Juniper Networks · Certification & Training

Juniper Security Specialist

JNCIS-SEC · JN0-336

JNCIS-SEC is Juniper's specialist-level security credential, validating that you can configure, operate, and troubleshoot Junos security features on SRX Series firewalls — IPsec VPNs, IDP, chassis clustering, and ATP Cloud. The exam moved to a new code, JN0-336, on September 2, 2025, retiring the old JN0-335. For network engineers, this is the cert that unlocks SRX-heavy roles and is the stepping stone to the professional-level JNCIP-SEC. This page breaks down exactly what JN0-336 tests, how it's delivered, and how to pass it the first time.

90 Minutes
65 Questions
Pass / Fail
Center or Online

Pay Only After You Pass

No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.

Exam Spec Sheet

Provider Juniper Networks
Exam Code JN0-336
Format Multiple choice · 7 domains
Duration 90 minutes
Questions 65
Scoring Pass / Fail (no numeric score)
Fee ~$300 USD
Delivery Pearson VUE (center / OnVUE)
Prerequisite JNCIA-SEC recommended
Validity 3 years
Language English
See JNCIS-SEC Help Options

EXAM FORMAT

How JN0-336 is built — at a glance

65

Multiple-choice questions

A single fixed-form section of 65 scenario and configuration questions. No live labs — but many items show CLI output or topology you must interpret correctly.

90

Minutes on the clock

Roughly 83 seconds per question. That's tight for the longer IPsec and chassis-cluster scenarios, so pacing and confident command recall matter as much as raw knowledge.

7

Objective domains

From IDP and IPsec VPN to ATP Cloud, HA clustering, identity-aware policy, SSL proxy, and Security Director — all on the Junos SRX security platform.

New code, same certification

JN0-336 went live on September 2, 2025, replacing the retired JN0-335. The certification name — JNCIS-SEC, the Security Specialist track — is unchanged. The refresh leans harder into ATP Cloud, Juniper Secure Connect, and identity-aware policy, so older JN0-335 study material is partly out of date.

How scoring works

Juniper reports the result as pass or fail — there is no numeric scaled score on your report. The cut score is set by Juniper and is not published, but it generally lands in the 60–70% range. You receive a provisional result on screen as soon as you finish, with the official outcome confirmed shortly after in your Juniper certification account.

WHAT'S TESTED

Seven Junos SRX security domains — Juniper does not publish fixed per-domain weightings

1

Intrusion Detection & Prevention

IDP concepts and policy, signature database management and updates, custom attack objects, and reading IDP logs to verify what the SRX is blocking.

2

IPsec VPN

Phase 1 / Phase 2 negotiation, site-to-site and route-based tunnels, traffic selectors and proxy IDs, plus Juniper Secure Connect remote-access VPN.

3

ATP Cloud

Juniper Advanced Threat Prevention Cloud: supported file types, components, security feeds, traffic remediation, encrypted-traffic insights, and DNS/IoT security.

4

High Availability Clustering

Chassis cluster requirements, redundancy groups, node priority and failover, control and fabric links, and session-state synchronization between SRX nodes.

5

Identity-Aware Policies

JIMS (Juniper Identity Management Service) integration, the ports and protocols involved, and how user and device identity data flows into security policy.

6

SSL Proxy

Forward (client-protection) and reverse (server-protection) SSL proxy, certificate handling, CA profiles, and inspecting encrypted traffic without breaking trust.

7

Security Director

Junos Space Security Director deployment options, device discovery and onboarding, and centralized firewall and security policy management at scale.

Juniper publishes the objective list but not the exact percentage each domain contributes. In practice IPsec VPN, IDP, and chassis clustering carry the most questions because they are the day-to-day building blocks of an SRX deployment — so they deserve the deepest preparation.

DELIVERY & PROCTORING

JN0-336 is delivered by Pearson VUE — two ways to sit it

At a Pearson VUE test center

You sit JN0-336 in a quiet, monitored room at a Pearson VUE center. Staff verify your government-issued ID, store your belongings, and supply an erasable noteboard. The exam fee is about $300 USD, paid at registration.

Online via OnVUE

You take the exam from a private room at home through Pearson VUE's OnVUE remote-proctoring platform. Expect a webcam room scan, an ID check, and a system test beforehand. No physical scratch paper — you use the built-in digital whiteboard. The fee is the same ~$300 USD.

ID & identity check

A valid, unexpired government photo ID with a name matching your Juniper certification profile exactly. The proctor captures your photo before the exam unlocks.

Environment scan (online)

A clear desk, no second monitor, no phone or notes within reach, and a 360° webcam scan of the room. No one else may enter while you test.

During the exam

Stay in frame the whole time — there are no scheduled breaks in the 90-minute window. Talking aloud, leaving the seat, or a dropped connection can flag the session.

WHO SHOULD TAKE THIS

JNCIS-SEC is built for SRX-focused security engineers

  • Network and security engineers who deploy Juniper SRX firewalls
  • JNCIA-SEC holders advancing to the specialist level
  • NOC/SOC staff managing IPsec VPNs, IDP, and chassis clusters
  • Consultants and integrators on Juniper-based enterprise networks
  • Engineers building toward the professional-level JNCIP-SEC

PREREQUISITES & DIFFICULTY

No hard gate — but SRX hands-on experience is assumed

  • JNCIA-SEC (JN0-231) recommended — no enforced exam lock
  • Working knowledge of Junos OS CLI on SRX Series devices
  • Comfort with security zones, screens, and policy fundamentals
  • Familiarity with IPsec, IKE, and general firewall concepts

Difficulty: JNCIS-SEC is a real step up from the associate level. The questions reward people who have actually configured IPsec tunnels and chassis clusters on Junos, not just read about them. Because JN0-336 is newer than most third-party prep, current and accurate material is harder to find — which is exactly the pressure point our help is designed to remove.

HOW EXAM ASSIST HELPS YOU PASS JNCIS-SEC

JN0-336 is a fast, dense, SRX-specific exam, and the move from JN0-335 means a lot of the prep out there is stale. Exam Assist pairs you with a vetted Juniper security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.

1

Share your exam details

Tell us your delivery method (Pearson VUE center or OnVUE), your target test date, and where you are on the Juniper track. Takes a couple of minutes over WhatsApp, Telegram, or Discord.

2

Get an honest feasibility answer

We review your timeline and background and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.

3

The sitting is handled

Exam Assist handles the sitting end to end. You're matched with a Juniper specialist who maps the work around the JN0-336 objectives — IPsec, IDP, ATP Cloud, HA clustering — and the OnVUE environment, discreetly and confidentially.

4

Settle after the verified result

You only pay once your passing result is confirmed in your Juniper certification account. No verified result, nothing owed.

Ready to lock in your JNCIS-SEC pass?

Tell us about your JN0-336 exam and get an honest, no-pressure feasibility answer — pay only after you pass.

Start with Your Exam Details

FREQUENTLY ASKED

Straight answers about the JNCIS-SEC JN0-336 exam

What exam do I take for JNCIS-SEC, and did the code change? +
The current Security Specialist exam is JN0-336. It replaced the older JN0-335 exam on September 2, 2025 — JN0-335 was retired on September 1, 2025. If you are registering now, you book JN0-336 through Pearson VUE. The certification name stays the same: JNCIS-SEC.
How many questions is the JN0-336 exam and how long do I get? +
JN0-336 is 65 multiple-choice questions with a 90-minute time limit. Juniper does not publish a fixed numeric pass mark — the result is reported as pass or fail, and the passing threshold is scaled, generally landing in the 60–70% range. You see your provisional result immediately after you finish.
Do I need JNCIA-SEC before sitting JNCIS-SEC? +
Juniper recommends holding the associate-level JNCIA-SEC (JN0-231) first, since JNCIS-SEC assumes you already understand SRX zones, screens, and basic security policy. There is no hard system block, but the specialist exam moves fast through IPsec VPN, IDP, chassis clustering, and ATP Cloud, so the JNCIA-SEC foundation matters in practice.
Can I take JNCIS-SEC online or only at a test center? +
Both. Juniper delivers JN0-336 through Pearson VUE, so you can sit it at a Pearson VUE test center or online from home via OnVUE remote proctoring. The online option requires a webcam, a clean private room, a government ID check, and a room scan before the exam unlocks.
How long is the JNCIS-SEC certification valid? +
Juniper certifications are valid for three years from the date you pass. To stay current you recertify by passing the JNCIS-SEC exam again or by earning the next level up, JNCIP-SEC, before your three-year window closes.
Do I pay Exam Assist before or after I see my JNCIS-SEC result? +
You settle only after your verified passing result is confirmed. There is no upfront fee — you share your exam details, receive an honest feasibility answer, and decide before any money changes hands. We advertise a guaranteed pass with money back if you do not pass; we offer a transparent, results-first arrangement.

KEEP EXPLORING

Book your exam help and compare sibling security certifications

YOUR JNCIS-SEC PASS, HANDLED

Get expert JN0-336 help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.

OR CHAT WITH US