Troubleshooting Security Policies and Security Zones |
This section of the exam measures the skills of security engineers and covers techniques for troubleshooting and monitoring security policies and zones. Candidates will demonstrate their ability to use tools like logging and tracing, along with other outputs, to effectively diagnose issues within logical systems and tenant systems. |
Logical Systems and Tenant Systems |
This section targets system administrators and security professionals, exploring the concepts, operations, and functionalities of logical systems. It includes discussions on administrative roles, security profiles, and the communication mechanisms between logical systems. Additionally, it examines tenant systems, focusing on the roles of primary system and tenant system administrators, as well as tenant system capacity considerations. |
Layer 2 Security |
Aimed at network engineers, this section provides an understanding of Layer 2 Security concepts, operations, and functionalities. Key topics include transparent mode, mixed mode, secure wire, MACsec, and Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) security. Candidates will also demonstrate their ability to configure or monitor Layer 2 Security in various scenarios |
Advanced Network Address Translation (NAT) |
This section evaluates the skills of network engineers specializing in NAT. It describes the functionalities of advanced NAT, including persistent NAT, Domain Name System (DNS) doctoring, and IPv6 NAT. Candidates are expected to demonstrate their capability to configure, troubleshoot, or monitor complex NAT scenarios effectively. |
Advanced IPsec VPNs |
Targeting network security professionals, this section covers advanced IPsec VPN concepts, operations, and functionalities. Key topics include hub-and-spoke VPNs, Public Key Infrastructure (PKI), auto discovery VPNs (ADVPNs), and handling overlapping IP addresses. Candidates will showcase their skills by configuring, troubleshooting, or monitoring advanced IPsec VPN setups. |
Advanced Policy-Based Routing (APBR) |
This section is designed for network engineers and focuses on advanced policy-based routing concepts. It includes the study of profiles, policies, routing instances, and various APBR options. Candidates will demonstrate their ability to configure or monitor advanced policy-based routing in practical scenarios. |
Multinode High Availability (HA) |
Aimed at system architects and network engineers, this section covers the concepts and functionalities of multinode HA. It discusses the differences between chassis clusters and multinode HA, deployment modes, services redundancy groups (SRG), and the behavior of active nodes. Candidates will demonstrate their skills in configuring or monitoring multinode HA systems. |
Automated Threat Mitigation |
This section targets security analysts and focuses on the concepts, operations, and functionalities of Automated Threat Mitigation. It covers integration with third-party or multi-cloud services and emphasizes secure enterprise practices. Candidates are expected to demonstrate their understanding of how to implement and manage automated threat mitigation strategies effectively. |
Official Information |
https://www.juniper.net/us/en/training/certification/tracks/security/jncip-sec.html |