- JN0-352 publishes nine unweighted objective headings; Juniper gives no percentage split, so cover every domain.
- The exam is 65 multiple-choice questions in 90 minutes, delivered through Pearson VUE.
- An active JNCIA-Junos certification is required; equivalent knowledge alone does not satisfy the prerequisite.
- Each protocol domain lists its own troubleshooting tools, and High Availability omits ping and traceroute.
How the JN0-352 Outline Is Organized
The Juniper Networks Certified Specialist, Enterprise Routing and Switching (JNCIS-ENT) exam, code JN0-352, is built on an official objectives outline with nine top-level headings: Layer 2 Switching or VLANs, Spanning Tree, Layer 2 Security, Protocol Independent Routing, OSPF, IS-IS, BGP, Tunnels, and High Availability. Juniper describes the outline as a high-level view of the skillset, which means it is not an exhaustive task analysis. Treat it as a floor for your preparation rather than a ceiling.
Two structural features matter for how you study. First, no percentage weights are published for any heading, so you cannot responsibly decide that one domain is "worth" more than another. Any site claiming a precise domain breakdown is inventing it. Second, almost every domain splits its objectives into two kinds of knowledge: conceptual understanding (how a protocol or feature works and why it exists) and configuration, monitoring, and troubleshooting knowledge (how you would set it up, verify it, and diagnose it in Junos OS). Both kinds are fair game on a written exam, and neither converts a multiple-choice test into a hands-on assessment.
If you are still orienting yourself on what the credential is and how it fits the Junos enterprise track, start with what JNCIS-ENT certification is, then return here for the content map.
Domains 1-3: The Layer 2 Block
Domain 1: Layer 2 Switching or VLANs
Layer 2 Switching or VLANs
This domain pairs concepts with configuration and monitoring knowledge across three parent areas.
- Layer 2 switching in Junos OS: bridging components and frame processing.
- VLAN concepts: ports, tagging, native VLANs and voice VLANs, and inter-VLAN routing.
- Configuration, monitoring, and troubleshooting: interfaces and ports, VLANs, and inter-VLAN routing.
The trap here is treating this as review material. Because the prerequisite is JNCIA-Junos, candidates assume the basics are covered. In practice, the specialist exam expects you to reason about how frames are processed on a Junos device, what happens to tagged versus untagged traffic on a trunk with a native VLAN, and how a voice VLAN differs from a data VLAN on the same access port. Inter-VLAN routing appears in both the concept and the configuration bullets, so expect questions about the routed interface construct as well as the decision of when routing between VLANs is required at all.
Domain 2: Spanning Tree
Spanning Tree
Concepts and operations on one side, configuration and troubleshooting on the other.
- STP and RSTP concepts: port roles and states, Bridge Protocol Data Units (BPDUs), convergence and reconvergence.
- Configuration, monitoring, and troubleshooting: STP and RSTP.
Spanning tree questions reward precision about roles versus states. A port role (root, designated, alternate, backup) is not the same thing as a port state (such as discarding or forwarding), and the difference between classic STP and RSTP behavior during reconvergence is a recurring conceptual theme. Know what information BPDUs carry and how a topology change propagates, because the exam can ask you to predict which port ends up in which role after a change.
Domain 3: Layer 2 Security
Layer 2 Security
The broadest of the switching domains, with three parent areas.
- Protection and security concepts: BPDU, loop, or root protection; port security including MAC limiting, DHCP snooping, dynamic ARP inspection (DAI), and IP source guard; MACsec; storm control.
- Layer 2 firewall filters: filter types, processing order, match criteria and actions.
- Configuration, monitoring, and troubleshooting: protection, port security, storm control, and firewall filter configuration and application.
Candidates routinely under-study this domain because it reads like a feature checklist. Do not skip MACsec, and do not collapse the port-security examples into a single idea: MAC limiting, DHCP snooping, DAI, and IP source guard each address a different attack or misbehavior and several depend on one another (DAI and IP source guard lean on the binding information DHCP snooping builds). Firewall filter processing order is a classic source of wrong answers; know how terms are evaluated and what the implicit behavior is when nothing matches.
Domains 4-7: Routing Fundamentals and Protocols
Domain 4: Protocol Independent Routing
Protocol Independent Routing
Functionality that applies regardless of which routing protocol is running.
- Concepts: static, aggregate, and generated routes; Martian addresses; routing instances including routing information base (RIB) groups; load balancing; filter-based forwarding.
- Configuration, monitoring, and troubleshooting: static, aggregate, and generated routes; load balancing; filter-based forwarding.
Notice what is conceptual-only. Martian addresses and routing instances, including RIB groups, appear in the concept list but not in the configuration bullets, so expect "what is this and why does it exist" rather than "which stanza configures it." The distinction between aggregate routes and generated routes is a favorite: both summarize, but they behave differently with respect to contributing routes and next-hop treatment. Load balancing in Junos is another place where candidates carry over assumptions from other vendors; study how Junos handles per-prefix versus per-packet behavior as the platform documents it.
Domain 5: OSPF
OSPF
The deepest of the link-state domains in terms of listed topics.
- Concepts: link-state database, OSPF packet types, router ID, adjacencies and neighbors, designated router (DR) and backup designated router (BDR), area and router types, realms, and LSA packet types.
- Configuration, monitoring, and troubleshooting: areas, interfaces, and neighbors; additional basic options; routing policy application; and the tool list of ping, traceroute, traceoptions, show commands, and logging.
Note that "Realms" is a published topic in this domain; make sure the study material you use actually addresses it rather than stopping at area and router types. The LSA types and which area types suppress which of them is the densest memorization load. Pair it with an understanding of why DR/BDR election exists on broadcast segments and what state an adjacency must reach before routes are exchanged.
Domain 6: IS-IS
IS-IS
Parallel in structure to OSPF but with its own vocabulary.
- Concepts: link-state database, IS-IS Protocol Data Units (PDUs), type-length-values (TLVs), adjacencies and neighbors, levels and areas, designated intermediate system (DIS), and metrics.
- Configuration, monitoring, and troubleshooting: levels, interfaces, and adjacencies; additional basic options; routing policy application; and ping, traceroute, traceoptions, show commands, and logging.
IS-IS is where candidates with a Cisco or OSPF-heavy background lose points, because the instincts do not transfer cleanly. Levels (Level 1, Level 2, and both) take the place of OSPF area types, the DIS replaces the DR/BDR concept with different election behavior, and TLVs are the extensible container for what OSPF carries in LSAs. Existing community tutorials on IS-IS are useful for the concepts, but verify anything you read against the Junos 23.1 scope rather than assuming a years-old post matches the current exam.
Domain 7: BGP
BGP
Both internal and external behavior are in scope.
- Concepts: basic operation, message types, attributes, route and path selection process, and IBGP/EBGP functionality and interaction.
- Configuration, monitoring, and troubleshooting: groups and peers; additional basic options; routing policy application; and ping, traceroute, traceoptions, show commands, and logging.
Path selection is the centerpiece. You should be able to take a set of candidate routes with differing attributes and determine which wins, and explain why IBGP and EBGP peers treat the same attribute differently. In Junos, BGP configuration is organized around groups and peers, so be comfortable reading how group-level and neighbor-level settings interact. Routing policy application ties Domains 5, 6, and 7 together, which is a good reason to learn Junos policy once and reuse it.
Domains 8-9: Tunnels and High Availability
Domain 8: Tunnels
Tunnels
The smallest domain by listed topic count, but not one to skip.
- Concepts: tunneling applications and considerations, Generic Routing Encapsulation (GRE), and IP-IP.
- Configuration, monitoring, and troubleshooting: GRE, IP-IP, and the ping, traceroute, traceoptions, show commands, and logging tool list.
Because the domain is compact, a few questions can hinge on small details: what each encapsulation adds, what the tunnel endpoints need in terms of reachability, and the considerations that make a tunnel behave badly (such as a recursive routing problem or an MTU mismatch). Do not assume a small objective list means few questions; with no published weights, you cannot know.
Domain 9: High Availability
High Availability
A wide domain that mixes Layer 2 and routing-plane resilience.
- Concepts: link aggregation groups (LAG), redundant trunk groups (RTG), virtual chassis, graceful restart, graceful Routing Engine switchover (GRES), nonstop active routing (NSR), nonstop bridging (NSB), Bidirectional Forwarding Detection (BFD), Virtual Router Redundancy Protocol (VRRP), and unified in-service software upgrade (ISSU).
- Configuration, monitoring, and troubleshooting: LAG and RTG; virtual chassis; graceful restart, GRES, NSB, and NSR; VRRP; ISSU; and traceoptions, show commands, and logging.
Two scoping details are worth noticing. BFD appears in the concept list but is not repeated in the configuration bullets, so study it as a mechanism (fast failure detection that protocols can lean on) rather than a configuration drill. And the High Availability troubleshooting list names traceoptions, show commands, and logging only; ping and traceroute are not listed here, unlike the four protocol and tunnel domains. The most common conceptual confusion is among GRES, graceful restart, NSR, and NSB: each protects a different layer of the control and forwarding behavior, and exam questions often ask which feature addresses a stated failure scenario.
Junos 23.1 and the Old-Material Trap
The exam is tied to Junos 23.1, and the current exam code is JN0-352. Older third-party offerings still circulate under earlier codes such as JN0-351, and some course catalogs continue to carry those labels. A course that carries an older exam code is a historical offering, not verified coverage of the current objectives. Networking fundamentals do not expire, so much of that material remains conceptually useful, but you cannot assume it addresses every current topic, and adding a year to a product title does not update its contents.
| Source type | How to use it | Caution |
|---|---|---|
| Official exam objectives page for JN0-352 | Authoritative scope and the nine headings | High-level view, not an exhaustive task list |
| Older JN0-351 or earlier courses | Concept reinforcement for stable protocols | Not verified as complete JN0-352 coverage |
| Issuer open learning course | Free-access preparation aligned to the track | Module software references can differ from Junos 23.1 |
| Commercial practice questions | Self-testing and gap discovery | Not official questions; vendor alignment claims are unverified |
For more on how much effort the material typically demands, read how hard the JNCIS-ENT exam is.
Sequencing the Nine Domains Across Your Prep
Because the outline is unweighted, sequence by dependency, not by guessed importance. Layer 2 foundations feed security; routing fundamentals feed every protocol; the protocols feed high availability. One short plan that follows that logic:
Layer 2 foundations
- Domain 1: frame processing, tagging, native and voice VLANs, inter-VLAN routing.
- Domain 2: port roles versus states, BPDUs, STP versus RSTP reconvergence.
Layer 2 security and routing basics
- Domain 3: MACsec, every port-security example, storm control, filter processing order.
- Domain 4: aggregate versus generated routes, Martian addresses, RIB groups, filter-based forwarding.
The three protocol domains
- Domain 5: LSA types, DR/BDR, area types, realms.
- Domain 6: levels, DIS, TLVs, metrics.
- Domain 7: attributes, path selection, IBGP versus EBGP.
Tunnels, availability, and review
- Domain 8: GRE and IP-IP considerations.
- Domain 9: separate GRES, NSR, NSB, and graceful restart; place BFD and VRRP.
Adjust the length to your own background; this is a template to bend, not a guarantee. The point is the ordering. For a fuller week-by-week framework, see our JNCIS-ENT study guide, and when you are ready to test recall under time pressure, use the JNCIS-ENT practice test to find which domains need another pass.
Key Takeaway
Rank your own weak domains from practice results, not from guessed exam weights. Re-study the domain where you miss both the concept question and its configuration counterpart, since the outline treats them as separate knowledge targets.
Exam Mechanics That Frame the Domains
The domains only matter in the context of the delivery format. JN0-352 is a written, multiple-choice exam of 65 questions with a 90-minute time limit, delivered through Pearson VUE either at a test center or via OnVUE online proctoring, in English only. That averages a little over a minute per question, so you need quick recognition of concepts rather than long derivations. The exam page does not publish a scored versus unscored split, and nothing indicates an adaptive format.
A few facts candidates often get wrong:
- Prerequisite: an active JNCIA-Junos certification is required. Equivalent knowledge does not substitute, and an expired certification cannot satisfy the prerequisite. Details are in the JNCIS-ENT requirements guide.
- Passing score: not publicly published; the score report for your attempt includes its threshold, and thresholds can differ between tests. See the passing score breakdown.
- Fee: an exact current price was not verified, so check the provider's voucher store directly rather than trusting a quoted figure. More context is in the certification cost article.
- Results: pass/fail is shown immediately, but results are provisional pending security validation, with valid results posted to CertMetrics within three business days.
- Retakes: no waiting period after a first failed attempt; after a second or later failure, a 14 calendar day wait applies. After passing, wait at least 18 months before taking the same exam again.
- Validity: three years, with renewal through an appropriate current-level exam, a higher-level certification in the same track, or the specified course route.
For OnVUE delivery, expect a system check, a private testing environment, matching government-issued photo identification, and no books or notes. Scheduling specifics are covered in the exam dates guide.
Frequently Asked Questions
No. Juniper publishes nine headings for JN0-352 but no percentage weights, so any specific domain split you see elsewhere is not official. Prepare all nine and let your practice results guide extra depth.
The exam is a written multiple-choice test. It does include configuration, monitoring, and troubleshooting knowledge targets in most domains, but answering those questions demonstrates knowledge, not practical competence on live equipment.
OSPF, IS-IS, BGP, and Tunnels each list ping, traceroute, traceoptions, show commands, and logging. High Availability lists traceoptions, show commands, and logging only.
They can reinforce stable protocol concepts, but they are not verified as complete JN0-352 coverage. Check everything against the current nine-domain outline and Junos 23.1 before relying on it.
No verified cohort pass rate or JNCIS-ENT-specific salary premium has been established. For discussion of what is and is not known, see the pass rate article and the salary guide.