300-410 Infrastructure Services Practice Question
A network engineer is configuring a Cisco IOS XE router to support a DMVPN Phase 3 hub-and-spoke topology. The hub router must be able to redirect spoke-to-spoke traffic without requiring the spokes to have a direct route to each other. Which technology should be implemented on the hub to enable the hub to inform the originating spoke of the optimal spoke-to-spoke path?
⚠ Common exam trap
Many exam-takers confuse NHRP shortcut with NHRP redirect; shortcut is on the spoke, redirect is on the hub.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NHRP redirect
In DMVPN Phase 3, the hub uses NHRP redirect to notify the originating spoke that a better path exists directly to the destination spoke. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, establishes a direct tunnel. This optimizes traffic flow and reduces hub load. NHRP shortcut on the spoke caches the direct path, but the hub's redirect is the trigger.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multipoint GRE (mGRE)
Why it's wrong here
Multipoint GRE (mGRE) is the tunnel interface type used on the hub in DMVPN, allowing a single tunnel interface to support multiple GRE tunnels. It is a foundational component of DMVPN, but it does not by itself provide the redirect capability. mGRE enables the hub to have a single tunnel interface, but the redirect function is provided by NHRP. Without NHRP redirect, the hub cannot signal the spoke to establish a direct tunnel.
- ✓
NHRP redirect
Why this is correct
NHRP redirect is a DMVPN Phase 3 feature that enables the hub to send an NHRP redirect message to the originating spoke when it detects traffic being routed through the hub to another spoke. The redirect instructs the spoke to initiate an NHRP resolution request for the destination spoke's NBMA address, allowing the spoke to build a direct tunnel. This reduces latency and hub load, and it is the correct mechanism for the hub to inform the spoke of the optimal path.
- ✗
IPsec tunnel protection
Why it's wrong here
IPsec tunnel protection is used to encrypt traffic on the DMVPN tunnels, providing confidentiality and integrity. While it is commonly deployed with DMVPN, it does not influence path selection or enable spoke-to-spoke communication. The question asks for the technology that allows the hub to redirect traffic; IPsec is a security feature, not a routing or NHRP optimization. Therefore, it is not the correct answer for this scenario.
- ✗
Next Hop Resolution Protocol (NHRP) shortcut
Why it's wrong here
NHRP shortcut allows the spoke to learn a direct path to another spoke by sending an NHRP resolution request. However, in DMVPN Phase 3, the hub does not simply respond with the other spoke's NBMA address; instead, the hub uses NHRP redirect to tell the originating spoke to query the destination spoke directly. NHRP shortcut is the mechanism on the spoke side that caches the shortcut, but it does not by itself enable the hub to redirect traffic. This option is a necessary component but not the hub's specific redirect function.
Go deeper
Related to this question
Learn chapter
EIGRP Route Summarization and Filtering
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.