mediumMultiple Choice
350-401 Practice Question: Consider the following configuration for a…
Consider the following configuration for a FlexVPN spoke router:
interface Tunnel0 ip address 10.0.0.2 255.255.255.0
tunnel source GigabitEthernet0/0/0 tunnel mode gre ip tunnel protection ipsec profile FLEXPROF
ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 ip nhrp map 10.0.0.1 192.168.1.1
What is the purpose of the 'ip nhrp map 10.0.0.1 192.168.1.1' command?
⚠ Common exam trap
Cisco often tests the distinction between NHRP static mapping (for the hub's address) and NHRP registration (where the spoke sends its own mapping to the hub), leading candidates to confuse the purpose of 'ip nhrp map' with registration or multicast functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides a static mapping from the hub's tunnel IP (10.0.0.1) to the hub's physical IP (192.168.1.1) so the spoke can reach the hub.
The 'ip nhrp map 10.0.0.1 192.168.1.1' command statically maps the hub's tunnel IP address (10.0.0.1) to its physical (NBMA) IP address (192.168.1.1). This is required on the spoke because NHRP is used to resolve the hub's tunnel IP to its underlying transport address so the spoke can build the GRE/IPsec tunnel. Without this static mapping, the spoke would not know where to send packets destined for the hub's tunnel interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It maps the spoke's tunnel IP to its own physical interface IP for local routing.
Why it's wrong here
The NHRP map command always maps a remote tunnel IP (the hub's) to a remote physical NBMA address. It is not used for local routing decisions; local routes come from interface configuration. The spoke's own tunnel IP and physical IP are already assigned to its interfaces, and NHRP does not create a local mapping.
- ✓
It provides a static mapping from the hub's tunnel IP (10.0.0.1) to the hub's physical IP (192.168.1.1) so the spoke can reach the hub.
Why this is correct
This static NHRP mapping on the spoke tells the spoke that the hub's tunnel interface 10.0.0.1 is reachable through the hub's physical NBMA address 192.168.1.1. Since the spoke needs to send initial NHRP registration and traffic to the hub before it learns dynamic mappings, this static map is essential. It is configured on the spoke, not the hub.
- ✗
It enables multicast mapping for dynamic spoke discovery.
Why it's wrong here
The command 'ip nhrp map multicast' with an address or 'ip nhrp map multicast dynamic' is used to forward multicast/broadcast traffic to all spokes via the hub. A unicast mapping like this only maps a single tunnel IP to a single physical IP and does not enable multicast or dynamic spoke discovery. Dynamic spoke discovery happens through NHRP registrations and resolution, not through a static map command.
- ✗
It configures the spoke to register with the hub using the specified physical address.
Why it's wrong here
The spoke does not use the map command to register itself; it uses it to know how to reach the hub's tunnel IP. NHRP registration is a separate process where the spoke sends a registration request to the hub's tunnel IP, and the hub then builds a mapping of the spoke's tunnel IP to its physical IP. The command specifies the hub's addresses, not the spoke's, so it cannot configure the spoke to register using a physical address.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
IPsec Tunnel
An IPsec tunnel is a secure, encrypted connection between two network devices that protects data as it travels across the internet or another untrusted network.
Key term
GRE
GRE (Generic Routing Encapsulation) is a tunneling protocol that encapsulates packets inside other packets to transport them across incompatible networks.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.