JNCIS-SEC · JN0-336
JNCIS-SEC is Juniper's specialist-level security credential, validating that you can configure, operate, and troubleshoot Junos security features on SRX Series firewalls — IPsec VPNs, IDP, chassis clustering, and ATP Cloud. The exam moved to a new code, JN0-336, on September 2, 2025, retiring the old JN0-335. For network engineers, this is the cert that unlocks SRX-heavy roles and is the stepping stone to the professional-level JNCIP-SEC. This page breaks down exactly what JN0-336 tests, how it's delivered, and how to pass it the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How JN0-336 is built — at a glance
65
A single fixed-form section of 65 scenario and configuration questions. No live labs — but many items show CLI output or topology you must interpret correctly.
90
Roughly 83 seconds per question. That's tight for the longer IPsec and chassis-cluster scenarios, so pacing and confident command recall matter as much as raw knowledge.
7
From IDP and IPsec VPN to ATP Cloud, HA clustering, identity-aware policy, SSL proxy, and Security Director — all on the Junos SRX security platform.
JN0-336 went live on September 2, 2025, replacing the retired JN0-335. The certification name — JNCIS-SEC, the Security Specialist track — is unchanged. The refresh leans harder into ATP Cloud, Juniper Secure Connect, and identity-aware policy, so older JN0-335 study material is partly out of date.
Juniper reports the result as pass or fail — there is no numeric scaled score on your report. The cut score is set by Juniper and is not published, but it generally lands in the 60–70% range. You receive a provisional result on screen as soon as you finish, with the official outcome confirmed shortly after in your Juniper certification account.
Seven Junos SRX security domains — Juniper does not publish fixed per-domain weightings
IDP concepts and policy, signature database management and updates, custom attack objects, and reading IDP logs to verify what the SRX is blocking.
Phase 1 / Phase 2 negotiation, site-to-site and route-based tunnels, traffic selectors and proxy IDs, plus Juniper Secure Connect remote-access VPN.
Juniper Advanced Threat Prevention Cloud: supported file types, components, security feeds, traffic remediation, encrypted-traffic insights, and DNS/IoT security.
Chassis cluster requirements, redundancy groups, node priority and failover, control and fabric links, and session-state synchronization between SRX nodes.
JIMS (Juniper Identity Management Service) integration, the ports and protocols involved, and how user and device identity data flows into security policy.
Forward (client-protection) and reverse (server-protection) SSL proxy, certificate handling, CA profiles, and inspecting encrypted traffic without breaking trust.
Junos Space Security Director deployment options, device discovery and onboarding, and centralized firewall and security policy management at scale.
Juniper publishes the objective list but not the exact percentage each domain contributes. In practice IPsec VPN, IDP, and chassis clustering carry the most questions because they are the day-to-day building blocks of an SRX deployment — so they deserve the deepest preparation.
JN0-336 is delivered by Pearson VUE — two ways to sit it
You sit JN0-336 in a quiet, monitored room at a Pearson VUE center. Staff verify your government-issued ID, store your belongings, and supply an erasable noteboard. The exam fee is about $300 USD, paid at registration.
You take the exam from a private room at home through Pearson VUE's OnVUE remote-proctoring platform. Expect a webcam room scan, an ID check, and a system test beforehand. No physical scratch paper — you use the built-in digital whiteboard. The fee is the same ~$300 USD.
A valid, unexpired government photo ID with a name matching your Juniper certification profile exactly. The proctor captures your photo before the exam unlocks.
A clear desk, no second monitor, no phone or notes within reach, and a 360° webcam scan of the room. No one else may enter while you test.
Stay in frame the whole time — there are no scheduled breaks in the 90-minute window. Talking aloud, leaving the seat, or a dropped connection can flag the session.
JNCIS-SEC is built for SRX-focused security engineers
No hard gate — but SRX hands-on experience is assumed
Difficulty: JNCIS-SEC is a real step up from the associate level. The questions reward people who have actually configured IPsec tunnels and chassis clusters on Junos, not just read about them. Because JN0-336 is newer than most third-party prep, current and accurate material is harder to find — which is exactly the pressure point our help is designed to remove.
JN0-336 is a fast, dense, SRX-specific exam, and the move from JN0-335 means a lot of the prep out there is stale. Exam Assist pairs you with a vetted Juniper security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your delivery method (Pearson VUE center or OnVUE), your target test date, and where you are on the Juniper track. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and background and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a Juniper specialist who maps the work around the JN0-336 objectives — IPsec, IDP, ATP Cloud, HA clustering — and the OnVUE environment, discreetly and confidentially.
You only pay once your passing result is confirmed in your Juniper certification account. No verified result, nothing owed.
Tell us about your JN0-336 exam and get an honest, no-pressure feasibility answer — pay only after you pass.
Straight answers about the JNCIS-SEC JN0-336 exam
Book your exam help and compare sibling security certifications
Share your JN0-336 details and get a vetted Juniper specialist on a results-first arrangement. No upfront fee — settle only after a verified pass.
Start now JNCIA-SECThe associate-level foundation (JN0-231) and the recommended prerequisite for JNCIS-SEC — security concepts, SRX products, and firewall basics.
View exam NSE 7The Fortinet counterpart for advanced firewall engineers — a strong comparison if you work across multi-vendor security estates.
View exam CCSECheck Point's expert-level firewall credential — another vendor-specific security certification in the same enterprise networking space.
View examGet expert JN0-336 help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.