- What the JNCIS-SEC Credential Actually Is
- JN0-336 at a Glance
- The Seven Content Areas
- JN0-336 vs. the Retired JN0-335
- Prerequisites and Expected Skills
- Registration, Delivery and Identity Rules
- Cost and Passing Score: What Is and Isn't Known
- Retakes, Validity and Renewal
- Where the Credential Fits in a Career
- A Domain-Ordered Preparation Sequence
- Frequently Asked Questions
- JNCIS-SEC is the Juniper Networks Certified Specialist, Security credential, earned by passing the 65-question, 90-minute JN0-336 exam.
- JN0-336 is based on Junos OS 24.4 and replaced JN0-335 on September 2, 2025.
- Seven unweighted domains run from IDP and IPsec VPN through ATP Cloud, HA clustering, JIMS, SSL Proxy and Security Director.
- An active JNCIA-SEC is the prerequisite, and the credential stays active for three years.
What the JNCIS-SEC Credential Actually Is
JNCIS-SEC stands for Juniper Networks Certified Specialist, Security. It is the specialist-level written credential in Juniper's Security certification track, sitting above the associate-level JNCIA-SEC and below the expert tier. Passing the JN0-336 exam earns it. The credential tells an employer that you understand how to deploy, configure, monitor and troubleshoot the advanced security features of Junos OS on SRX Series firewalls, and that you grasp the management layer around them.
Juniper's certification program is now delivered under HPE branding. From September 15, 2026, it is called the HPE Networking Certification Program, and written exams are managed through Alpine CertMetrics with an hpe.com login. That is a rename and a change in registration plumbing. The credential you are studying for is still Juniper's Security, Specialist (JNCIS-SEC) certification, and the exam is still JN0-336.
Be careful with the acronym when you search. Other credentials in the industry abbreviate to the same letters, and their exam codes, fees and objectives have nothing to do with Juniper's. Everything on this page refers only to the Juniper exam. If you want the short-form definitions, our pages on what JNCIS-SEC stands for and the JNCIS-SEC meaning cover the naming in more detail.
JN0-336 at a Glance
| Item | JN0-336 detail |
|---|---|
| Credential | Juniper Networks Certified Specialist, Security (JNCIS-SEC) |
| Exam code | JN0-336 |
| Software basis | Junos OS 24.4 |
| Format | 65 multiple-choice questions |
| Time allowed | 90 minutes |
| Language | English |
| Delivery | Pearson VUE test centers or eligible OnVUE online delivery |
| Prerequisite | Active JNCIA-SEC |
| Validity | Three years |
This is a written specialist exam, not a practical lab. You will not be handed a virtual SRX and asked to build a tunnel against a clock. That said, the questions are written to test whether you could do the work: expect scenario wording that asks what a configuration will do, which command confirms a state, or what explains a failure shown in output. The split between scored and unscored questions is not published, so treat all 65 as if they count.
The Seven Content Areas
Juniper's published objectives for JN0-336 are organized into seven domains. None of them carries a published weighting, so you cannot assume that, say, IPsec is worth more than SSL Proxy. The high-level objectives table also does not claim exhaustive command coverage, which means you should study the feature behavior rather than memorize a fixed command list. For a deeper walkthrough, see our complete guide to all seven JNCIS-SEC content areas.
For Domains 1 through 6, the objectives call for conceptual understanding plus knowledge of configuration, monitoring and troubleshooting. Domain 7 is specified as concepts, features and functionality, without an added troubleshooting objective.
Domain 1: Intrusion Detection and Prevention (IDP)
Covers IDP database management and IDP policies.
- How the signature database is obtained, updated and managed on the device
- How IDP policies are constructed and applied to traffic
- Monitoring IDP activity and troubleshooting why traffic was or wasn't matched
Domain 2: IPsec VPN
Covers IPsec tunnel establishment, IPsec traffic processing, site-to-site VPNs and Juniper Secure Connect. This domain also expressly covers the benefits and operation of VPNs.
- The phases of tunnel establishment and what breaks them
- How traffic is processed once a tunnel is up
- Site-to-site VPN design and configuration on SRX devices
- Juniper Secure Connect as the remote-access option
Domain 3: Juniper Advanced Threat Prevention (ATP) Cloud
The broadest domain by subtopic count.
- Supported file types and ATP Cloud components
- Security feeds and traffic remediation
- The ATP Cloud workflow from submission to verdict
- Encrypted Traffic Insights (ETI)
- DNS and IoT security
- Adaptive threat profiling
Domain 4: High Availability (HA) Clustering
Covers HA features and characteristics, deployment requirements and considerations, chassis-cluster characteristics and operation, and real-time object and state synchronization.
- What chassis clustering provides and what it requires
- How cluster members stay in sync so sessions survive failover
- Deployment considerations before you build a cluster
Domain 5: Identity-Aware Security Policies
Centered on Juniper Identity Management Service (JIMS).
- What JIMS does and where it sits in the architecture
- The ports and protocols involved
- The data flow between identity sources, JIMS and the SRX
Domain 6: SSL Proxy
Covers SSL Proxy certificates and client and server protection.
- Certificate handling for inspected sessions
- The difference between protecting clients and protecting servers
- Monitoring and troubleshooting proxied sessions
Domain 7: Security Director
Covers Junos Space Security Director deployment options, device onboarding and security-policy management.
- Deployment options for the management platform
- Onboarding devices into Security Director
- Managing security policy centrally
Notice that the objectives continue well past ATP Cloud. Candidates who stop studying after the first three headline technologies often get surprised by identity-aware policy, SSL Proxy and Security Director. Those last four areas are easy to underweight because they look smaller, but nothing in the published objectives lets you skip them.
JN0-336 vs. the Retired JN0-335
JN0-336 began on September 2, 2025, replacing JN0-335, which retired on September 1, 2025. The change was announced on July 24, 2025. This matters for exam prep because a lot of study material online was written for JN0-335, and it is easy to land on it by accident.
- Check the exam code first. Any guide, video or question set should say JN0-336 and Junos 24.4. If it says JN0-335 or an older Junos release, treat it as background reading only.
- Check the question count. A description with 75 questions is a sign the page is describing older material.
- Do not confuse course versions with exam versions. Juniper's recommended four-day Juniper Security course uses Junos 24.2R1, Junos Space and Security Director 23.1R1 and JIMS 1.7.0R2. Those are the training environment's versions and duration, not the JN0-336 specification. The exam objectives refer to Junos OS 24.4.
Key Takeaway
Build your notes from the current JN0-336 objectives table, not from a forum thread about the old exam. When a feature behaves differently across Junos releases, verify against 24.4 documentation before you commit it to memory.
Prerequisites and Expected Skills
The formal prerequisite is an active JNCIA-SEC. It is not JNCIA-Junos, which is a common mix-up. Beyond the paper requirement, the exam assumes intermediate Junos and SRX knowledge: you should already be comfortable with the Junos CLI, security zones, security policies, NAT concepts and basic troubleshooting before you open the specialist material. Our JNCIS-SEC requirements guide goes through eligibility in more depth, and the comparison of the two levels is worth keeping in mind:
| Aspect | JNCIA-SEC | JNCIS-SEC |
|---|---|---|
| Level | Associate | Specialist |
| Role in the track | Entry point and prerequisite | Advanced security features and management |
| Depth | Foundational concepts | Configuration, monitoring and troubleshooting of advanced features |
Juniper Security training is recommended, not mandatory. You can sit the exam without having taken the course, but the course is the closest structured match to the objectives, and it also counts toward renewal. For a fuller discussion of learning resources, see our JNCIS-SEC training overview.
Registration, Delivery and Identity Rules
You can take the exam at a Pearson VUE test center or through eligible OnVUE online proctoring. With the program rename, written exams are scheduled, managed and launched through Alpine CertMetrics using an hpe.com login, so make sure that account is working before you try to book.
- Online delivery: OnVUE requires a compliant, private testing space with no books or notes. Check the delivery and identity requirements for your specific appointment rather than relying on memory of someone else's experience.
- Identification: You need matching government-issued photo and signature identification. Make sure the name on your ID matches the name on your registration.
- Results: You will see an immediate result, but it is provisional. Validated results normally appear in CertMetrics within three business days.
- Cancellations: The policy refers to one business day, and the appointment is forfeited inside 24 hours. Do not assume those are equivalent across weekends or holidays. Follow the deadline shown for your actual booking.
For scheduling context, our JNCIS-SEC exam dates guide explains how to plan around testing windows.
Cost and Passing Score: What Is and Isn't Known
Two of the most searched questions about this exam are what it costs and what score you need. The honest answer to both is that you should read the live provider pages, because the figures are not established in a way that can be quoted safely.
Exam fee
No current retail checkout fee has been verified. A 2021 statement from program staff cited USD 300, but that is historical and should not be treated as the price today. Free Open Learning content, voucher-based assessments and training offers are separate things and do not tell you what the exam voucher costs. See our JNCIS-SEC certification cost breakdown for how to think about the total outlay without relying on an unverified number.
Passing score
The live passing threshold is exam-specific and statistically established. It is not a published universal percentage. Juniper's official practice assessment uses a 70% threshold, but that figure belongs to the practice assessment and is not necessarily the certification passing score. Anyone quoting a single percentage as the JN0-336 cut score is guessing. Read more in our JNCIS-SEC passing score article, and for the related question of how candidates fare, the JNCIS-SEC pass rate page explains why no trustworthy figure is available.
Retakes, Validity and Renewal
Retake rules
- After a first failed written attempt, there is no mandated waiting interval.
- After a second or subsequent failure, you must wait 14 calendar days, starting the day after the failure.
- After passing, you must wait at least 18 months before retaking the same exam.
Validity and renewal
The certification is active for three years. To renew, you can pass the applicable current exam, earn a higher Security-track certification, or complete an eligible designated course at the same or higher level. The Juniper Security course explicitly lists JNCIS-SEC renewal. If the credential expires, you restart the track under the published policy. There is no generic continuing-education credit quota to track here, so ignore advice that borrows one from other certification programs.
Where the Credential Fits in a Career
JNCIS-SEC is most relevant where Juniper SRX firewalls sit at the network edge or in the data center: managed security service providers, enterprises with established Juniper footprints, service providers, and the integrators and resellers who deploy and support that equipment. Typical roles that ask for this skill set include network security engineer, firewall administrator, security operations engineer and pre-sales or post-sales systems engineer.
The syllabus lines up with day-to-day tasks in those jobs. Building and troubleshooting site-to-site tunnels, tuning IDP policy, wiring up ATP Cloud, running a chassis cluster, integrating identity sources and managing many firewalls through a central console are the jobs themselves, not abstractions. Our pages on JNCIS-SEC jobs and the salary guide discuss the market side. Be cautious with any source that attributes a specific pay increase to the credential, since an individual's pay depends on role, region and experience. For the broader question of return, see whether the certification is worth it.
A Domain-Ordered Preparation Sequence
Because the domains are unweighted, order your study by dependency and by how much hands-on repetition each topic needs, not by assumed exam weight. One workable sequence for someone already holding JNCIA-SEC follows. Our JNCIS-SEC study guide expands on resources for each step.
IPsec VPN (Domain 2)
- Walk through tunnel establishment, then traffic processing
- Configure a site-to-site VPN and read the monitoring output
- Review Juniper Secure Connect
IDP and SSL Proxy (Domains 1 and 6)
- IDP database management and policy construction
- SSL Proxy certificates, then client versus server protection
- Note how encrypted traffic limits what IDP can inspect
ATP Cloud (Domain 3)
- Components, supported files, feeds and remediation
- Workflow, ETI, DNS and IoT security, adaptive threat profiling
HA, JIMS and Security Director (Domains 4, 5, 7)
- Chassis-cluster operation and state synchronization
- JIMS ports, protocols and data flow
- Security Director deployment, onboarding and policy management
Pairing IDP with SSL Proxy makes sense because the two interact, and putting the three newest-feeling areas last in the rotation keeps them fresh for exam day. Then spend the remaining time on timed question sets. Use our JNCIS-SEC practice tests to find weak domains, and keep a one-page recap handy using the JNCIS-SEC cheat sheet.
One limit worth stating plainly: knowledge questions that touch configuration, monitoring and troubleshooting are supplementary preparation. They are independently written, are not actual exam questions, and do not replace time on a real or virtual SRX. If you are unsure how demanding the exam is, our difficulty guide sets out what to expect.
Frequently Asked Questions
You take JN0-336, the Security, Specialist exam based on Junos OS 24.4. It has 65 multiple-choice questions and a 90-minute time limit, delivered in English through Pearson VUE test centers or eligible OnVUE online proctoring.
Yes. An active JNCIA-SEC is the prerequisite, not JNCIA-Junos. The exam also assumes intermediate Junos and SRX knowledge, so the associate credential alone may not be enough preparation on its own.
JN0-336 began on September 2, 2025, after JN0-335 retired on September 1, 2025. JN0-336 targets Junos OS 24.4 and lists 65 questions, so older 75-question descriptions refer to the retired exam.
It is active for three years. Renew before expiry by passing the applicable current exam, earning a higher Security-track certification, or completing an eligible designated course. The Juniper Security course lists JNCIS-SEC renewal. An expired credential means restarting the track.
After a first failure there is no mandated wait. After a second or later failure you wait 14 calendar days, starting the day after. Once you pass, you must wait at least 18 months before retaking the same exam.