- How the JN0-214 Blueprint Is Organized
- Domain 1: Cloud Fundamentals
- Domain 2: Cloud Infrastructure (NFV and SDN)
- Domain 3: Network Virtualization
- Domain 4: Cloud Virtualization
- Domain 5: Cloud Orchestration with OpenStack
- Domain 6: Cloud Orchestration with Kubernetes
- Domain 7: Cloud Orchestration with OpenShift
- Sequencing the Seven Domains Across Your Study Weeks
- Exam Format and Logistics That Frame the Domains
- Frequently Asked Questions
- The JN0-214 blueprint has exactly seven official objective headings, and Juniper does not publish percentage weights for any of them.
- The exam is 65 multiple-choice questions in 90 minutes, delivered through Pearson VUE at a published base fee of $200.
- Published software versions are Contrail 22.4, OpenStack Zed, Kubernetes 1.24 and OpenShift 4.10, so study material should match them.
- Three of the seven domains are orchestration platforms: OpenStack, Kubernetes and OpenShift. Expect to distinguish them clearly.
How the JN0-214 Blueprint Is Organized
The Juniper Networks Certified Associate, Cloud (JNCIA-Cloud) credential is tested by exam code JN0-214. Its official objectives are published by Juniper (now presented under HPE Juniper Networking branding) as seven headings. Each heading lists specific subtopics, and the verbs are consistently "identify" and "describe" level: candidates are expected to recognize concepts, explain how components work, and tell similar technologies apart.
One point deserves emphasis up front: the issuer does not publish percentage weights for these domains. Plenty of third-party pages claim to know the split, but those figures are not issuer facts. This guide therefore treats all seven domains as in scope and gives you a way to prioritize based on the structure of the blueprint rather than invented percentages. If you want the bigger picture of the credential first, see What Is JNCIA-Cloud?, and for a preparation roadmap that builds on these domains, read the JNCIA-Cloud Study Guide 2026.
| # | Official Domain | Core Theme |
|---|---|---|
| 1 | Cloud Fundamentals | Deployment and service models, cloud-native architecture, automation tools |
| 2 | Cloud Infrastructure (NFV and SDN) | NFV architecture, orchestration, VNFs; SDN architecture, controllers, solutions |
| 3 | Network Virtualization | Virtual network types, underlay/overlay, tunneling and encapsulation |
| 4 | Cloud Virtualization | Linux virtualization, hypervisors, KVM/QEMU, Linux containers, Docker |
| 5 | Cloud Orchestration with OpenStack | VMs, Heat templates, UIs, networking plugins, security groups |
| 6 | Cloud Orchestration with Kubernetes | Containers, API objects, namespaces, CNI plug-ins |
| 7 | Cloud Orchestration with OpenShift | Workloads, CLI/WebUI, node types, network types |
Domain 1: Cloud Fundamentals
This is the vocabulary domain, and it underpins everything else. The blueprint asks you to identify concepts and functionality across four areas: deployment models, service models, cloud-native architectures, and cloud automation tools.
Domain 1 Topics to Master
You should be able to look at a short scenario and name the model it describes.
- Deployment models: public, private and hybrid cloud, including why an organization would choose each.
- Service models: SaaS, IaaS and PaaS, and who manages which layer in each.
- Cloud-native architectures: the idea of building applications as loosely coupled, containerized services designed for elastic environments.
- Cloud automation tools: what automation and orchestration tooling does for provisioning, repeatability and scale.
Because this domain is conceptual, it is easy to underestimate. The risk is not difficulty but imprecision: questions in this style often hinge on one distinguishing word, such as who controls the operating system in IaaS versus PaaS. Build crisp, one-sentence definitions and be ready to separate near-neighbors.
Domain 2: Cloud Infrastructure (NFV and SDN)
Domain 2 covers two related but distinct ideas, and the blueprint lists them separately. Keeping them separate in your head is the key to avoiding confusion.
Network Functions Virtualization
NFV is about running network functions (firewalls, routers, load balancers) as software rather than dedicated appliances. The objectives call out the NFV architecture, NFV orchestration, and VNFs (virtualized network functions). Know the role each plays: the infrastructure that hosts the functions, the orchestration layer that deploys and manages them, and the functions themselves.
Software-Defined Networking
SDN is about separating the control plane from the data plane and centralizing control. The objectives list the SDN architecture, the SDN controller, and SDN solutions. Expect to explain what a controller does, how it communicates with the devices it manages, and why centralized control changes how networks are operated. Juniper's published software versions include Contrail 22.4, which is the relevant Juniper SDN product context for this exam version, so study materials tied to that release will align best.
Domain 3: Network Virtualization
This domain is where networking professionals tend to feel most at home, and it is also where the exam gets specific. The objectives cover virtual network types, underlay and overlay networks, and encapsulation and tunneling.
Encapsulation and Tunneling Technologies Named in the Blueprint
The official list is explicit, so learn each one by name:
- MPLS over GRE
- MPLS over UDP
- VXLAN
- EVPN with VXLAN
- GENEVE
For each, be able to explain what problem the encapsulation solves, how it relates to the underlay and overlay, and how the technologies differ from one another. Underlay versus overlay is a foundational distinction: the underlay is the physical or routed transport, and the overlay is the virtual network built on top of it using tunnels. Candidates who skip GENEVE or treat EVPN with VXLAN as identical to plain VXLAN are exposing themselves to avoidable misses, since EVPN supplies a control plane that VXLAN alone does not.
Domain 4: Cloud Virtualization
Domain 4 splits into two halves: Linux virtualization and Linux containers. Both are necessary groundwork for the orchestration domains that follow.
Linux Virtualization
The objectives cover Linux architecture, hypervisor types (Type 1 and Type 2), hypervisor operations and concepts, KVM and QEMU concepts and operations, and creating virtual machines. Know how a Type 1 (bare-metal) hypervisor differs from a Type 2 (hosted) hypervisor, and understand how KVM and QEMU work together in a Linux environment.
Linux Containers
The container half of the domain asks you to compare containers with virtual machines, identify container components, and understand creating containers using Docker. The central conceptual contrast is that containers share the host kernel while VMs each run their own guest operating system. That single idea explains most of the differences in isolation, footprint and startup behavior that questions probe.
Domain 5: Cloud Orchestration with OpenStack
OpenStack is the VM-oriented orchestration platform in the blueprint, and the published version for this exam is OpenStack Zed. The objectives focus on creating and managing VMs, automation using Heat templates written in YAML, using the OpenStack user interfaces, OpenStack networking plugins, and OpenStack security groups.
Domain 5 Topics to Master
- Creating and managing VMs: the workflow and the components involved in launching instances.
- Heat templates (YAML): how declarative templates automate the deployment of resources. Be comfortable reading a simple YAML template and recognizing what it provisions.
- OpenStack UIs: the dashboard and command-line interfaces for managing resources.
- Networking plugins: how networking is extended and integrated within OpenStack.
- Security groups: how they filter traffic to instances.
Reading YAML is a practical skill worth building even though the exam is multiple-choice. Being able to scan a Heat template and understand its structure makes template-based questions much faster to answer.
Domain 6: Cloud Orchestration with Kubernetes
Kubernetes handles container orchestration, and the published version for this exam is Kubernetes 1.24. The objectives cover creating and managing containers in Kubernetes, the core API objects (Pods, ReplicaSets, Deployments and Services), and Kubernetes namespaces and CNI plug-ins.
The Four API Objects You Must Distinguish
- Pods: the smallest deployable unit, wrapping one or more containers.
- ReplicaSets: maintain a stable set of replica Pods.
- Deployments: manage ReplicaSets and provide declarative updates.
- Services: give a stable network endpoint to a set of Pods.
The layering relationship among these objects (a Deployment manages ReplicaSets, which manage Pods, fronted by a Service) is a frequent source of questions. Namespaces provide logical separation of resources within a cluster, and CNI plug-ins are how pod networking is implemented. If you only memorize definitions without understanding the relationships, scenario-style questions will be harder than they need to be.
Domain 7: Cloud Orchestration with OpenShift
OpenShift is the final orchestration platform, and the published version here is OpenShift 4.10. The objectives cover creating, managing and monitoring OpenShift workloads, navigating the OpenShift CLI or WebUI, node types (provisioner and control plane), and network types (routable, provisioning, management).
Domain 7 Topics to Master
- Workloads: creating, managing and monitoring them within OpenShift.
- Interfaces: navigating the OpenShift CLI or WebUI.
- Node types: provisioner and control plane.
- Network types: routable, provisioning and management.
OpenShift builds on Kubernetes, so a solid Domain 6 foundation makes this domain far easier. The node and network type vocabulary is distinctive, though, and generic Kubernetes study will not cover it. Treat those lists as memorization targets: know what each node type and each network type is for.
Key Takeaway
The three orchestration domains are easy to blur together. Build a one-page comparison of OpenStack (VMs, Heat/YAML, security groups), Kubernetes (Pods, ReplicaSets, Deployments, Services, CNI) and OpenShift (node types, network types) so you can tell them apart instantly under time pressure.
Sequencing the Seven Domains Across Your Study Weeks
Since the issuer publishes no weights, a sensible order follows dependencies rather than guesses about emphasis. Foundational concepts first, then the virtualization layer, then the three orchestrators in increasing specificity. Here is one way to lay it out over six weeks:
Domains 1 and 2
- Lock down deployment and service model definitions
- Separate NFV from SDN and learn the controller's role
Domain 3
- Underlay versus overlay
- MPLS over GRE, MPLS over UDP, VXLAN, EVPN with VXLAN and GENEVE
Domain 4
- Type 1 versus Type 2 hypervisors, KVM/QEMU
- Containers versus VMs, Docker basics
Domain 5
- VM lifecycle, Heat templates in YAML
- Networking plugins and security groups
Domains 6 and 7
- Pods, ReplicaSets, Deployments, Services, namespaces, CNI
- OpenShift node types and network types
Review and practice
- Revisit weak domains
- Take timed practice questions on the JNCIA-Cloud practice test site
The reasoning is dependency-driven: Domain 4's container concepts feed directly into Kubernetes, and Kubernetes feeds directly into OpenShift. For quick last-mile review, the JNCIA-Cloud Cheat Sheet condenses the must-know facts, and you can gauge your readiness with the practice questions on the main site.
Exam Format and Logistics That Frame the Domains
Understanding the container the domains sit in helps you pace your preparation. The JN0-214 exam is an English-language written multiple-choice examination of 65 questions with a 90-minute time limit. It is delivered through Pearson VUE, either at a test center or through OnVUE remote proctoring, subject to availability and the technical and ID requirements. The published base examination fee is $200 plus applicable taxes. For the full cost picture, see the JNCIA-Cloud Certification Cost breakdown.
A few facts are worth getting exactly right:
- Passing score: the exam uses an exam-specific statistical cut score. It is not the 70% threshold used by the separate voucher assessment, and third-party "pass rate" figures do not establish an official score. Details are in the passing score guide.
- Prerequisites: none. No mandatory degree, experience hours or prior certification is stated. See JNCIA-Cloud Requirements.
- Validity: three years, with renewal through the issuer's recertification options.
- Retakes: no waiting period after a first failed attempt, 14 calendar days after second and subsequent failures, and a passed exam cannot be retaken within 18 months.
- Results: shown immediately but subject to security validation.
Because the exam tests recognition of concepts and functionality rather than live configuration, strong conceptual clarity beats rote command memorization. If you are wondering how demanding that makes it, the difficulty guide walks through what to expect.
Frequently Asked Questions
The official objectives are organized into seven headings: Cloud Fundamentals, Cloud Infrastructure (NFV and SDN), Network Virtualization, Cloud Virtualization, Cloud Orchestration with OpenStack, Cloud Orchestration with Kubernetes, and Cloud Orchestration with OpenShift.
Juniper does not publish percentage weights for these domains, so no domain can be officially identified as the highest weighted. Treat all seven as testable and prepare each of them.
The published versions for JN0-214 are Contrail 22.4, OpenStack Zed, Kubernetes 1.24 and OpenShift 4.10. Older study resources may reference earlier releases and older objective headings, so check that your materials match.
The exam is a written multiple-choice test, so it measures knowledge of concepts, operations and functionality rather than a practical lab skill. Hands-on practice can still deepen your understanding, but the exam itself is not a hands-on assessment.
No. There is no prerequisite certification for JNCIA-Cloud. The two are separate associate-level credentials, and neither is required to attempt the other.