on what JNCIS-SEC certification is and what JNCIS-SEC stands for cover the background.

This guide focuses on the preparation decisions that matter: what the exam covers, where candidates trip on version differences, how to sequence seven very different technology areas, and how to use practice material honestly. For a complete domain-by-domain reference, see the JNCIS-SEC exam domains guide.

Exam Format, Delivery and Registration Mechanics

ItemJN0-336 Detail
Exam codeJN0-336 (Junos OS 24.4)
Question count65 multiple-choice questions
Time limit90 minutes
LanguageEnglish
Scored vs. unscored splitNot established in the published details
FormatWritten specialist exam (not a hands-on lab)
DeliveryPearson VUE test centers or eligible OnVUE online delivery
PrerequisiteActive JNCIA-SEC

Ninety minutes for 65 questions leaves a little under 1.4 minutes per question. That is workable for recognition-style items but tight for questions that present a configuration stanza or a long CLI output and ask what is wrong. Practice reading output quickly rather than line by line.

Test center versus online delivery

You can test at a Pearson VUE center or, where eligible, through OnVUE online proctoring. OnVUE requires a compliant, private testing space with no books or notes, and you should verify the delivery and identity requirements for your specific appointment before exam day. Matching government-issued photo and signature identification is required either way. Names on your registration and your ID must line up.

The September 15, 2026 registration change

From September 15, 2026, written examinations are scheduled, managed and launched through Alpine CertMetrics using an hpe.com login, under the HPE Networking Certification Program name. If you are scheduling around that date, confirm which system your appointment lives in. For timing questions, see JNCIS-SEC exam dates and scheduling.

About the exam fee: We have not verified a current retail checkout price for JN0-336. A figure of USD 300 appears in a 2021 program-staff community statement, but that is historical and should not be treated as today's fee. Check the provider's voucher store at registration time, and see our JNCIS-SEC certification cost breakdown for how we separate verified training offers from unverified prices.

Prerequisites and Training Options

The required prerequisite is an active JNCIA-SEC, not JNCIA-Junos. That is a common point of confusion because the Junos associate certification is the more famous entry point. Beyond the formal requirement, the exam assumes intermediate Junos and SRX knowledge: you should already be comfortable with security zones, security policies, address books, NAT concepts, and the basic flow of traffic through an SRX. If any of that feels shaky, shore it up before attacking the specialist domains. Our JNCIS-SEC requirements guide walks through eligibility in more detail.

Recommended training

Juniper recommends its four-day Juniper Security course, but it is not a mandatory admission course. The course lab environment uses Junos 24.2R1, Junos Space/Security Director 23.1R1 and JIMS 1.7.0R2. Those are course versions, not the JN0-336 exam specification, so do not assume every course screen matches what the Junos 24.4 exam objectives describe. The same course also lists JNCIS-SEC renewal among its benefits.

Free Open Learning material, voucher assessments and training offers exist, and they are useful for preparation, but they do not establish the retail exam fee or the live passing score. For a broader look at courses, see JNCIS-SEC training.

The Seven Domains: What Each One Demands

The published objectives table lists seven domain headings with no weights. Domains 1 through 6 require conceptual understanding plus knowledge of configuration, monitoring and troubleshooting. Domain 7 specifies concepts, features and functionality, without an added troubleshooting objective. The high-level table also does not establish exhaustive command coverage, so treat it as a map, not a command checklist.

Domain 1: Intrusion Detection and Prevention (IDP)

Covers IDP database management and IDP policies.

  • How the IDP signature database is obtained, updated and managed on the device
  • Building IDP policies: rules, match criteria, and the actions applied to matched attacks
  • Monitoring IDP activity and troubleshooting why a policy is or is not matching traffic

Domain 2: IPsec VPN

Covers IPsec tunnel establishment, IPsec traffic processing, site-to-site VPNs, and Juniper Secure Connect. This domain also expressly covers VPN benefits and operation.

  • The phases of tunnel establishment and what each negotiates
  • How traffic is selected, encrypted and processed once a tunnel is up
  • Site-to-site VPN configuration, verification and troubleshooting of failed negotiations
  • Juniper Secure Connect as the remote-access VPN solution

Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud

This is the broadest domain by subtopic count: supported files, ATP Cloud components, security feeds, traffic remediation, workflow, Encrypted Traffic Insights (ETI), DNS and IoT security, and adaptive threat profiling.

  • What file types are supported for analysis and how the submission workflow operates
  • Security feeds and how remediation acts on infected hosts or malicious traffic
  • ETI for threats hidden in encrypted traffic, plus DNS and IoT security features
  • Adaptive threat profiling and how it feeds back into policy

Domain 4: High Availability (HA) Clustering

Covers HA features and characteristics, deployment requirements and considerations, chassis-cluster characteristics and operation, and real-time object and state synchronization.

  • What a chassis cluster provides and the requirements to deploy one
  • How the control and data planes behave across the two nodes
  • What gets synchronized in real time and why that matters during failover
  • Verifying cluster health and troubleshooting a cluster that is degraded

Domain 5: Identity-Aware Security Policies

Covers Juniper Identity Management Service (JIMS), its ports and protocols, and its data flow.

  • What JIMS collects, from where, and how it shares identity information with SRX devices
  • The ports and protocols involved, which is a classic source of precise recall questions
  • How user identity becomes a policy match criterion and how to troubleshoot missing identity data

Domain 6: SSL Proxy

Covers SSL Proxy certificates plus client and server protection.

  • Certificate handling: what the device presents and what clients must trust
  • The difference between protecting clients (forward proxy) and protecting servers (reverse proxy)
  • Configuration, monitoring and troubleshooting of decryption behavior

Domain 7: Security Director

Covers Junos Space Security Director deployment options, device onboarding, and security-policy management, at the level of concepts, features and functionality.

  • Deployment options for Security Director
  • How devices are onboarded and brought under management
  • Managing security policy centrally rather than device by device
Do not skip the back half: Candidates often over-invest in IDP, IPsec and clustering because those are familiar from associate-level study, then treat JIMS, SSL Proxy and Security Director as afterthoughts. Because the objectives table is unweighted, there is no safe domain to ignore. The later topics are exactly where under-prepared candidates lose questions.

Version Traps: JN0-336 vs. Retired JN0-335 Material

JN0-336 began September 2, 2025, replacing JN0-335, which was retired on September 1, 2025. The change was announced July 24, 2025. That timeline matters because a lot of study material online predates it. Watch for these traps:

  • Old question counts. Some older descriptions cite 75 questions. The current exam is 65 questions in 90 minutes.
  • Outdated command examples. Notes written for earlier Junos releases may not reflect Junos OS 24.4 behavior or terminology.
  • Missing later-domain content. Guides that stop after ATP Cloud omit JIMS, SSL Proxy and Security Director entirely. The current objectives include all seven headings.
  • Course versions mistaken for exam versions. The recommended course's Junos 24.2R1, Security Director 23.1R1 and JIMS 1.7.0R2 are training lab versions, not the exam specification.

When you pull any third-party material, check its date and the exam code it targets before investing time in it.

Scoring: Practice Thresholds vs. the Live Exam

The live passing threshold for JN0-336 is exam-specific and statistically established; it is not published as a universal percentage. The official practice and voucher assessment uses a 70% threshold, but that figure is not necessarily the certification passing score. Treating 70% as the real cut line is a mistake in both directions: it may make you overconfident or needlessly anxious.

Results work in two stages. Immediate results at the end of the exam are provisional, and validated results normally appear in CertMetrics within three business days. We do not publish a pass rate because no verified figure exists; our passing score guide and pass rate analysis explain what is and is not known.

Key Takeaway

Aim for consistent mastery across all seven domains rather than a target percentage. Because the live cut score is not a published universal number, the safest strategy is to leave no domain meaningfully weak.

A Domain-Ordered Study Sequence

This is the one place we will talk scheduling, and it is tied to the domains themselves. The logic: start with topics that build on associate-level SRX knowledge, put the densest subtopic list in the middle when you are fresh, and leave centralized management for last because it conceptually depends on understanding the policies it manages.

Week 1

IPsec VPN (Domain 2)

  • Tunnel establishment, traffic processing and site-to-site configuration
  • Juniper Secure Connect and VPN benefits and operation
  • Practice reading VPN status output to diagnose a down tunnel
Week 2

IDP and HA Clustering (Domains 1 and 4)

  • IDP database management and policy construction
  • Chassis-cluster requirements, operation and state synchronization
  • Failover behavior and cluster verification
Week 3

ATP Cloud (Domain 3)

  • Components, supported files, feeds and remediation workflow
  • ETI, DNS and IoT security, adaptive threat profiling
  • Give this domain extra time; it has the longest subtopic list
Week 4

JIMS, SSL Proxy, Security Director (Domains 5, 6, 7)

  • JIMS ports, protocols and data flow
  • SSL Proxy certificates, client and server protection
  • Security Director deployment, onboarding and policy management
Week 5

Integration and review

  • Timed passes through mixed-domain questions at roughly 1.4 minutes each
  • Revisit your weakest domain and re-read the official objectives line by line

A reasonable pace is flexible; stretch the plan if your hands-on SRX experience is limited. For a sense of where candidates find the exam demanding, read how hard the JNCIS-SEC exam is, and keep the JNCIS-SEC cheat sheet handy for last-week review.

Using Practice Questions Without Fooling Yourself

Practice questions are supplementary knowledge preparation. They test whether you can recall and apply concepts around configuration, monitoring and troubleshooting, but they do not measure hands-on competence, and no legitimate resource contains real exam questions. Be wary of anything that advertises "actual exam questions" or dump-style content; it is unreliable and undermines the purpose of certification.

Use practice sets diagnostically:

  1. Take a domain-focused set right after studying that domain, and review every explanation, including the questions you got right.
  2. Track misses by subtopic, not just by domain. Missing "JIMS ports and protocols" is a different fix from missing "ATP Cloud supported files."
  3. Rebuild what you missed in a lab or virtual SRX where you can. Even though the exam is not a lab, seeing configuration and output firsthand makes recognition questions far easier.
  4. Save mixed-domain timed sets for the final week to rehearse pacing.

You can work through original, independently authored questions on our JNCIS-SEC practice tests. They map to the seven domains above and are written as supplementary preparation, not as a mock of the official exam.

Results, Retakes and Renewal

If you do not pass

After a first failed written attempt there is no mandated waiting interval. After a second or any subsequent failure, you must wait 14 calendar days, counting from the day after the failure. After passing, you must wait at least 18 months before retaking the same exam. Cancellation policy refers to one business day, with forfeiture inside 24 hours; do not assume that works out identically across weekends or holidays, and follow the deadline that applies to your appointment.

Keeping the credential active

The certification is active for three years. You can renew before expiry by passing the applicable current exam, earning a higher Security-track certification, or completing an eligible designated same-level or higher-level course. The Juniper Security course explicitly lists JNCIS-SEC renewal. If a credential expires, you restart the track under published policy. There is no generic CPE quota to chase, so do not plan around one.

Career context

The specialist level fits roles that deploy and operate SRX-based security, such as network security engineering and security operations positions in environments running Juniper. We do not attribute any specific salary change to the credential, since no verified figure exists. For a measured discussion, see whether the JNCIS-SEC is worth it, JNCIS-SEC jobs and the salary guide.

Frequently Asked Questions

What is the JNCIS-SEC exam code and format?

The exam is JN0-336, based on Junos OS 24.4. It has 65 multiple-choice questions, a 90-minute time limit, and is delivered in English. It is a written specialist exam, not a practical lab.

Do I need JNCIA-SEC or JNCIA-Junos first?

An active JNCIA-SEC is the prerequisite. JNCIA-Junos alone does not satisfy it. Intermediate Junos and SRX knowledge is also expected.

Are the domains weighted?

No weights are published for the seven domain headings in the objectives table. Plan to cover all of them: IDP, IPsec VPN, ATP Cloud, HA clustering, JIMS-based identity policies, SSL Proxy and Security Director.

What score do I need to pass?

The live passing threshold is exam-specific and statistically established, not a published universal percentage. The 70% figure on the official practice assessment is not necessarily the certification passing score.

Is the Juniper Security course mandatory?

No. The four-day Juniper Security course is recommended, not required. Its lab versions (Junos 24.2R1, Security Director 23.1R1, JIMS 1.7.0R2) differ from the Junos 24.4 exam specification, so use it as training rather than as an exam definition.

For the full picture of the credential, start with our overview of what JNCIS-SEC is, return to this JNCIS-SEC study guide as you plan, and build confidence with domain-by-domain work on the practice test site.

Ready to pass your JNCIS-SEC exam?

Put this into practice with free JNCIS-SEC questions across every exam domain.