Courseiva
VPN Technologies →hardMultiple Select

300-410 VPN Technologies Practice Question

A network engineer is deploying DMVPN Phase 3 with IPsec protection on a Cisco IOS router acting as a hub. The engineer wants to ensure that spoke-to-spoke traffic is encrypted and that spoke routers can dynamically establish direct tunnels. Which two statements are true about this deployment? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse DMVPN Phase 3 requirements with Phase 2 or assuming that static crypto maps are needed; Phase 3 uses NHRP redirect and shortcut for dynamic spoke-to-spoke tunnels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The hub must be configured with 'ip nhrp redirect' to signal spokes about a better path.

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path, and spokes use 'ip nhrp shortcut' to install shortcut routes for direct spoke-to-spoke tunnels. These two features work together to enable dynamic spoke-to-spoke communication. IPsec protection is typically implemented using IPsec profiles, not static crypto maps, and multicast mapping is separate from this functionality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The hub must be configured with 'ip nhrp redirect' to signal spokes about a better path.

    Why this is correct

    In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform the spoke that a more optimal path exists to the destination. This allows the spoke to initiate a direct tunnel to the other spoke. Without redirect, spoke-to-spoke traffic would continue to go through the hub.

  • ✗

    The hub must be configured with 'ip nhrp map multicast dynamic' to support dynamic multicast mapping.

    Why it's wrong here

    'ip nhrp map multicast dynamic' is typically configured on the hub to allow it to replicate multicast and broadcast packets to all spokes. However, this is not specific to enabling spoke-to-spoke traffic or encryption; it is used for multicast support. The question asks about ensuring spoke-to-spoke traffic is encrypted and direct tunnels are established, so this statement is not directly relevant.

  • ✗

    Spoke routers must have a static crypto map entry for each possible destination spoke.

    Why it's wrong here

    DMVPN is designed to avoid the need for static crypto map entries for each spoke. With DMVPN, a single IPsec profile or crypto map entry can handle multiple dynamic tunnels. Static entries per spoke would defeat the scalability of DMVPN.

  • ✗

    The hub must use a crypto map with 'ipsec-isakmp' to encrypt all GRE traffic.

    Why it's wrong here

    While IPsec protection is used, in DMVPN the recommended approach is to use IPsec profiles rather than crypto maps. Crypto maps can be used, but they are not the only method and may not support dynamic spoke-to-spoke tunnels as efficiently. The statement that the hub must use a crypto map is not true; IPsec profiles are preferred.

  • ✓

    Spoke routers must be configured with 'ip nhrp shortcut' to install shortcut routes for direct spoke-to-spoke tunnels.

    Why this is correct

    On spokes in DMVPN Phase 3, 'ip nhrp shortcut' enables the router to intercept NHRP redirect messages and install a shortcut route in the routing table, allowing direct spoke-to-spoke communication. This is required to bypass the hub for spoke-to-spoke traffic.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.