Courseiva
hardMultiple SelectObjective-mapped

CCNP Practice Question: Which two statements about DMVPN phase 2 are…

Which two statements about DMVPN phase 2 are true? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.

DMVPN phase 2 allows spoke-to-spoke tunnels after initial hub registration, using NHRP to resolve destination addresses and enabling direct traffic flows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.

    Why this is correct

    Correct because phase 2 enables spoke-to-spoke dynamic tunnels after the hub provides the peer's NBMA address via NHRP.

  • DMVPN phase 2 requires mGRE on the hub only; spokes use point-to-point GRE tunnels.

    Why it's wrong here

    Incorrect because both hub and spokes must use mGRE to support multiple tunnel endpoints; point-to-point GRE would limit connectivity.

  • NHRP redirect messages are used in phase 2 to inform spokes of better paths to remote destinations.

    Why this is correct

    Correct because the hub sends NHRP redirects to trigger spokes to initiate direct NHRP resolution and establish spoke-to-spoke tunnels.

  • DMVPN phase 2 supports only IPsec protection and cannot operate without encryption.

    Why it's wrong here

    Incorrect because DMVPN can operate without IPsec, though encryption is recommended for security; it is not mandatory.

  • In DMVPN phase 2, spoke routers must be configured with static crypto maps for IPsec.

    Why it's wrong here

    Incorrect because DMVPN uses IPsec profiles and dynamic crypto maps, not static crypto maps, to allow dynamic peer negotiation.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,175 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.