JNCIS-SEC: Juniper Networks Certified Specialist Security (JNCIS-SEC)

Expert Juniper Juniper
Browse certifications

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

About the JNCIS-SEC Exam

IDP, IPsec VPNs, Juniper ATP Cloud, chassis-cluster HA, identity-aware policies, SSL proxy, and Security Director

250 original practice questions covering all 7 JNCIS-SEC (JN0-336) exam domains: Intrusion Detection and Prevention (IDP), IPsec VPN (including Juniper Secure Connect), Juniper Advanced Threat Prevention (ATP) Cloud, High Availability (HA) Clustering, Identity-Aware Security Policies, SSL Proxy, and Junos Space Security Director. Character-driven SRX/Junos scenarios aligned to the current specialist-level blueprint (Junos OS 24.4).

Who Should Take This Exam?

The JNCIS-SEC is designed for security and network engineers who deploy and operate Juniper SRX firewalls. JNCIA-SEC (the Security Associate) is the recommended prerequisite, and hands-on SRX configuration experience helps a lot.

Typical study time: 4-8 weeks of focused study

Exam Quick Facts

DetailValue
Exam CodeJN0-336
TitleJuniper Networks Certified Specialist Security (JNCIS-SEC)
Duration90 minutes
Questions65
Cost$300 USD
ProviderPearson VUE
Validity3 years
PrerequisitesJNCIA-SEC recommended (no hard prerequisite)
Question TypesMultiple choice
Official PageView on Juniper →

Exam Domains & Weights

The JNCIS-SEC exam covers 7 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.

DomainWeightPractice Qs
Intrusion Detection and Prevention (IDP)15%38
IPsec VPN18%45
Juniper Advanced Threat Prevention (ATP) Cloud17%42
High Availability (HA) Clustering15%37
Identity-Aware Security Policies12%30
SSL Proxy12%30
Junos Space Security Director11%28
Total100%250

💡 Study tip: IPsec VPN (18%) and Juniper ATP Cloud (17%) are the two heaviest domains — start there. Juniper does not publish official percentage weights for JNCIS-SEC, so treat these as study guidance based on objective breadth: give every domain real time, because exam questions can come from any of the seven.

Practice Exam — 250 Questions

Prepare for the JNCIS-SEC with our 250-question practice exam covering all 7 exam domains. Every question includes detailed explanations and maps to official exam objectives.

What you get:

  • ✅ Exam simulation mode with timer
  • ✅ Spaced repetition for weak areas
  • ✅ Detailed explanations for every question
  • ✅ Progress tracking across domains
  • ✅ 20 free questions — no account needed

Juniper Certification Path

Juniper follows: Associate (JNCIA) → Specialist (JNCIS) → Professional (JNCIP) → Expert (JNCIE). On the Security track that is JNCIA-SEC → JNCIS-SEC → JNCIP-SEC → JNCIE-SEC. JNCIS-SEC is the specialist step, best taken after JNCIA-SEC.

If you’re studying for the JNCIS-SEC, you might also be interested in these Juniper certifications:

Study Tips

  1. Start with the heaviest domains — IPsec VPN and ATP Cloud together are a third of the exam
  2. Get hands-on — build a site-to-site VPN and a chassis cluster in a lab (vSRX works); the config and show-command output stick far better once you’ve seen them
  3. Use our practice exam — try the 20 free questions first to gauge your readiness
  4. Review explanations — don’t just check if you got it right; read why each answer is correct
  5. Check the official pageofficial exam details always have the latest objectives

Frequently asked questions

The JNCIS-SEC questions I hear most — usually from engineers who already run SRX firewalls and want to know how deep the specialist exam goes, and how it differs from the JNCIA-SEC they took first.

What does JNCIS-SEC actually cover? #

The current JNCIS-SEC (JN0-336) focuses on the advanced SRX/Junos security features: Intrusion Detection and Prevention (IDP), IPsec VPNs including Juniper Secure Connect, Juniper ATP Cloud (Sky ATP) with Encrypted Traffic Insights, DNS and IoT security and adaptive threat profiling, high-availability chassis clustering, identity-aware security policies with the Juniper Identity Management Service (JIMS), SSL forward and reverse proxy, and centralised management with Junos Space Security Director. The foundational SRX topics — security zones, basic policies, screens, NAT, and UTM — sit in the JNCIA-SEC prerequisite, not here.

How hard is JNCIS-SEC, and what is the exam format? #

It is a specialist-level exam: 65 multiple-choice questions in 90 minutes, delivered at Pearson VUE, no lab. It is more hands-on than the associate — expect questions that ask you to read a ‘show security ike security-associations’ state, pick the right IDP action, reason about a chassis-cluster failover, or choose between SSL forward and reverse proxy. JNCIA-SEC is the recommended prerequisite. If you already configure SRX firewalls day to day, plan on 4 to 8 weeks of focused study.

How much does the JNCIS-SEC exam cost? #

USD $300 via Pearson VUE. Juniper regularly runs free or discounted voucher promotions through the Juniper Open Learning portal — create a free account and watch for promo emails and free on-demand courses. The certification is valid for 3 years and is renewed by passing the current version again or moving up the Juniper ladder to JNCIP-SEC.

Is it JN0-335 or JN0-336 — which version should I study? #

JN0-336 is the current exam. It replaced JN0-335 (which retired in September 2025), and the blueprint is aligned to Junos OS 24.4. Study JN0-336 objectives: IDP, IPsec VPN, Juniper ATP Cloud, HA clustering, identity-aware policies, SSL proxy, and Security Director. If a study resource still says JN0-335 or leans heavily on UTM/NAT/screens, it is aligned to the older exam or to the JNCIA-SEC associate tier.

Does JNCIS-SEC lead anywhere useful for my career? #

Yes — it is the recognised mid-tier credential for engineers who design, deploy, and operate Juniper SRX security. It maps directly to firewall/network-security engineer and SOC roles in enterprises, service providers, and government networks that run Juniper. On the Juniper ladder it sits at Specialist: JNCIA-SEC (Associate) is below it, and JNCIP-SEC (Professional) and JNCIE-SEC (Expert) are the next steps up if you want to go deeper into advanced VPNs, HA, logical systems, and automated threat mitigation.

Frequently Asked Questions

1. What does JNCIS-SEC actually cover?

The current JNCIS-SEC (JN0-336) focuses on the advanced SRX/Junos security features: Intrusion Detection and Prevention (IDP), IPsec VPNs including Juniper Secure Connect, Juniper ATP Cloud (Sky ATP) with Encrypted Traffic Insights, DNS and IoT security and adaptive threat profiling, high-availability chassis clustering, identity-aware security policies with the Juniper Identity Management Service (JIMS), SSL forward and reverse proxy, and centralised management with Junos Space Security Director. The foundational SRX topics — security zones, basic policies, screens, NAT, and UTM — sit in the JNCIA-SEC prerequisite, not here.

2. How hard is JNCIS-SEC, and what is the exam format?

It is a specialist-level exam: 65 multiple-choice questions in 90 minutes, delivered at Pearson VUE, no lab. It is more hands-on than the associate — expect questions that ask you to read a 'show security ike security-associations' state, pick the right IDP action, reason about a chassis-cluster failover, or choose between SSL forward and reverse proxy. JNCIA-SEC is the recommended prerequisite. If you already configure SRX firewalls day to day, plan on 4 to 8 weeks of focused study.

3. How much does the JNCIS-SEC exam cost?

USD $300 via Pearson VUE. Juniper regularly runs free or discounted voucher promotions through the [Juniper Open Learning portal](https://learning.juniper.net/) — create a free account and watch for promo emails and free on-demand courses. The certification is valid for 3 years and is renewed by passing the current version again or moving up the Juniper ladder to JNCIP-SEC.

4. Is it JN0-335 or JN0-336 — which version should I study?

JN0-336 is the current exam. It replaced JN0-335 (which retired in September 2025), and the blueprint is aligned to Junos OS 24.4. Study JN0-336 objectives: IDP, IPsec VPN, Juniper ATP Cloud, HA clustering, identity-aware policies, SSL proxy, and Security Director. If a study resource still says JN0-335 or leans heavily on UTM/NAT/screens, it is aligned to the older exam or to the JNCIA-SEC associate tier.

5. Does JNCIS-SEC lead anywhere useful for my career?

Yes — it is the recognised mid-tier credential for engineers who design, deploy, and operate Juniper SRX security. It maps directly to firewall/network-security engineer and SOC roles in enterprises, service providers, and government networks that run Juniper. On the Juniper ladder it sits at Specialist: JNCIA-SEC (Associate) is below it, and JNCIP-SEC (Professional) and JNCIE-SEC (Expert) are the next steps up if you want to go deeper into advanced VPNs, HA, logical systems, and automated threat mitigation.

20 Free Questions Practice Exam $9 →