hardMultiple Select
CCNP Practice Question: Which two statements about DMVPN phase 2 are…
Which two statements about DMVPN phase 2 are true? (Choose two.)
⚠ Common exam trap
The trap is confusing DMVPN phases: phase 1 only hub-to-spoke, phase 2 adds spoke-to-spoke with NHRP redirect, phase 3 adds NHRP shortcut and scalability improvements. Candidates must remember that phase 2 uses mGRE on spokes and NHRP redirect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.
Option A is correct because DMVPN phase 2 enables spoke-to-spoke direct tunnels: spokes learn each other's NBMA addresses via NHRP and can build dynamic mGRE tunnels so data traffic bypasses the hub. Option C is correct because in phase 2 the hub uses NHRP redirect messages to tell a spoke that a better path to the destination exists, prompting the spoke to send an NHRP resolution request and build a direct tunnel. Option B is wrong because phase 2 requires mGRE on both the hub and the spokes, not point-to-point GRE on spokes. Option D is wrong because DMVPN phase 2 can run with or without IPsec; encryption is optional. Option E is wrong because spokes use dynamic crypto maps or IPsec profiles, not static crypto maps, to support spoke-to-spoke IPsec tunnels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.
Why this is correct
Phase 2 permits spoke-to-spoke tunnels built directly, bypassing the hub for data forwarding. Spokes learn each other's tunnel endpoints via NHRP resolution through the hub, then establish direct GRE tunnels, satisfying the requirement that inter-spoke traffic avoids hub transit.
- ✗
DMVPN phase 2 requires mGRE on the hub only; spokes use point-to-point GRE tunnels.
Why it's wrong here
DMVPN phase 2 uses mGRE on both hub and spokes, with a single mGRE tunnel interface per router; NHRP resolves spoke NBMA addresses so spoke-to-spoke traffic bypasses the hub. Point-to-point GRE on spokes describes phase 1. Phase 2's defining feature is direct spoke-to-spoke tunnels via NHRP shortcut switching.
- ✓
NHRP redirect messages are used in phase 2 to inform spokes of better paths to remote destinations.
Why this is correct
In DMVPN phase 2, NHRP redirect messages tell a spoke that a more optimal path exists to a remote destination, prompting it to query for the remote NBMA address and build a direct spoke-to-spoke tunnel.
- ✗
DMVPN phase 2 supports only IPsec protection and cannot operate without encryption.
Why it's wrong here
DMVPN phase 2 runs mGRE with NHRP and can carry plain GRE, mGRE or IPsec-protected tunnels; encryption is optional and configured separately via a protection profile. The statement would hold only if the design mandated IPsec everywhere. Phase 2's defining feature is spoke-to-spoke direct tunnels with NHRP shortcut switching.
- ✗
In DMVPN phase 2, spoke routers must be configured with static crypto maps for IPsec.
Why it's wrong here
DMVPN phase 2 uses multipoint GRE with NHRP, so spokes register their tunnel addresses dynamically and no static crypto maps are needed; IPsec profiles reference the mGRE tunnel. Static crypto maps suit point-to-point or phase 1 hub-and-spoke designs where peer addresses are fixed, which is why this distractor tempts.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.