300-410 VPN Technologies Practice Question
A network engineer is deploying DMVPN Phase 3 with IPsec protection on a Cisco IOS router acting as a hub. The engineer wants to ensure that spoke-to-spoke traffic is encrypted and that spoke routers can dynamically establish direct tunnels. Which two statements are true about this deployment? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse DMVPN Phase 3 requirements with Phase 2 or assuming that static crypto maps are needed; Phase 3 uses NHRP redirect and shortcut for dynamic spoke-to-spoke tunnels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hub must be configured with 'ip nhrp redirect' to signal spokes about a better path.
In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path, and spokes use 'ip nhrp shortcut' to install shortcut routes for direct spoke-to-spoke tunnels. These two features work together to enable dynamic spoke-to-spoke communication. IPsec protection is typically implemented using IPsec profiles, not static crypto maps, and multicast mapping is separate from this functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The hub must be configured with 'ip nhrp redirect' to signal spokes about a better path.
Why this is correct
In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform the spoke that a more optimal path exists to the destination. This allows the spoke to initiate a direct tunnel to the other spoke. Without redirect, spoke-to-spoke traffic would continue to go through the hub.
- ✗
The hub must be configured with 'ip nhrp map multicast dynamic' to support dynamic multicast mapping.
Why it's wrong here
'ip nhrp map multicast dynamic' is typically configured on the hub to allow it to replicate multicast and broadcast packets to all spokes. However, this is not specific to enabling spoke-to-spoke traffic or encryption; it is used for multicast support. The question asks about ensuring spoke-to-spoke traffic is encrypted and direct tunnels are established, so this statement is not directly relevant.
- ✗
Spoke routers must have a static crypto map entry for each possible destination spoke.
Why it's wrong here
DMVPN is designed to avoid the need for static crypto map entries for each spoke. With DMVPN, a single IPsec profile or crypto map entry can handle multiple dynamic tunnels. Static entries per spoke would defeat the scalability of DMVPN.
- ✗
The hub must use a crypto map with 'ipsec-isakmp' to encrypt all GRE traffic.
Why it's wrong here
While IPsec protection is used, in DMVPN the recommended approach is to use IPsec profiles rather than crypto maps. Crypto maps can be used, but they are not the only method and may not support dynamic spoke-to-spoke tunnels as efficiently. The statement that the hub must use a crypto map is not true; IPsec profiles are preferred.
- ✓
Spoke routers must be configured with 'ip nhrp shortcut' to install shortcut routes for direct spoke-to-spoke tunnels.
Why this is correct
On spokes in DMVPN Phase 3, 'ip nhrp shortcut' enables the router to intercept NHRP redirect messages and install a shortcut route in the routing table, allowing direct spoke-to-spoke communication. This is required to bypass the hub for spoke-to-spoke traffic.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Control Plane Policing and Protection
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.