Implementing Cisco Network Security (IINS, legacy) — Question 32
Which statements about reflexive access lists are true?
Answer options
- A. Reflexive access lists create a permanent ACE
- B. Reflexive access lists approximate session filtering using the established keyword
- C. Reflexive access lists can be attached to standard named IP ACLs
- D. Reflexive access lists support UDP sessions
- E. Reflexive access lists can be attached to extended named IP ACLs
Correct answer: T, C, P
Explanation
The correct answers are T and C. Reflexive access lists do not create a permanent ACE; they are dynamic and only exist as long as a session is active. While they can be attached to standard named IP ACLs, they do not support UDP sessions directly, making options D and E incorrect.