300-410 VPN Technologies Practice Question
A network administrator is deploying DMVPN Phase 3 with IKEv2 IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers register with the hub and can communicate directly with each other. The administrator wants to ensure that spoke-to-spoke traffic is encrypted. Which statement about the IPsec configuration is true?
⚠ Common exam trap
The trap here is thinking that spoke-to-spoke traffic, because it bypasses the hub, also bypasses IPsec encryption, when in fact the encryption is applied at the tunnel interface on each spoke.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A single IPsec profile on the hub and spokes can protect both hub-to-spoke and spoke-to-spoke traffic.
In DMVPN Phase 3, the same IPsec profile applied to the multipoint GRE tunnel interface on all routers (hub and spokes) protects all traffic, including spoke-to-spoke. When a spoke initiates a direct tunnel to another spoke, the IPsec session is established using the same profile. This uniform configuration is a primary benefit of DMVPN, allowing scalable and secure any-to-any connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPsec must be configured on the physical interfaces of the spokes.
Why it's wrong here
Configuring IPsec on physical interfaces would encrypt all traffic, not just the DMVPN tunnel traffic. In DMVPN, IPsec is typically applied to the tunnel interface via an IPsec profile. Applying it to physical interfaces would be inefficient and could interfere with other traffic. The requirement is to encrypt spoke-to-spoke traffic within the DMVPN cloud, so the tunnel interface is the correct place.
- ✓
A single IPsec profile on the hub and spokes can protect both hub-to-spoke and spoke-to-spoke traffic.
Why this is correct
In DMVPN Phase 3, a single IPsec profile applied to the tunnel interface on all routers can secure both hub-to-spoke and spoke-to-spoke traffic. The dynamic multipoint tunnels are established on demand, and the same IPsec profile is used because the tunnel interface is the encryption endpoint. This simplifies configuration and is a key advantage of DMVPN with IPsec.
- ✗
IPsec encryption for spoke-to-spoke traffic requires a separate IPsec profile on each spoke.
Why it's wrong here
A separate IPsec profile per spoke is not required. DMVPN uses a single IPsec profile on all routers because the tunnel interface configuration is identical. The profile defines the transform set and IKEv2 parameters, which are the same for all peers. Using separate profiles would complicate management and is unnecessary for spoke-to-spoke encryption.
- ✗
Spoke-to-spoke traffic bypasses IPsec encryption because it does not traverse the hub.
Why it's wrong here
In DMVPN Phase 3, spoke-to-spoke traffic does not traverse the hub, but it still uses the DMVPN tunnel interfaces on the spokes. Since IPsec is applied to the tunnel interfaces, the traffic is encrypted. The dynamic tunnels are established directly between spokes, and IPsec protection is maintained end-to-end. Thus, the statement is false.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
DMVPN and FlexVPN Technologies
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
FlexVPN
FlexVPN is a Cisco VPN solution that combines multiple VPN technologies (site-to-site, remote access, and hub-and-spoke) under a single, modular framework based on IKEv2.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.