Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
JUNIPER NETWORKS

Juniper Networks Certified Specialist, Security (JNCIS-SEC)

JN0-336

The Juniper Networks Certified Specialist, Security (JNCIS-SEC) certification validates your ability to configure, monitor, and troubleshoot Junos OS security technologies on SRX Series devices. Designed for networking professionals with intermediate knowledge, it covers IDP, IPsec VPNs, Juniper ATP Cloud, high availability clustering, and more. Earning JNCIS-SEC demonstrates your expertise in securing modern networks with Juniper solutions.

725 practice questions · Updated 2026-07-30

7Domains
32Objectives
193Concepts
725Questions

JN0-336 Curriculum

Every domain, objective, and concept the JN0-336 exam measures.

IDP database management

8 concepts · 32 questions
  1. IDP database overview
  2. Attack object categories
  3. Signature types
  4. Custom attack objects
  5. Attack object groups
  6. IDP database updates
  7. Update verification
  8. Troubleshooting database issues

IDP policy

7 concepts · 23 questions
  1. IDP policy structure
  2. IDP rulebase configuration
  3. IDP attack objects
  4. IDP rule actions
  5. IDP policy ordering and evaluation
  6. IDP policy management
  7. IDP policy tuning

Configure, monitor, or troubleshoot IDP

3 concepts · 17 questions
  1. IDP configuration basics
  2. IDP monitoring
  3. IDP troubleshooting

IPsec tunnel establishment

9 concepts · 28 questions
  1. IPsec tunnel establishment phases
  2. IKE Phase 1 negotiation
  3. IKE Phase 2 negotiation
  4. Main mode vs. aggressive mode
  5. Quick mode
  6. Perfect Forward Secrecy (PFS)
  7. Authentication methods
  8. IPsec SA parameters
  9. Tunnel establishment troubleshooting

IPsec traffic processing

10 concepts · 27 questions
  1. IPsec traffic processing overview
  2. Outbound IPsec packet processing
  3. Inbound IPsec packet processing
  4. IPsec anti-replay checking
  5. IPsec traffic selectors and policy lookup
  6. IPsec fragmentation and MTU handling
  7. IPsec and NAT interaction
  8. IPsec tunnel and transport modes
  9. IPsec SA lifecycle and rekeying
  10. IPsec traffic processing on Junos

IPsec site-to-site VPNs

7 concepts · 29 questions
  1. IPsec site-to-site VPN overview
  2. IPsec protocol suite
  3. IKE phases
  4. IPsec security associations
  5. Tunnel and transport modes
  6. IPsec configuration on Junos
  7. VPN monitoring and troubleshooting

Juniper Secure Connect

6 concepts · 23 questions
  1. Juniper Secure Connect Overview
  2. Architecture and Components
  3. Configuration of Secure Connect
  4. Client Access and User Experience
  5. Integration with Existing VPNs
  6. Troubleshooting and Monitoring
  1. IPsec VPN configuration basics
  2. IPsec VPN monitoring
  3. IPsec VPN troubleshooting

Supported files

4 concepts · 18 questions
  1. Supported file types for ATP Cloud
  2. File size limitations
  3. File upload methods
  4. Handling unsupported files

Components

4 concepts · 24 questions
  1. ATP Cloud Components Overview
  2. Cloud-Based Threat Intelligence
  3. On-Premises Integration
  4. Management and Reporting

Security feeds

6 concepts · 24 questions
  1. Understanding security feeds
  2. Types of security feeds
  3. Managing security feeds
  4. Feed sources and updates
  5. Integration with security policies
  6. Monitoring and troubleshooting feeds

Traffic remediation

6 concepts · 29 questions
  1. Traffic remediation overview
  2. Remediation actions
  3. Remediation policies
  4. Integration with Juniper devices
  5. Remediation workflow
  6. Monitoring and reporting

Workflow

6 concepts · 23 questions
  1. ATP Cloud Workflow Overview
  2. Initial Configuration and Integration
  3. Traffic Redirection and Inspection
  4. Threat Detection and Analysis
  5. Policy Enforcement and Response
  6. Reporting and Remediation

Encrypted Traffic Insights (ETI)

5 concepts · 26 questions
  1. ETI Overview
  2. ETI Architecture
  3. ETI Deployment
  4. ETI Policy Configuration
  5. ETI Operation and Monitoring

DNS and IoT security

7 concepts · 28 questions
  1. DNS Security Overview
  2. DNS Sinkholing
  3. DNS Security Policies
  4. IoT Security Fundamentals
  5. IoT Device Profiling
  6. IoT Threat Detection
  7. IoT Policy Enforcement

Adaptive threat profiling

6 concepts · 29 questions
  1. Adaptive Threat Profiling Overview
  2. Threat Profiling Process
  3. Behavioral Analysis
  4. Integration with ATP Cloud
  5. Policy Configuration
  6. Monitoring and Reporting
  1. Juniper ATP Cloud Overview
  2. Initial Configuration
  3. Policy Configuration
  4. Monitoring and Reporting
  5. Troubleshooting Connectivity
  6. Troubleshooting Policy and Inspection
  7. Troubleshooting Threat Detection

HA features and characteristics

9 concepts · 29 questions
  1. HA Cluster Overview
  2. HA Cluster Modes
  3. HA Cluster Components
  4. HA Cluster States
  5. HA Cluster Configuration
  6. HA Cluster Monitoring
  7. HA Cluster Failover
  8. HA Cluster Synchronization
  9. HA Cluster Limitations
  1. HA Cluster Deployment Requirements
  2. HA Cluster Configuration Considerations
  3. HA Cluster Deployment Modes
  4. HA Cluster Synchronization
  5. HA Cluster Failure Detection and Recovery
  6. HA Cluster Monitoring and Maintenance
  1. Chassis cluster overview
  2. Cluster components
  3. Control link operation
  4. Fabric link operation
  5. Node roles and states
  6. Cluster formation and failover
  7. Redundancy group concept
  8. Chassis cluster configuration basics
  9. Monitoring and troubleshooting
  1. Real-time object synchronization overview
  2. Synchronization of configuration and runtime objects
  3. Synchronization of security objects
  4. Synchronization of state information
  5. Synchronization mechanisms and protocols
  6. Handling of unsynchronized objects
  7. Monitoring and verifying synchronization
  1. Cluster Configuration Basics
  2. Cluster Monitoring
  3. Cluster Troubleshooting

  1. JIMS Overview
  2. JIMS Architecture
  3. User Identity Mapping
  4. JIMS Configuration
  5. JIMS Integration with SRX
  6. Troubleshooting JIMS

Ports and protocols

5 concepts · 23 questions
  1. Common security ports
  2. Protocol behavior for security
  3. Port-based policy configuration
  4. Service objects and applications
  5. Port and protocol matching in security policies

Data flow

6 concepts · 18 questions
  1. Data flow overview
  2. Packet processing stages
  3. Session establishment
  4. Policy enforcement in data flow
  5. Traffic forwarding and NAT
  6. Flow control and exceptions
  1. Identity Provider Integration
  2. User Firewall Authentication
  3. Identity-Aware Policy Configuration
  4. Monitoring Identity-Aware Policies
  5. Troubleshooting Identity Issues

Certificates

5 concepts · 24 questions
  1. Certificate types and roles
  2. Certificate validation and trust chain
  3. Certificate revocation checking
  4. Certificate installation and management
  5. Certificate renewal and replacement

Client and server protection

7 concepts · 19 questions
  1. Client protection
  2. Server protection
  3. SSL proxy deployment modes
  4. Certificate handling for client and server protection
  5. Traffic flow and interception
  6. Security policies for SSL proxy
  7. Troubleshooting SSL proxy issues
  1. SSL proxy configuration basics
  2. SSL proxy profiles
  3. SSL proxy certificate management
  4. SSL proxy policy enforcement
  5. SSL proxy monitoring
  6. SSL proxy troubleshooting

Deployment options

5 concepts · 22 questions
  1. Deployment modes
  2. Architecture components
  3. Integration with Juniper devices
  4. High availability considerations
  5. Scalability and performance

Onboarding devices

4 concepts · 18 questions
  1. Device onboarding overview
  2. Device discovery and addition
  3. Device configuration and templates
  4. Device status and validation

Security policies management

6 concepts · 21 questions
  1. Security policy fundamentals
  2. Policy creation and configuration
  3. Policy ordering and evaluation
  4. Policy management operations
  5. Policy validation and deployment
  6. Policy troubleshooting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for JN0-336, so none is invented.