Courseiva
mediumMultiple Select

300-410 Practice Question: Which TWO commands can be used to verify the NHRP…

Which TWO commands can be used to verify the NHRP shortcut route creation in a DMVPN Phase 3 network? (Choose TWO.)

⚠ Common exam trap

300-410 often tests the confusion between DMVPN peer-state verification commands (show dmvpn) and NHRP shortcut route verification commands (show ip nhrp, show ip route), tricking candidates into picking show dmvpn.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

show ip nhrp

Option A, `show ip nhrp`, is correct because it displays the NHRP cache including dynamic shortcut entries created when a spoke resolves a destination spoke's NBMA address, showing the type as 'dynamic' and the destination network — direct evidence that the NHRP shortcut was installed. Option B, `show ip route`, is correct because a successfully created NHRP shortcut appears in the routing table as a route pointing out the tunnel interface with the next hop being the destination spoke's tunnel IP, confirming the shortcut route is actually used for forwarding. Option C, `show dmvpn`, only shows NHRP peer and tunnel state (up/down, peer type) and does not display the shortcut route itself. Option D, `show crypto ipsec sa`, verifies IPsec security associations for the data plane but says nothing about NHRP shortcut route creation. Option E, `show ip eigrp topology`, shows EIGRP topology entries and would not specifically confirm an NHRP shortcut route, which is installed via NHRP rather than as an EIGRP route.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    show ip nhrp

    Why this is correct

    The show ip nhrp command displays NHRP cache entries, including type and flag fields. Shortcut entries appear as dynamic mappings with the 'S' flag set, confirming that a spoke has resolved a peer's NBMA address and installed a direct tunnel path.

  • ✓

    show ip route

    Why this is correct

    show ip route reveals shortcut routes installed by NHRP, typically marked with the 'H' or next-hop as the tunnel peer address rather than the hub. Their presence confirms Phase 3 shortcut forwarding is operational for that destination prefix.

  • ✗

    show dmvpn

    Why it's wrong here

    'show dmvpn' displays tunnel and NHRP peer state, but not the routing table entries that shortcut switching installs. Verifying shortcut route creation requires examining the routing table, for example 'show ip route nhrp', which reveals the installed NHRP-derived routes.

  • ✗

    show crypto ipsec sa

    Why it's wrong here

    'show crypto ipsec sa' lists IPsec security associations and their traffic counters, revealing nothing about NHRP resolution or routing. Shortcut route creation is verified through NHRP and routing commands such as 'show ip nhrp' or 'show ip route nhrp', not IPsec state.

  • ✗

    show ip eigrp topology

    Why it's wrong here

    EIGRP topology shows learned routes and their successors, but NHRP shortcut entries appear only after traffic triggers resolution, so it cannot confirm shortcut creation. It is tempting because EIGRP over the tunnel is the routing protocol whose adjacencies DMVPN Phase 3 relies on, yet the shortcut itself is an NHRP forwarding-plane entry, not an EIGRP route.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.