This article describes which EX models support Secure Boot and how to check if Secure Boot has been enabled on the device or not?
The Secure Boot process begins with Secure Flash, which ensures that unauthorized changes cannot be made to the firmware. Authorized releases of Junos OS carry a digital signature produced by either Juniper Networks directly or one of its authorized partners. At each point of the boot-up process, each component verifies the next link is sound by checking the signature to ensure that the binaries have not been modified.The boot process cannot continue unless the signature is correct. This "chain of trust" continues until the operating system takes control. In this way, overall system security is enhanced, increasing resistance to some firmware-based persistent threats.Secure Boot requires no actions on your part to implement. It is implemented on supported hardware by default. Below is the link to check for supported models and versions:-https://apps.juniper.net/feature-explorer/feature-info.html?fKey=7360&fn=Secure+Boot
https://apps.juniper.net/feature-explorer/parent-feature-info.html?pFKey=1224&pFName=Secure%20Boot#:~:text=QFX5200%2D32C%20cannot%20use%20a%20secure%20image%0AQFX5200%2D48Y%20only%20supports%20a%20secure%20image