Courseiva
Infrastructure Services →mediumMultiple Choice

300-410 Infrastructure Services Practice Question

A network engineer is configuring a DMVPN Phase 3 hub router. Spoke routers are behind dynamic NAT and cannot receive inbound connections. The engineer needs to ensure that spoke-to-spoke traffic flows directly without traversing the hub. Which technology must be enabled on the hub to achieve this?

⚠ Common exam trap

A common mix-up: candidates confuse NHRP shortcut with NHRP redirect; shortcut is configured on spokes, but redirect must be enabled on the hub to trigger the process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NHRP redirect

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination's public address and establish a direct tunnel. Without NHRP redirect on the hub, spokes continue to send traffic through the hub even if they are capable of direct communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec transport mode

    Why it's wrong here

    IPsec transport mode encrypts only the payload of the packet and is often used with GRE to reduce overhead. While it can be used in DMVPN, it does not by itself enable spoke-to-spoke direct tunnels. The question asks for the technology to allow direct spoke-to-spoke traffic, which requires NHRP redirect and shortcut, not a specific IPsec mode.

  • ✓

    NHRP redirect

    Why this is correct

    NHRP redirect allows the hub to inform the originating spoke that a shorter path exists to the destination spoke, enabling direct spoke-to-spoke tunnels. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's public address and builds a direct tunnel. This is a key feature of DMVPN Phase 3.

  • ✗

    NHRP shortcut

    Why it's wrong here

    NHRP shortcut is a related but distinct feature that is enabled on spoke routers to allow them to use the redirect information and create a shortcut path. However, the hub must first be configured with NHRP redirect to generate the redirect messages. Without redirect on the hub, shortcut alone on spokes does not enable direct spoke-to-spoke communication.

  • ✗

    Multipoint GRE with dynamic routing

    Why it's wrong here

    Multipoint GRE (mGRE) is the underlying tunnel interface type used in DMVPN, and dynamic routing protocols enable spoke reachability. However, these are foundational components of DMVPN Phase 2 as well. They do not inherently provide the redirect mechanism needed for Phase 3 direct spoke-to-spoke tunnels when spokes are behind NAT.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Go deeper

Related to this question

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.