300-410 VPN Technologies Practice Question
A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router is a Cisco IOS XE device with the tunnel source as a physical interface and tunnel mode gre multipoint. Spoke routers are configured with dynamic NHRP mappings. The engineer notices that spoke-to-spoke traffic initially goes through the hub, but after the first packet, the spokes establish a direct tunnel. Which NHRP feature is responsible for this behavior?
⚠ Common exam trap
Watch out — candidates often confuse NHRP authentication or registration with the mechanisms that enable direct spoke-to-spoke tunnels, when redirect and shortcut switching are the actual features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NHRP redirect and shortcut switching
In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to the destination. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, builds a direct mGRE tunnel. This reduces latency and hub load by allowing direct spoke-to-spoke traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NHRP holdtime and registration
Why it's wrong here
Holdtime and registration control how long NHRP mappings are valid and how spokes register with the hub. They are essential for maintaining the NHRP database but do not cause the spoke to establish a direct tunnel to another spoke. These parameters affect stability and reachability, not the optimization of the data path.
- ✓
NHRP redirect and shortcut switching
Why this is correct
NHRP redirect allows the hub to inform the source spoke that a better path exists, and shortcut switching enables the spoke to build a direct tunnel to the destination spoke. This is the core of DMVPN Phase 3, where the hub sends a redirect message and the spoke initiates an NHRP resolution for the destination, creating a direct spoke-to-spoke tunnel.
- ✗
NHRP server-only and client-only configuration
Why it's wrong here
Server-only and client-only settings define the role of a router in NHRP, but they do not inherently enable spoke-to-spoke direct tunnels. The hub is typically the server, and spokes are clients, but without redirect and shortcut switching, traffic continues to traverse the hub. These roles are foundational but not the specific mechanism for direct spoke-to-spoke communication.
- ✗
NHRP authentication and mapping
Why it's wrong here
NHRP authentication secures NHRP messages between peers, and static mapping provides a fixed mapping, but neither triggers direct spoke-to-spoke tunnel creation. Authentication ensures only trusted devices participate, while static mapping is used when dynamic resolution is not desired. These features do not cause the spoke to bypass the hub after the first packet.
Go deeper
Related to this question
Learn chapter
DMVPN and FlexVPN Technologies
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.