Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router is a Cisco IOS XE device with the tunnel source as a physical interface and tunnel mode gre multipoint. Spoke routers are configured with dynamic NHRP mappings. The engineer notices that spoke-to-spoke traffic initially goes through the hub, but after the first packet, the spokes establish a direct tunnel. Which NHRP feature is responsible for this behavior?

⚠ Common exam trap

Watch out — candidates often confuse NHRP authentication or registration with the mechanisms that enable direct spoke-to-spoke tunnels, when redirect and shortcut switching are the actual features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NHRP redirect and shortcut switching

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to the destination. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, builds a direct mGRE tunnel. This reduces latency and hub load by allowing direct spoke-to-spoke traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NHRP holdtime and registration

    Why it's wrong here

    Holdtime and registration control how long NHRP mappings are valid and how spokes register with the hub. They are essential for maintaining the NHRP database but do not cause the spoke to establish a direct tunnel to another spoke. These parameters affect stability and reachability, not the optimization of the data path.

  • ✓

    NHRP redirect and shortcut switching

    Why this is correct

    NHRP redirect allows the hub to inform the source spoke that a better path exists, and shortcut switching enables the spoke to build a direct tunnel to the destination spoke. This is the core of DMVPN Phase 3, where the hub sends a redirect message and the spoke initiates an NHRP resolution for the destination, creating a direct spoke-to-spoke tunnel.

  • ✗

    NHRP server-only and client-only configuration

    Why it's wrong here

    Server-only and client-only settings define the role of a router in NHRP, but they do not inherently enable spoke-to-spoke direct tunnels. The hub is typically the server, and spokes are clients, but without redirect and shortcut switching, traffic continues to traverse the hub. These roles are foundational but not the specific mechanism for direct spoke-to-spoke communication.

  • ✗

    NHRP authentication and mapping

    Why it's wrong here

    NHRP authentication secures NHRP messages between peers, and static mapping provides a fixed mapping, but neither triggers direct spoke-to-spoke tunnel creation. Authentication ensures only trusted devices participate, while static mapping is used when dynamic resolution is not desired. These features do not cause the spoke to bypass the hub after the first packet.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.