Which VPN Solution Connects 100+ Branches with Encryption?

Configure and verify DMVPN (single hub)
Answer Correct answer: C — DMVPN provides scalable mGRE/NHRP branch-to-branch tunnels with IPsec encryption for over 100 sites.

A company is looking to implement VPN between their Head Quarter and over 100+ Branch Offices. They are looking for a solution that: 1. Reduces deployment complexity 2. Simplifies branch communications 3. Offers branch to branch connectivity. 4. Is cost effective 5. Offers strong encryption Select the best option from the below options that you would recommend to implement.

  1. MPLS
  2. IPSEC
  3. DMVPN Correct Answer
  4. GRE

Community Votes

C
83%
B
17%

83% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of scalable VPN design; the trap is assuming DMVPN lacks encryption because it uses GRE, or choosing IPsec alone without considering hub-and-spoke scale.

For 100+ branch offices needing simplified, cost-effective encrypted branch-to-branch VPN, DMVPN is the recommended Cisco solution. This page explains why DMVPN (C) meets all five requirements while MPLS, IPsec, and GRE each fail at least one criterion.

The most common wrong answer is IPsec (B), because it provides encryption but lacks native dynamic branch-to-branch tunnelling and requires more point-to-point configuration at scale.

Community Discussion (3 comments)

Pietjeplukgeluk 👍 8 Selected: C
Of course C == correct, but ideally this was a "select two" as IPSEC need also to be used in addition to DMVPN
AlbertoStu 👍 1 Selected: C
@CiscoTerminator Yes, DMVPN can be encrypted, just add tunnel protection. GRE is one of several technologies that make up DMVPN.
CiscoTerminator 👍 2 Selected: B
But DMVPN has no encryption and is based off GRE, how is it the best here?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

DMVPN (C) is the only option that natively combines multipoint GRE (mGRE), Next Hop Resolution Protocol (NHRP), and IPsec protection to meet all five stated goals. It reduces deployment complexity because new branches only need a tunnel to the hub, and the hub configuration stays largely static as sites are added. It simplifies branch communications and provides branch-to-branch connectivity by allowing spokes to build direct dynamic tunnels through NHRP once they register with the hub. Running over ordinary internet links makes it cost-effective, and adding an IPsec profile with tunnel protection supplies strong encryption, so DMVPN satisfies the encryption requirement without sacrificing scalability.

Why the Other Options Are Wrong

MPLS (A) can provide any-to-any connectivity and traffic separation, but it is typically a carrier-managed service and is less cost-effective for 100+ branches, and it does not itself provide strong encryption. IPsec (B) delivers encryption but is usually deployed as point-to-point or full-mesh tunnels, which becomes complex to manage at this scale and does not inherently simplify dynamic branch-to-branch reachability. GRE (D) can carry multicast and routing protocols, but plain GRE has no encryption, so it fails the strong encryption requirement unless it is combined with IPsec — which essentially describes part of DMVPN but not the full scalable solution. Therefore only DMVPN meets the complete requirement set.

Community Comment Notes

As Pietjeplukgeluk noted, DMVPN is the correct answer, though the question could arguably have been a "select two" because IPsec is still used alongside DMVPN for encryption. CiscoTerminator questioned how DMVPN can be best if it uses GRE and has no encryption, but AlbertoStu correctly pointed out that DMVPN can be encrypted by adding tunnel protection. The vote tally also shows strong community agreement on C, with 83 votes versus 17 for B, and the comments clarify the common misconception that DMVPN and encryption are mutually exclusive. The discussion reinforces that DMVPN's strength is the scalable overlay, while IPsec supplies the crypto.

Official Reference

Exam Strategy

When a scenario lists scalability, simplification, cost, and encryption together, map each requirement to known Cisco architectures: DMVPN delivers mGRE/NHRP dynamic tunnels and can use IPsec encryption, whereas MPLS is costly and IPsec/GRE alone do not scale as easily. Remember DMVPN uses GRE as transport but strong encryption is achieved with tunnel protection.

Frequently Asked Questions

Why isn't IPsec alone the best answer for 100+ branches?

IPsec can encrypt traffic but lacks DMVPN's dynamic mGRE/NHRP mesh, so hub-and-spoke or full-mesh IPsec requires far more configuration and does not simplify branch-to-branch connectivity as cleanly.

Does DMVPN provide strong encryption without extra configuration?

DMVPN itself relies on GRE/mGRE for tunneling; you enable strong encryption by applying IPsec tunnel protection (for example, tunnel protection ipsec profile) to the DMVPN tunnel interfaces.

More 300-410 FAQ →

Related Analysis

Practice All 300-410 Questions

Access 159 questions with complete answers and detailed explanations.

View Full 300-410 Practice Test →

← Back to 300-410 Study Guide