- Role separation between primary and tenant system administrators
- Tenant system administrator scope of control
- Primary system administrator privileges
- Configuration of tenant system administrator accounts
- Configuration of primary system administrator accounts
- Login class and permission mapping for tenant administrators
- Management access and authentication for tenant administrators
- Operational tasks permitted for tenant administrators
- Configuration tasks permitted for tenant administrators
- Impact of primary administrator actions on tenant systems

Juniper Networks Certified Professional, Security (JNCIP-SEC)
The Juniper Networks Certified Professional, Security (JNCIP-SEC) certification validates advanced knowledge of Junos OS for SRX Series devices, covering security policies, IPsec VPNs, NAT, and high availability. Designed for networking professionals with deep security expertise, this credential demonstrates the ability to configure, troubleshoot, and monitor complex security solutions. Earning JNCIP-SEC positions you as a skilled security practitioner ready to tackle enterprise-grade challenges.
679 practice questions · Updated 2026-07-30
JN0-637 Curriculum
Every domain, objective, and concept the JN0-637 exam measures.
- Identify available troubleshooting tools
- Use traceoptions for security policies
- Use traceoptions for security zones
- Interpret security flow logs
- Use show commands for policies and zones
- Use monitor traffic for policy and zone issues
- Use syslog for security events
- Logging configuration
- Tracing configuration
- Log file management
- Troubleshooting with logs
- Troubleshooting with traces
- Interpreting Security Policy Logs
- Using Traceoptions for Security Policies
- Verifying Security Zone Configuration
- Troubleshooting Zone-Based Policy Issues
- Monitoring Security Policy Counters
- Validating Policy Order and Precedence
- Diagnosing Policy Match Failures
- Interpreting Security Policy Error Messages
- Administrative roles overview
- Role-based access control (RBAC)
- Configuring administrative roles
- Assigning roles to users
- Verifying administrative roles
- Security profile fundamentals
- Security profile components
- Applying security profiles
- Security profile inheritance and override
- Troubleshooting security profiles
- Logical system communication overview
- Routing instances in logical systems
- Inter-logical system routing
- Firewall filters for logical system traffic
- NAT between logical systems
- VPNs and logical systems
- Troubleshooting logical system communication
- Tenant system capacity limits
- Resource allocation for tenant systems
- Configuration of tenant system capacity
- Impact of tenant systems on device performance
- Transparent mode overview
- Transparent mode configuration
- Layer 2 security zones
- Transparent mode traffic handling
- Transparent mode high availability
- Transparent mode troubleshooting
- Mixed mode overview
- Configuration of mixed mode
- Traffic handling in mixed mode
- Mixed mode with VLANs
- Troubleshooting mixed mode
- Secure Wire Overview
- Secure Wire Configuration
- Secure Wire Traffic Handling
- Secure Wire Security Features
- Secure Wire Troubleshooting
- MACsec Overview
- MACsec Key Management
- MACsec Configuration
- MACsec Operation and Verification
- EVPN-VXLAN Overview
- EVPN-VXLAN Security Threats
- MACsec for EVPN-VXLAN
- IPsec for EVPN-VXLAN
- Firewall Integration with EVPN-VXLAN
- EVPN-VXLAN Access Control
- EVPN-VXLAN Segmentation and Micro-segmentation
- EVPN-VXLAN Monitoring and Visibility
- EVPN-VXLAN Security Best Practices
- Persistent NAT Overview
- Persistent NAT Configuration
- Persistent NAT Types
- Persistent NAT Behavior
- Persistent NAT and High Availability
- Persistent NAT Troubleshooting
- DNS doctoring overview
- DNS doctoring configuration
- DNS doctoring with NAT rules
- DNS doctoring verification
- DNS doctoring troubleshooting
- IPv6 NAT Overview
- NAT66 (IPv6-to-IPv6 NAT)
- NAT64 (IPv6-to-IPv4 NAT)
- NPTv6 (Network Prefix Translation)
- IPv6 NAT Configuration on Junos
- IPv6 NAT Monitoring and Troubleshooting
- Hub-and-spoke VPN architecture
- IPsec tunnel establishment in hub-and-spoke
- Traffic forwarding in hub-and-spoke
- Routing in hub-and-spoke VPNs
- Hub-and-spoke scalability and performance
- Redundancy and failover in hub-and-spoke
- Troubleshooting hub-and-spoke VPNs
- PKI Fundamentals
- Certificate Enrollment
- Certificate Validation
- Certificate Revocation
- PKI Configuration on Junos
- PKI Integration with IPsec
- ADVPN Overview
- ADVPN Components
- ADVPN Tunnel Establishment
- ADVPN Configuration
- ADVPN Routing
- ADVPN Troubleshooting
- IPsec tunnel routing fundamentals
- Static routes for IPsec
- Policy-based routing with IPsec
- Dynamic routing over IPsec
- Route preference and failover
- Monitoring and troubleshooting IPsec routing
- Identify overlapping IP address scenarios
- Explain NAT and routing implications
- Configure NAT for overlapping addresses
- Apply IPsec with NAT traversal
- Verify and troubleshoot overlapping VPNs
- Dynamic gateway overview
- Dynamic gateway configuration
- Dynamic gateway with route-based VPNs
- Dynamic gateway with policy-based VPNs
- Dynamic gateway authentication
- Dynamic gateway monitoring and troubleshooting
- IPsec CoS Overview
- CoS Fields in IPsec Headers
- CoS Classification and Marking
- CoS Queuing and Scheduling
- CoS and Tunnel Interfaces
- CoS with IPsec and NAT
- Troubleshooting CoS in IPsec
- APBR Profile Overview
- Profile Components
- Creating APBR Profiles
- Applying Profiles to Interfaces
- Profile Precedence and Ordering
- Default and Fallback Behavior
- Verifying APBR Profiles
- Troubleshooting APBR Profiles
- APBR policy structure
- APBR policy configuration
- APBR policy application
- APBR policy verification
- Routing instance types
- Routing instance configuration
- Routing instance isolation
- Routing instance and APBR integration
- APBR Overview
- APBR Configuration
- APBR Application Identification
- APBR User Identification
- APBR Path Selection
- APBR Monitoring and Troubleshooting
- Multinode HA Overview
- HA Terminology
- HA Modes
- HA Requirements
- HA Configuration Basics
- HA Monitoring and Failover
- Chassis cluster architecture
- Multinode HA architecture
- Comparison of chassis cluster and multinode HA
- Deployment scenarios
- Cluster deployment modes
- Active/passive mode
- Active/active mode
- Mode selection criteria
- SRG Overview
- SRG Configuration
- SRG Monitoring and Failover
- SRG and Chassis Clustering
- SRG Session Ownership
- SRG Synchronization
- SRG Troubleshooting
- Interchassis link (ICL) purpose and role
- ICL configuration parameters
- ICL traffic flow and forwarding behavior
- ICL redundancy and failover mechanisms
- ICL monitoring and troubleshooting
- Active/active mode overview
- Chassis clustering in active/active mode
- Configuration of active/active mode
- Traffic load balancing
- Failover behavior
- Monitoring and troubleshooting
- Active/passive mode overview
- Device roles and states
- Failover and failback behavior
- Configuration synchronization
- Session and state synchronization
- Monitoring and health checks
- Cluster formation and management
- Troubleshooting active/passive issues
- Active node determination
- Active node enforcement
- Third-party integration overview
- Multicloud integration fundamentals
- Integration methods and APIs
- Configuration of third-party integrations
- Configuration of multicloud integrations
- Troubleshooting integration issues
- Operational considerations
- Secure Enterprise Overview
- Security Policy Design
- Threat Mitigation Techniques
- Integration with Juniper Security Products
- Automation and Orchestration
- Monitoring and Reporting
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for JN0-637, so none is invented.