JNCIS-SEC: Juniper Networks Certified Specialist Security (JNCIS-SEC)
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the JNCIS-SEC Exam
IDP, IPsec VPNs, Juniper ATP Cloud, chassis-cluster HA, identity-aware policies, SSL proxy, and Security Director
250 original practice questions covering all 7 JNCIS-SEC (JN0-336) exam domains: Intrusion Detection and Prevention (IDP), IPsec VPN (including Juniper Secure Connect), Juniper Advanced Threat Prevention (ATP) Cloud, High Availability (HA) Clustering, Identity-Aware Security Policies, SSL Proxy, and Junos Space Security Director. Character-driven SRX/Junos scenarios aligned to the current specialist-level blueprint (Junos OS 24.4).
Who Should Take This Exam?
The JNCIS-SEC is designed for security and network engineers who deploy and operate Juniper SRX firewalls. JNCIA-SEC (the Security Associate) is the recommended prerequisite, and hands-on SRX configuration experience helps a lot.
Typical study time: 4-8 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Code | JN0-336 |
| Title | Juniper Networks Certified Specialist Security (JNCIS-SEC) |
| Duration | 90 minutes |
| Questions | 65 |
| Cost | $300 USD |
| Provider | Pearson VUE |
| Validity | 3 years |
| Prerequisites | JNCIA-SEC recommended (no hard prerequisite) |
| Question Types | Multiple choice |
| Official Page | View on Juniper → |
Exam Domains & Weights
The JNCIS-SEC exam covers 7 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.
| Domain | Weight | Practice Qs |
|---|---|---|
| Intrusion Detection and Prevention (IDP) | 15% | 38 |
| IPsec VPN | 18% | 45 |
| Juniper Advanced Threat Prevention (ATP) Cloud | 17% | 42 |
| High Availability (HA) Clustering | 15% | 37 |
| Identity-Aware Security Policies | 12% | 30 |
| SSL Proxy | 12% | 30 |
| Junos Space Security Director | 11% | 28 |
| Total | 100% | 250 |
💡 Study tip: IPsec VPN (18%) and Juniper ATP Cloud (17%) are the two heaviest domains — start there. Juniper does not publish official percentage weights for JNCIS-SEC, so treat these as study guidance based on objective breadth: give every domain real time, because exam questions can come from any of the seven.
Practice Exam — 250 Questions
Prepare for the JNCIS-SEC with our 250-question practice exam covering all 7 exam domains. Every question includes detailed explanations and maps to official exam objectives.
What you get:
- ✅ Exam simulation mode with timer
- ✅ Spaced repetition for weak areas
- ✅ Detailed explanations for every question
- ✅ Progress tracking across domains
- ✅ 20 free questions — no account needed
Juniper Certification Path
Juniper follows: Associate (JNCIA) → Specialist (JNCIS) → Professional (JNCIP) → Expert (JNCIE). On the Security track that is JNCIA-SEC → JNCIS-SEC → JNCIP-SEC → JNCIE-SEC. JNCIS-SEC is the specialist step, best taken after JNCIA-SEC.
Related Juniper Certifications
If you’re studying for the JNCIS-SEC, you might also be interested in these Juniper certifications:
- JNCIP-SEC: Juniper Networks Certified Professional, Security (JNCIP-SEC) — 250 practice questions
- JNCIA-Cloud: Juniper Networks Certified Associate - Cloud (JNCIA-Cloud) — 250 practice questions
- JNCIS-ENT: Juniper Networks Certified Specialist, Enterprise Routing and Switching (JNCIS-ENT) — 250 practice questions
Study Tips
- Start with the heaviest domains — IPsec VPN and ATP Cloud together are a third of the exam
- Get hands-on — build a site-to-site VPN and a chassis cluster in a lab (vSRX works); the config and show-command output stick far better once you’ve seen them
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Review explanations — don’t just check if you got it right; read why each answer is correct
- Check the official page — official exam details always have the latest objectives
Frequently asked questions
The JNCIS-SEC questions I hear most — usually from engineers who already run SRX firewalls and want to know how deep the specialist exam goes, and how it differs from the JNCIA-SEC they took first.
What does JNCIS-SEC actually cover? #
How hard is JNCIS-SEC, and what is the exam format? #
How much does the JNCIS-SEC exam cost? #
Is it JN0-335 or JN0-336 — which version should I study? #
Does JNCIS-SEC lead anywhere useful for my career? #
Frequently Asked Questions
1. What does JNCIS-SEC actually cover?
The current JNCIS-SEC (JN0-336) focuses on the advanced SRX/Junos security features: Intrusion Detection and Prevention (IDP), IPsec VPNs including Juniper Secure Connect, Juniper ATP Cloud (Sky ATP) with Encrypted Traffic Insights, DNS and IoT security and adaptive threat profiling, high-availability chassis clustering, identity-aware security policies with the Juniper Identity Management Service (JIMS), SSL forward and reverse proxy, and centralised management with Junos Space Security Director. The foundational SRX topics — security zones, basic policies, screens, NAT, and UTM — sit in the JNCIA-SEC prerequisite, not here.
2. How hard is JNCIS-SEC, and what is the exam format?
It is a specialist-level exam: 65 multiple-choice questions in 90 minutes, delivered at Pearson VUE, no lab. It is more hands-on than the associate — expect questions that ask you to read a 'show security ike security-associations' state, pick the right IDP action, reason about a chassis-cluster failover, or choose between SSL forward and reverse proxy. JNCIA-SEC is the recommended prerequisite. If you already configure SRX firewalls day to day, plan on 4 to 8 weeks of focused study.
3. How much does the JNCIS-SEC exam cost?
USD $300 via Pearson VUE. Juniper regularly runs free or discounted voucher promotions through the [Juniper Open Learning portal](https://learning.juniper.net/) — create a free account and watch for promo emails and free on-demand courses. The certification is valid for 3 years and is renewed by passing the current version again or moving up the Juniper ladder to JNCIP-SEC.
4. Is it JN0-335 or JN0-336 — which version should I study?
JN0-336 is the current exam. It replaced JN0-335 (which retired in September 2025), and the blueprint is aligned to Junos OS 24.4. Study JN0-336 objectives: IDP, IPsec VPN, Juniper ATP Cloud, HA clustering, identity-aware policies, SSL proxy, and Security Director. If a study resource still says JN0-335 or leans heavily on UTM/NAT/screens, it is aligned to the older exam or to the JNCIA-SEC associate tier.
5. Does JNCIS-SEC lead anywhere useful for my career?
Yes — it is the recognised mid-tier credential for engineers who design, deploy, and operate Juniper SRX security. It maps directly to firewall/network-security engineer and SOC roles in enterprises, service providers, and government networks that run Juniper. On the Juniper ladder it sits at Specialist: JNCIA-SEC (Associate) is below it, and JNCIP-SEC (Professional) and JNCIE-SEC (Expert) are the next steps up if you want to go deeper into advanced VPNs, HA, logical systems, and automated threat mitigation.