Courseiva
hardMultiple Select

350-401 Practice Question: Which two statements about DMVPN phase 2 are…

Which two statements about DMVPN phase 2 are true? (Choose two.)

⚠ Common exam trap

The trap is confusing DMVPN phases: phase 1 only hub-to-spoke, phase 2 adds spoke-to-spoke with NHRP redirect, phase 3 adds NHRP shortcut and scalability improvements. Candidates must remember that phase 2 uses mGRE on spokes and NHRP redirect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.

Option A is correct because DMVPN phase 2 enables spoke-to-spoke direct tunnels: spokes learn each other's NBMA addresses via NHRP and can build dynamic mGRE tunnels so data traffic bypasses the hub. Option C is correct because in phase 2 the hub uses NHRP redirect messages to tell a spoke that a better path to the destination exists, prompting the spoke to send an NHRP resolution request and build a direct tunnel. Option B is wrong because phase 2 requires mGRE on both the hub and the spokes, not point-to-point GRE on spokes. Option D is wrong because DMVPN phase 2 can run with or without IPsec; encryption is optional. Option E is wrong because spokes use dynamic crypto maps or IPsec profiles, not static crypto maps, to support spoke-to-spoke IPsec tunnels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.

    Why this is correct

    Phase 2 permits spoke-to-spoke tunnels built directly, bypassing the hub for data forwarding. Spokes learn each other's tunnel endpoints via NHRP resolution through the hub, then establish direct GRE tunnels, satisfying the requirement that inter-spoke traffic avoids hub transit.

  • ✗

    DMVPN phase 2 requires mGRE on the hub only; spokes use point-to-point GRE tunnels.

    Why it's wrong here

    DMVPN phase 2 uses mGRE on both hub and spokes, with a single mGRE tunnel interface per router; NHRP resolves spoke NBMA addresses so spoke-to-spoke traffic bypasses the hub. Point-to-point GRE on spokes describes phase 1. Phase 2's defining feature is direct spoke-to-spoke tunnels via NHRP shortcut switching.

  • ✓

    NHRP redirect messages are used in phase 2 to inform spokes of better paths to remote destinations.

    Why this is correct

    In DMVPN phase 2, NHRP redirect messages tell a spoke that a more optimal path exists to a remote destination, prompting it to query for the remote NBMA address and build a direct spoke-to-spoke tunnel.

  • ✗

    DMVPN phase 2 supports only IPsec protection and cannot operate without encryption.

    Why it's wrong here

    DMVPN phase 2 runs mGRE with NHRP and can carry plain GRE, mGRE or IPsec-protected tunnels; encryption is optional and configured separately via a protection profile. The statement would hold only if the design mandated IPsec everywhere. Phase 2's defining feature is spoke-to-spoke direct tunnels with NHRP shortcut switching.

  • ✗

    In DMVPN phase 2, spoke routers must be configured with static crypto maps for IPsec.

    Why it's wrong here

    DMVPN phase 2 uses multipoint GRE with NHRP, so spokes register their tunnel addresses dynamically and no static crypto maps are needed; IPsec profiles reference the mGRE tunnel. Static crypto maps suit point-to-point or phase 1 hub-and-spoke designs where peer addresses are fixed, which is why this distractor tempts.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.