Courseiva
Architecture →easyMultiple Choice

350-401 Architecture Practice Question

A network engineer is deploying a new branch office that requires a WAN connection with built-in encryption and dynamic multipoint VPN capabilities. The engineer wants to use a Cisco technology that supports spoke-to-spoke communication without requiring traffic to traverse the hub. Which technology should be implemented?

⚠ Common exam trap

Many candidates confuse IPsec VPN with DMVPN, assuming that any encrypted VPN automatically supports dynamic spoke-to-spoke tunnels, when DMVPN specifically adds the multipoint dynamic capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DMVPN

DMVPN is designed to provide dynamic multipoint VPN connectivity, allowing spokes to establish direct tunnels with each other as needed. It combines mGRE, NHRP, and IPsec to deliver scalable, encrypted, and dynamic branch connectivity. This eliminates the need to route spoke-to-spoke traffic through the hub, improving latency and reducing hub bandwidth consumption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DMVPN

    Why this is correct

    DMVPN (Dynamic Multipoint VPN) allows spoke-to-spoke tunnels to be established on demand, enabling direct communication between branch sites without routing traffic through the hub. It uses mGRE (multipoint GRE) and NHRP (Next Hop Resolution Protocol) to dynamically discover and build tunnels. This matches the requirement for dynamic multipoint VPN with encryption, typically provided by IPsec.

  • ✗

    IPsec VPN

    Why it's wrong here

    IPsec VPN provides encryption and integrity but is typically used for point-to-point or hub-and-spoke tunnels. Without additional technologies like DMVPN, IPsec does not dynamically establish spoke-to-spoke tunnels; traffic must traverse the hub. Therefore, IPsec alone does not satisfy the requirement for dynamic multipoint communication between branch sites.

  • ✗

    GRE tunnel

    Why it's wrong here

    A GRE tunnel is a point-to-point encapsulation that can carry multicast and non-IP protocols, but it does not provide encryption by itself and does not support dynamic multipoint tunnel establishment. To achieve spoke-to-spoke communication, you would need to configure multiple static tunnels, which is not dynamic and does not scale. Thus, GRE alone does not meet the requirements.

  • ✗

    MPLS L3VPN

    Why it's wrong here

    MPLS L3VPN is a service provider technology that provides any-to-any connectivity and traffic isolation using VRFs. While it supports direct spoke-to-spoke communication, it does not inherently provide encryption, and it requires the service provider to enable MPLS. It also does not use dynamic multipoint tunnels built by the customer edge devices, so it does not meet the requirement for built-in encryption and dynamic multipoint VPN.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.