nerdexam
Cisco

210-260 · Question #18

Which statements about reflexive access lists are true?

The correct answer is D. Reflexive access lists support UDP sessions E. Reflexive access lists can be attached to extended named IP ACLs F. Reflexive access lists support TCP sessions. Reflexive access lists allow IP packets to be filtered based on upper-layer session information. You can use reflexive access lists to permit IP traffic for sessions originating from within your network but to deny IP traffic for sessions originating from outside your network…

Secure Routing and Switching

Question

Which statements about reflexive access lists are true?

Options

  • AReflexive access lists create a permanent ACE
  • BReflexive access lists approximate session filtering using the established keyword
  • CReflexive access lists can be attached to standard named IP ACLs
  • DReflexive access lists support UDP sessions
  • EReflexive access lists can be attached to extended named IP ACLs
  • FReflexive access lists support TCP sessions

How the community answered

(61 responses)
  • A
    2% (1)
  • B
    10% (6)
  • C
    5% (3)
  • D
    84% (51)

Explanation

Reflexive access lists allow IP packets to be filtered based on upper-layer session information. You can use reflexive access lists to permit IP traffic for sessions originating from within your network but to deny IP traffic for sessions originating from outside your network. This is accomplished by reflexive filtering, a kind of session filtering. Reflexive access lists can be defined with extended named IP access lists only. You cannot define reflexive access lists with numbered or standard named IP access lists or with other protocol access lists.

Topics

#reflexive ACL#session filtering#extended ACL#UDP TCP sessions

Community Discussion

No community discussion yet for this question.

Full 210-260 Practice