350-401 Architecture Practice Question
A network engineer is deploying a new branch office that requires a WAN connection with built-in encryption and dynamic multipoint VPN capabilities. The engineer wants to use a Cisco technology that supports spoke-to-spoke communication without requiring traffic to traverse the hub. Which technology should be implemented?
⚠ Common exam trap
Many candidates confuse IPsec VPN with DMVPN, assuming that any encrypted VPN automatically supports dynamic spoke-to-spoke tunnels, when DMVPN specifically adds the multipoint dynamic capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DMVPN
DMVPN is designed to provide dynamic multipoint VPN connectivity, allowing spokes to establish direct tunnels with each other as needed. It combines mGRE, NHRP, and IPsec to deliver scalable, encrypted, and dynamic branch connectivity. This eliminates the need to route spoke-to-spoke traffic through the hub, improving latency and reducing hub bandwidth consumption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DMVPN
Why this is correct
DMVPN (Dynamic Multipoint VPN) allows spoke-to-spoke tunnels to be established on demand, enabling direct communication between branch sites without routing traffic through the hub. It uses mGRE (multipoint GRE) and NHRP (Next Hop Resolution Protocol) to dynamically discover and build tunnels. This matches the requirement for dynamic multipoint VPN with encryption, typically provided by IPsec.
- ✗
IPsec VPN
Why it's wrong here
IPsec VPN provides encryption and integrity but is typically used for point-to-point or hub-and-spoke tunnels. Without additional technologies like DMVPN, IPsec does not dynamically establish spoke-to-spoke tunnels; traffic must traverse the hub. Therefore, IPsec alone does not satisfy the requirement for dynamic multipoint communication between branch sites.
- ✗
GRE tunnel
Why it's wrong here
A GRE tunnel is a point-to-point encapsulation that can carry multicast and non-IP protocols, but it does not provide encryption by itself and does not support dynamic multipoint tunnel establishment. To achieve spoke-to-spoke communication, you would need to configure multiple static tunnels, which is not dynamic and does not scale. Thus, GRE alone does not meet the requirements.
- ✗
MPLS L3VPN
Why it's wrong here
MPLS L3VPN is a service provider technology that provides any-to-any connectivity and traffic isolation using VRFs. While it supports direct spoke-to-spoke communication, it does not inherently provide encryption, and it requires the service provider to enable MPLS. It also does not use dynamic multipoint tunnels built by the customer edge devices, so it does not meet the requirement for built-in encryption and dynamic multipoint VPN.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.