Courseiva
VPN Technologies →hardMultiple Choice

300-410 VPN Technologies Practice Question

A network administrator is deploying DMVPN Phase 3 with IKEv2 IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers register with the hub and can communicate directly with each other. The administrator wants to ensure that spoke-to-spoke traffic is encrypted. Which statement about the IPsec configuration is true?

⚠ Common exam trap

The trap here is thinking that spoke-to-spoke traffic, because it bypasses the hub, also bypasses IPsec encryption, when in fact the encryption is applied at the tunnel interface on each spoke.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A single IPsec profile on the hub and spokes can protect both hub-to-spoke and spoke-to-spoke traffic.

In DMVPN Phase 3, the same IPsec profile applied to the multipoint GRE tunnel interface on all routers (hub and spokes) protects all traffic, including spoke-to-spoke. When a spoke initiates a direct tunnel to another spoke, the IPsec session is established using the same profile. This uniform configuration is a primary benefit of DMVPN, allowing scalable and secure any-to-any connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec must be configured on the physical interfaces of the spokes.

    Why it's wrong here

    Configuring IPsec on physical interfaces would encrypt all traffic, not just the DMVPN tunnel traffic. In DMVPN, IPsec is typically applied to the tunnel interface via an IPsec profile. Applying it to physical interfaces would be inefficient and could interfere with other traffic. The requirement is to encrypt spoke-to-spoke traffic within the DMVPN cloud, so the tunnel interface is the correct place.

  • ✓

    A single IPsec profile on the hub and spokes can protect both hub-to-spoke and spoke-to-spoke traffic.

    Why this is correct

    In DMVPN Phase 3, a single IPsec profile applied to the tunnel interface on all routers can secure both hub-to-spoke and spoke-to-spoke traffic. The dynamic multipoint tunnels are established on demand, and the same IPsec profile is used because the tunnel interface is the encryption endpoint. This simplifies configuration and is a key advantage of DMVPN with IPsec.

  • ✗

    IPsec encryption for spoke-to-spoke traffic requires a separate IPsec profile on each spoke.

    Why it's wrong here

    A separate IPsec profile per spoke is not required. DMVPN uses a single IPsec profile on all routers because the tunnel interface configuration is identical. The profile defines the transform set and IKEv2 parameters, which are the same for all peers. Using separate profiles would complicate management and is unnecessary for spoke-to-spoke encryption.

  • ✗

    Spoke-to-spoke traffic bypasses IPsec encryption because it does not traverse the hub.

    Why it's wrong here

    In DMVPN Phase 3, spoke-to-spoke traffic does not traverse the hub, but it still uses the DMVPN tunnel interfaces on the spokes. Since IPsec is applied to the tunnel interfaces, the traffic is encrypted. The dynamic tunnels are established directly between spokes, and IPsec protection is maintained end-to-end. Thus, the statement is false.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.