
Juniper Networks Certified Specialist, Security (JNCIS-SEC)
The Juniper Networks Certified Specialist, Security (JNCIS-SEC) certification validates your ability to configure, monitor, and troubleshoot Junos OS security technologies on SRX Series devices. Designed for networking professionals with intermediate knowledge, it covers IDP, IPsec VPNs, Juniper ATP Cloud, high availability clustering, and more. Earning JNCIS-SEC demonstrates your expertise in securing modern networks with Juniper solutions.
725 practice questions · Updated 2026-07-30
7Domains
32Objectives
193Concepts
725Questions
JN0-336 Curriculum
Every domain, objective, and concept the JN0-336 exam measures.
- IDP database overview
- Attack object categories
- Signature types
- Custom attack objects
- Attack object groups
- IDP database updates
- Update verification
- Troubleshooting database issues
- IDP policy structure
- IDP rulebase configuration
- IDP attack objects
- IDP rule actions
- IDP policy ordering and evaluation
- IDP policy management
- IDP policy tuning
- IDP configuration basics
- IDP monitoring
- IDP troubleshooting
- IPsec tunnel establishment phases
- IKE Phase 1 negotiation
- IKE Phase 2 negotiation
- Main mode vs. aggressive mode
- Quick mode
- Perfect Forward Secrecy (PFS)
- Authentication methods
- IPsec SA parameters
- Tunnel establishment troubleshooting
- IPsec traffic processing overview
- Outbound IPsec packet processing
- Inbound IPsec packet processing
- IPsec anti-replay checking
- IPsec traffic selectors and policy lookup
- IPsec fragmentation and MTU handling
- IPsec and NAT interaction
- IPsec tunnel and transport modes
- IPsec SA lifecycle and rekeying
- IPsec traffic processing on Junos
- IPsec site-to-site VPN overview
- IPsec protocol suite
- IKE phases
- IPsec security associations
- Tunnel and transport modes
- IPsec configuration on Junos
- VPN monitoring and troubleshooting
- Juniper Secure Connect Overview
- Architecture and Components
- Configuration of Secure Connect
- Client Access and User Experience
- Integration with Existing VPNs
- Troubleshooting and Monitoring
- IPsec VPN configuration basics
- IPsec VPN monitoring
- IPsec VPN troubleshooting
- Supported file types for ATP Cloud
- File size limitations
- File upload methods
- Handling unsupported files
- ATP Cloud Components Overview
- Cloud-Based Threat Intelligence
- On-Premises Integration
- Management and Reporting
- Understanding security feeds
- Types of security feeds
- Managing security feeds
- Feed sources and updates
- Integration with security policies
- Monitoring and troubleshooting feeds
- Traffic remediation overview
- Remediation actions
- Remediation policies
- Integration with Juniper devices
- Remediation workflow
- Monitoring and reporting
- ATP Cloud Workflow Overview
- Initial Configuration and Integration
- Traffic Redirection and Inspection
- Threat Detection and Analysis
- Policy Enforcement and Response
- Reporting and Remediation
- ETI Overview
- ETI Architecture
- ETI Deployment
- ETI Policy Configuration
- ETI Operation and Monitoring
- DNS Security Overview
- DNS Sinkholing
- DNS Security Policies
- IoT Security Fundamentals
- IoT Device Profiling
- IoT Threat Detection
- IoT Policy Enforcement
- Adaptive Threat Profiling Overview
- Threat Profiling Process
- Behavioral Analysis
- Integration with ATP Cloud
- Policy Configuration
- Monitoring and Reporting
- Juniper ATP Cloud Overview
- Initial Configuration
- Policy Configuration
- Monitoring and Reporting
- Troubleshooting Connectivity
- Troubleshooting Policy and Inspection
- Troubleshooting Threat Detection
- HA Cluster Overview
- HA Cluster Modes
- HA Cluster Components
- HA Cluster States
- HA Cluster Configuration
- HA Cluster Monitoring
- HA Cluster Failover
- HA Cluster Synchronization
- HA Cluster Limitations
- HA Cluster Deployment Requirements
- HA Cluster Configuration Considerations
- HA Cluster Deployment Modes
- HA Cluster Synchronization
- HA Cluster Failure Detection and Recovery
- HA Cluster Monitoring and Maintenance
- Chassis cluster overview
- Cluster components
- Control link operation
- Fabric link operation
- Node roles and states
- Cluster formation and failover
- Redundancy group concept
- Chassis cluster configuration basics
- Monitoring and troubleshooting
- Real-time object synchronization overview
- Synchronization of configuration and runtime objects
- Synchronization of security objects
- Synchronization of state information
- Synchronization mechanisms and protocols
- Handling of unsynchronized objects
- Monitoring and verifying synchronization
- Cluster Configuration Basics
- Cluster Monitoring
- Cluster Troubleshooting
- JIMS Overview
- JIMS Architecture
- User Identity Mapping
- JIMS Configuration
- JIMS Integration with SRX
- Troubleshooting JIMS
- Common security ports
- Protocol behavior for security
- Port-based policy configuration
- Service objects and applications
- Port and protocol matching in security policies
- Data flow overview
- Packet processing stages
- Session establishment
- Policy enforcement in data flow
- Traffic forwarding and NAT
- Flow control and exceptions
- Identity Provider Integration
- User Firewall Authentication
- Identity-Aware Policy Configuration
- Monitoring Identity-Aware Policies
- Troubleshooting Identity Issues
- Certificate types and roles
- Certificate validation and trust chain
- Certificate revocation checking
- Certificate installation and management
- Certificate renewal and replacement
- Client protection
- Server protection
- SSL proxy deployment modes
- Certificate handling for client and server protection
- Traffic flow and interception
- Security policies for SSL proxy
- Troubleshooting SSL proxy issues
- SSL proxy configuration basics
- SSL proxy profiles
- SSL proxy certificate management
- SSL proxy policy enforcement
- SSL proxy monitoring
- SSL proxy troubleshooting
- Deployment modes
- Architecture components
- Integration with Juniper devices
- High availability considerations
- Scalability and performance
- Device onboarding overview
- Device discovery and addition
- Device configuration and templates
- Device status and validation
- Security policy fundamentals
- Policy creation and configuration
- Policy ordering and evaluation
- Policy management operations
- Policy validation and deployment
- Policy troubleshooting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for JN0-336, so none is invented.