Courseiva
VPN Technologies →mediumMultiple Select

300-410 VPN Technologies Practice Question

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP, and wants spokes to reach other spokes directly without routing through the hub for every packet. The engineer must configure the hub so that it advertises a default route to the spokes while still allowing spoke-to-spoke shortcut tunnels. (Choose two.)

⚠ Common exam trap

The trap here is thinking that distributing a default route or adjusting split horizon enables shortcuts, when Phase 3 specifically depends on NHRP redirect on the hub and NHRP shortcut on the spokes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NHRP redirect on the hub so it can inform spokes of a better path to the destination.

DMVPN Phase 3 achieves spoke-to-spoke shortcuts through two cooperating NHRP features. The hub enables NHRP redirect so it can tell a spoke that a better path exists, and each spoke enables NHRP shortcut so it can resolve the destination and install a temporary direct route. Together these allow direct tunnels while the hub still advertises a summarizable default route to all spokes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable split horizon on the hub's mGRE interface to allow spoke routes to be re-advertised.

    Why it's wrong here

    Split horizon affects whether routes learned on an interface are advertised back out the same interface. Disabling it can help in some hub-and-spoke designs, but it is not the mechanism that creates Phase 3 shortcuts. Phase 3 relies on NHRP redirect and shortcut, not on routing advertisement behavior, so this change would not enable direct spoke-to-spoke tunnels by itself.

  • ✓

    Enable NHRP redirect on the hub so it can inform spokes of a better path to the destination.

    Why this is correct

    NHRP redirect is a Phase 3 feature that lets the hub inspect traffic arriving on its mGRE interface and send a redirect message to the originating spoke when a shorter path exists. The spoke then resolves the destination NBMA address and builds a direct tunnel to the target spoke. Without redirect, spokes keep sending all inter-spoke traffic through the hub, so this is required for shortcut behavior.

  • ✗

    Configure the hub with a default route pointing to the provider and redistribute it into the routing protocol with a metric that spokes accept.

    Why it's wrong here

    Redistributing a default route from the hub does give spokes a path, but this alone does not enable spoke-to-spoke shortcuts in Phase 3. Phase 3 shortcut behavior depends on NHRP resolution of the destination next hop and on the spokes retaining specific host routes. Distributing a default route is a reachability step, not the mechanism that permits direct spoke tunnels, so it is only part of the picture.

  • ✗

    Configure the spokes with a static route for every remote spoke subnet pointing at the hub.

    Why it's wrong here

    Static routes to every remote spoke subnet through the hub would actually prevent shortcut behavior because the spokes would always forward inter-spoke traffic to the hub. Phase 3 is designed to avoid this full-mesh routing requirement by using NHRP resolution on demand. This approach contradicts the goal of direct spoke-to-spoke communication and adds maintenance overhead.

  • ✓

    Configure NHRP shortcut on each spoke to allow it to install and use a direct route learned from the redirect.

    Why this is correct

    NHRP shortcut is the spoke-side counterpart to redirect. When a spoke receives a redirect message, shortcut processing lets it send an NHRP resolution for the destination and install a temporary route pointing at the directly reachable peer. This enables the spoke-to-spoke tunnel without a permanent route through the hub, which is the defining behavior of DMVPN Phase 3.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.