Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke deployment where the hub uses mGRE and spokes use mGRE. Spoke-to-spoke traffic works, but the administrator notices that the spokes are installing host routes for other spokes in their routing tables. Which DMVPN Phase 3 feature is responsible for adding these specific host routes?

⚠ Common exam trap

It's easy for candidates to confuse the hub-side redirect trigger with the spoke-side shortcut that actually installs the host route in the routing table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NHRP shortcut on the spokes

In DMVPN Phase 3, the hub uses NHRP redirect to inform a spoke that a better path exists, and the spokes use NHRP shortcut to resolve the destination and install a host route for the peer tunnel address. Those host routes are what let the spoke forward traffic directly to another spoke. Without NHRP shortcut on the spokes, the redirect messages would not result in usable direct paths.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip nhrp registration no-unique on the spokes

    Why it's wrong here

    The ip nhrp registration no-unique command allows multiple spokes to register with the same tunnel address, which is useful behind NAT or for redundancy. It does not create host routes for peer tunnel addresses on the spokes; that behavior comes from the shortcut mechanism after NHRP resolution succeeds.

  • ✗

    ip nhrp map multicast dynamic on the hub

    Why it's wrong here

    The ip nhrp map multicast dynamic command lets the hub dynamically create multicast NHRP mappings for registering spokes. It affects how multicast traffic is replicated to spokes and does not cause spokes to install host routes for peer tunnel addresses, so it is unrelated to the observed host routes.

  • ✓

    NHRP shortcut on the spokes

    Why this is correct

    With NHRP shortcut, the spoke installs a host route for the destination spoke tunnel address after successful NHRP resolution. This route points at the tunnel interface and allows the spoke to send traffic directly to the peer, bypassing the hub. The host routes observed in the routing table are the visible result of NHRP shortcut operation.

  • ✗

    NHRP redirect on the hub

    Why it's wrong here

    NHRP redirect is the hub-side mechanism that tells a spoke that a more optimal path exists for a flow it sent through the hub. It triggers the spoke to initiate NHRP resolution, but redirect itself does not install host routes in the routing table; it is the shortcut mechanism that consumes the resolution result.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.