hardMultiple ChoiceObjective-mapped
300-410 Practice Question: A DMVPN network uses PBR to route traffic from…
A DMVPN network uses PBR to route traffic from spoke routers to specific hubs based on source IP. After a hub failure, traffic from spoke 1 (source 192.168.1.0/24) is being sent to a backup hub, but the backup hub drops the traffic. Router R1 (spoke) shows: 'show ip policy' shows PBR applied, 'debug ip policy' shows traffic being forwarded to next-hop 10.1.1.2 (backup hub). Router R2 (backup hub) shows: 'show ip route 192.168.1.0' returns no route. What is the root cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The backup hub does not have a route to the source subnet, causing it to drop traffic. Add a static route or enable routing protocol on the backup hub for the spoke subnet.
PBR on the spoke forwards traffic to the backup hub, but the backup hub does not have a route back to the source subnet (192.168.1.0/24). This causes asymmetric routing, where the backup hub drops the traffic because it cannot find a return route. The solution is to ensure the backup hub has a route to the spoke subnet, either via dynamic routing or a static route.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The backup hub does not have a route to the source subnet, causing it to drop traffic. Add a static route or enable routing protocol on the backup hub for the spoke subnet.
Why this is correct
PBR forwards traffic to the backup hub, but without a return route, the hub cannot respond. This is a common issue in DMVPN with PBR when hubs are not fully meshed.
- ✗
The PBR route-map on the spoke is missing a 'set ip next-hop verify-availability' command, causing it to use the backup hub even when it is not fully reachable.
Why it's wrong here
The backup hub is reachable (traffic is being forwarded), but it lacks a return route. The 'verify-availability' command checks next-hop reachability, not routing on the remote side.
- ✗
The spoke's routing table has a better route to the destination via the backup hub, overriding PBR.
Why it's wrong here
PBR overrides the routing table for matched traffic. The debug output confirms PBR is forwarding traffic to the backup hub, so the routing table is not the issue.
- ✗
The backup hub has a route to the source subnet but with a higher administrative distance, causing it to be ignored.
Why it's wrong here
If the backup hub had a route, it would use it. The 'show ip route' output shows no route at all, indicating the route is missing entirely.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.