- What the JNCIS-SEC Credential Actually Is
- JN0-336 at a Glance
- The Seven Exam Domains
- Prerequisites and Where It Sits in the Security Track
- Registration, Delivery and Results
- Passing Score and Cost: What Is and Is Not Known
- Retakes, Validity and Renewal
- Who Benefits From This Credential
- Sequencing Your Preparation by Domain
- Frequently Asked Questions
- JNCIS-SEC is Juniper's written specialist security exam, JN0-336, based on Junos OS 24.4 and replacing JN0-335 on September 2, 2025.
- The exam has 65 multiple-choice questions in 90 minutes, delivered in English through Pearson VUE test centers or OnVUE.
- Seven unweighted domains run from IDP and IPsec VPN through ATP Cloud, HA clustering, JIMS, SSL Proxy and Security Director.
- An active JNCIA-SEC is the prerequisite, and the credential stays valid for three years.
What the JNCIS-SEC Credential Actually Is
JNCIS-SEC stands for Juniper Networks Certified Specialist, Security. It is the mid-level written credential in Juniper's security certification track, positioned above the associate-level JNCIA-SEC and aimed at engineers who deploy and operate SRX Series firewalls and the surrounding security ecosystem. Juniper is now branded under HPE as HPE Juniper Networking, and the broader program is being renamed the HPE Networking Certification Program, but the credential itself is the same Juniper Networks Certified Specialist, Security certification.
The exam code to know is JN0-336, built against Junos OS 24.4. If you see study material, forum posts, or practice banks that reference JN0-335, that is the retired predecessor. JN0-335 was retired on September 1, 2025, and JN0-336 became available the next day, with Juniper's announcement published on July 24, 2025. Anything written for the older exam, including older descriptions of its question count, should be treated with caution rather than assumed to apply today.
It is also worth being clear about what this credential is not. JNCIS-SEC is a written, multiple-choice specialist exam. It is not an expert-level practical lab, and it does not require you to configure a live device in front of a proctor. That said, the questions are written to probe whether you understand configuration, monitoring and troubleshooting well enough to reason about real SRX behavior, so hands-on familiarity pays off even though the format is knowledge-based. For a deeper look at the credential's naming and meaning, see our explainer on what JNCIS-SEC stands for.
JN0-336 at a Glance
| Attribute | Detail |
|---|---|
| Credential | Juniper Networks Certified Specialist, Security (JNCIS-SEC) |
| Exam code | JN0-336 |
| Junos version basis | Junos OS 24.4 |
| Format | 65 multiple-choice questions |
| Time allowed | 90 minutes |
| Language | English |
| Prerequisite | Active JNCIA-SEC |
| Delivery | Pearson VUE test centers or eligible OnVUE online delivery |
| Validity | Three years |
| Predecessor | JN0-335, retired September 1, 2025 |
One detail the published exam details do not settle is how many of the 65 questions are scored versus unscored. Do not assume every question counts, and do not try to game which ones might not. Treat each question as live.
A useful pacing note: 90 minutes for 65 questions leaves a little under a minute and a half per question on average. Scenario-style items that describe a topology, a log excerpt, or a configuration fragment will eat more time than definition-style items, so the practical goal is to bank time on the quick ones. If you want a candid read on how demanding this is, our guide on how hard the JNCIS-SEC exam is goes through the difficulty factors.
The Seven Exam Domains
Juniper publishes seven domain headings for JN0-336, and none of them carry a published percentage weight. That matters: you cannot allocate study hours by weight, and you should not trust any third-party site that claims to know a precise percentage split. The published table is also high-level, so it does not establish exhaustive command-by-command coverage. For domains one through six, the stated expectation is conceptual understanding plus knowledge of configuration, monitoring and troubleshooting. Domain seven is framed around concepts, features and functionality rather than an added troubleshooting objective.
Domain 1: Intrusion Detection and Prevention (IDP)
This domain covers how SRX devices detect and block attacks using signature-based inspection.
- IDP database management, including how the signature database is obtained and kept current
- IDP policies, including how rules and actions are structured and applied
- Configuration, monitoring and troubleshooting of IDP behavior
Domain 2: IPsec VPN
A core domain for anyone connecting sites or remote users through SRX gateways.
- IPsec tunnel establishment and IPsec traffic processing
- Site-to-site VPNs
- Juniper Secure Connect
- VPN benefits and operation, which this domain expressly calls out
Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
The cloud-delivered threat analysis service, and a domain with unusually broad subtopics.
- Supported files and ATP Cloud components
- Security feeds, traffic remediation and workflow
- Encrypted Traffic Insights (ETI)
- DNS and IoT security
- Adaptive threat profiling
Domain 4: High Availability (HA) Clustering
Chassis clustering concepts and operation on SRX devices.
- HA features and characteristics
- Deployment requirements and considerations
- Chassis-cluster characteristics and operation
- Real-time object and state synchronization
Domain 5: Identity-Aware Security Policies
Tying policy decisions to user identity rather than only to addresses.
- Juniper Identity Management Service (JIMS)
- Ports and protocols involved
- Data flow between the identity source and the firewall
Domain 6: SSL Proxy
Inspecting encrypted traffic by terminating and re-establishing TLS sessions.
- SSL Proxy certificates
- Client protection and server protection
Domain 7: Security Director
Centralized management through Junos Space Security Director.
- Deployment options
- Device onboarding
- Security-policy management
Candidates who built their mental model from older material often under-prepare for the later domains. Identity-aware policies, SSL Proxy and Security Director are easy to dismiss as peripheral, yet each is a named domain, and the ATP Cloud domain in particular has grown to include ETI, DNS and IoT security, and adaptive threat profiling. A full walkthrough of all seven is available in our JNCIS-SEC exam domains guide.
Prerequisites and Where It Sits in the Security Track
The stated prerequisite for JNCIS-SEC is an active JNCIA-SEC. This is a point candidates sometimes get wrong: it is JNCIA-SEC, the associate-level security certification, and not JNCIA-Junos. Beyond the certification gate, intermediate Junos and SRX knowledge is expected. The exam assumes you are comfortable with the Junos CLI, security zones, security policies, and basic SRX flow behavior, because the specialist-level questions build on those fundamentals without re-teaching them.
Juniper recommends its Juniper Security training course, a four-day offering, as preparation. It is recommended, not a mandatory admission requirement, so you can sit the exam without having attended. The course is built on Junos 24.2R1, Junos Space and Security Director 23.1R1, and JIMS 1.7.0R2. Those are the lab and course software versions, not the exam specification; the exam itself is defined against Junos OS 24.4. Do not conflate the two when you compare notes with someone who took the course.
| Question | JNCIA-SEC | JNCIS-SEC |
|---|---|---|
| Level | Associate | Specialist |
| Role in the track | Entry gate and prerequisite | Mid-level written credential |
| Depth | Foundational SRX and security concepts | Configuration, monitoring and troubleshooting across seven feature domains |
For the full eligibility picture, read our page on JNCIS-SEC requirements.
Registration, Delivery and Results
JNCIS-SEC is administered through Pearson VUE, either at a test center or via eligible OnVUE online proctored delivery. There is an important program transition to plan around: from September 15, 2026, the program is named the HPE Networking Certification Program, and written examinations are scheduled, managed and launched through Alpine CertMetrics using an hpe.com login. These are registration and branding changes; they do not turn JNCIS-SEC into a different credential. If you are booking near that date, check which system your appointment actually sits in.
Practical requirements to prepare for:
- Identification: matching government-issued photo and signature identification is required.
- OnVUE testing space: a compliant private space with no books or notes. Delivery and identity requirements should be checked for your specific appointment before test day.
- Results: immediate results are provisional. Validated results normally appear in CertMetrics within three business days.
- Cancellation: the policy refers to one business day, and forfeiture applies inside 24 hours. Do not assume these two statements are equivalent across weekends or holidays; follow the deadline stated by the provider for your booking.
For scheduling windows and timing considerations, see our guide to JNCIS-SEC exam dates.
Passing Score and Cost: What Is and Is Not Known
This is where a lot of web content overreaches, so precision helps.
On cost, no current retail checkout fee for JN0-336 could be verified, because the provider's linked voucher-store page did not yield a usable price. A 2021 statement from program staff mentioned USD 300, but that is historical and is not evidence of today's fee. Free training offers, voucher assessments and Open Learning materials do not establish the retail exam price either. The safe approach is to confirm the current price directly in the provider's checkout before budgeting. Our pages on the JNCIS-SEC passing score and JNCIS-SEC certification cost keep these distinctions in one place.
Likewise, there is no verified public pass rate to quote, so be skeptical of any site that cites one. Our pass rate analysis explains what can and cannot be said.
Retakes, Validity and Renewal
Retake rules
- After the first failed written attempt, there is no mandated waiting interval.
- After the second or any subsequent failure, you wait 14 calendar days, counting from the day after the failure.
- After passing, you must wait at least 18 months before retaking the same exam.
Validity and renewal
The certification is active for three years. To renew, you can pass the applicable current exam, earn a higher certification in the Security track, or complete an eligible designated course at the same or higher level. The Juniper Security course explicitly lists JNCIS-SEC renewal. If the credential lapses entirely, the track must be restarted under published policy. There is no generic continuing-education credit quota for this credential, so ignore any claim of one.
Who Benefits From This Credential
JNCIS-SEC is relevant to people who work hands-on with Juniper SRX firewalls and the products built around them. Typical roles include network security engineers, firewall administrators, security operations staff who manage VPNs and threat-prevention policy, and engineers at managed service providers and integrators that support Juniper environments. It also suits engineers moving from the associate level who want a credential that reflects deployment and operational skill across IDP, VPN, advanced threat prevention, clustering, identity and centralized management.
Be realistic about the market signal. Employers value Juniper credentials most where Juniper security gear is actually deployed, and the certification demonstrates structured knowledge rather than guaranteeing a particular outcome. There is no verified salary figure attributable to this credential alone, and attributing a pay increase to it would be unsupported. For a measured discussion, see our analysis of whether the JNCIS-SEC is worth it, our salary guide, and the page on JNCIS-SEC jobs.
Sequencing Your Preparation by Domain
Generic study advice matters less than ordering the material sensibly. A reasonable sequence puts foundational flow and policy concepts first, then the domains that rely on them. Because the domains are unweighted, give each one real attention rather than skipping any.
IPsec VPN and IDP
- Walk through IPsec tunnel establishment and traffic processing before touching Secure Connect
- Review IDP policies and signature database management
HA Clustering and Identity-Aware Policies
- Learn chassis-cluster operation and real-time object and state synchronization
- Map the JIMS data flow, ports and protocols
ATP Cloud and SSL Proxy
- Cover ATP Cloud components, feeds, remediation, ETI, DNS and IoT security, and adaptive threat profiling
- Study SSL Proxy certificates and client versus server protection
Security Director and Review
- Review deployment options, device onboarding and policy management
- Use independently written knowledge questions to find weak domains
A few specifics are worth emphasizing. Start with IPsec because VPN logic recurs in other topics and it is one of the most configuration-heavy areas. Pair HA clustering with identity because both reward careful reasoning about state and data flow. Leave ATP Cloud for the middle of your plan since its subtopic list is long and benefits from a focused, uninterrupted pass. For a fuller schedule, use our JNCIS-SEC study guide, and keep the JNCIS-SEC cheat sheet handy for last-week review.
Key Takeaway
Practice questions are supplementary knowledge preparation, not a hands-on competence test and not a preview of actual exam questions. Use them to expose gaps, then close those gaps with the Junos 24.4 documentation and lab time. Our practice test platform offers independently written questions organized by these seven domains.
If you want free and low-cost preparation, Juniper's Open Learning material and voucher assessments are public starting points, though they do not establish the retail exam price or the live passing score. For structured instruction, see our overview of JNCIS-SEC training, and when you are ready to test your retention, try the JNCIS-SEC practice exams.
Frequently Asked Questions
You take JN0-336, the written specialist exam based on Junos OS 24.4. It replaced JN0-335, which was retired on September 1, 2025. JN0-336 began on September 2, 2025.
The exam has 65 multiple-choice questions and a 90-minute time limit, delivered in English. The split between scored and unscored questions is not established, so treat every question as counting.
The prerequisite is an active JNCIA-SEC, not JNCIA-Junos. Intermediate Junos and SRX knowledge is also expected. Juniper's four-day Security course is recommended but not required for admission.
The live passing threshold is exam-specific and not published as a universal percentage; the 70% figure on the official practice assessment is not necessarily the certification cutoff. No current retail fee was verified, so confirm the price at checkout.
It is active for three years. You can renew by passing the applicable current exam, earning a higher Security-track certification, or completing an eligible designated course such as the Juniper Security course. An expired credential means restarting the track.