Which three statements correctly describe ACL processing of packets? (Choose three.)
- An implicit deny any rejects any packet that does not match any ACE.
- A packet can either be rejected or forwarded as directed by the ACE that is matched.
- A packet that has been denied by one ACE can be permitted by a subsequent ACE.
- A packet that does not match the conditions of any ACE will be forwarded by default.
- Each statement is checked only until a match is detected or until the end of the ACE list.
- Each packet is compared to the conditions of every ACE in the ACL before a forwarding decision is made.
Explanation: Access Control Lists (ACLs) follow a strict logic where entries are processed from the top to the bottom in order. When a packet matches an Access Control Entry (ACE), it is immediately executed as either a permit or a deny, and the router stops checking further statements. If a packet reaches the end of the list without matching any specific ACE, it is automatically dropped by an invisible implicit deny any statement.
Related exam: Checkpoint Exam: MPLS and VPN Technologies
