Courseiva
Infrastructure →mediumMultiple Select

350-401 Infrastructure Practice Question

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic over an IP network that does not support multicast. The engineer must ensure the tunnel is operational and multicast is forwarded correctly. Which two statements are true about GRE tunnel configuration and operation? (Choose two.)

⚠ Common exam trap

The trap here is assuming GRE provides encryption or that multipoint mode is needed for multicast, when point-to-point GRE can carry multicast if multicast routing is enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multicast routing must be enabled on the tunnel interface and the underlying physical interface.

A GRE tunnel requires that the tunnel source and destination be reachable via the underlay. Additionally, to carry multicast, multicast routing must be enabled on both the tunnel and the physical interface. These two conditions ensure the tunnel is up and multicast is forwarded. The other options describe incorrect or unnecessary configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The tunnel interface must be configured with the 'tunnel mode gre multipoint' command to support multicast.

    Why it's wrong here

    The 'tunnel mode gre multipoint' command is used for mGRE (multipoint GRE) configurations, often with NHRP, to support multiple destinations. For a simple point-to-point GRE tunnel, the default 'tunnel mode gre ip' is sufficient. Multicast can be transported over point-to-point GRE without multipoint mode. This option is incorrect for the scenario.

  • ✗

    The tunnel interface must be configured with an IP address from the same subnet as the physical interface.

    Why it's wrong here

    The tunnel interface is a logical interface and typically uses a separate IP subnet from the physical underlay. This allows routing over the tunnel without conflicts. Using the same subnet as the physical interface would cause overlapping addresses and routing issues. The tunnel source/destination are physical addresses, but the tunnel IP is independent.

  • ✗

    GRE tunnels automatically encrypt all traffic, so no additional security configuration is required.

    Why it's wrong here

    GRE does not provide encryption; it only encapsulates packets. To secure GRE traffic, you must use IPsec in conjunction with GRE. Without IPsec, the traffic is sent in clear text. This option is a common misconception. The scenario does not mention encryption, but the statement is false in general.

  • ✓

    Multicast routing must be enabled on the tunnel interface and the underlying physical interface.

    Why this is correct

    To forward multicast traffic over a GRE tunnel, multicast routing must be enabled on both the tunnel interface and the physical interface that carries the tunnel. The tunnel interface must be included in the multicast routing configuration (e.g., 'ip pim sparse-mode'). Otherwise, multicast packets will not be forwarded into or out of the tunnel.

  • ✓

    The tunnel source and destination must be reachable via the underlay routing table.

    Why this is correct

    For a GRE tunnel to come up, the tunnel source and destination addresses must be reachable. The router uses the underlay routing table to route the GRE-encapsulated packets. If the destination is not reachable, the tunnel interface will remain down. This is a fundamental requirement for any point-to-point tunnel.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.