300-410 VPN Technologies Practice Question
A network engineer is configuring DMVPN Phase 3 on a hub router. The hub has a public IP address and is reachable. Spokes are behind NAT devices and have dynamic public IP addresses. Which technology allows spokes to communicate directly without routing traffic through the hub?
⚠ Common exam trap
Many candidates confuse NHRP redirect with NHRP shortcut; redirect is the trigger, but shortcut is the mechanism that actually creates the direct tunnel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NHRP shortcut
In DMVPN Phase 3, NHRP shortcut enables direct spoke-to-spoke tunnels. When a spoke sends traffic to another spoke via the hub, the hub sends an NHRP redirect, and the spoke then uses NHRP shortcut to establish a direct tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NHRP redirect
Why it's wrong here
NHRP redirect is used in DMVPN Phase 3 to inform the spoke that a shorter path exists, but it requires NHRP shortcut to actually establish the direct tunnel. Without shortcut, the redirect alone does not enable direct spoke-to-spoke communication.
- ✗
NHRP resolution
Why it's wrong here
NHRP resolution is used to resolve a tunnel IP address to an NBMA address, but in DMVPN Phase 3, the shortcut mechanism is what triggers the spoke to initiate a direct tunnel. Resolution alone would still send traffic through the hub unless shortcut is configured.
- ✓
NHRP shortcut
Why this is correct
NHRP shortcut allows a spoke to dynamically create a direct tunnel to another spoke when it receives an NHRP redirect from the hub. This enables direct spoke-to-spoke communication, bypassing the hub, which is a key feature of DMVPN Phase 3.
- ✗
NHRP registration
Why it's wrong here
NHRP registration is the process by which spokes register their NBMA addresses with the hub. It is fundamental for DMVPN but does not itself enable direct spoke-to-spoke tunnels. It only allows the hub to know the mapping of tunnel IP to public IP.
Visual reference
Go deeper
Related to this question
Learn chapter
DMVPN and FlexVPN Technologies
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.