Answer B is the technically correct selection. A stateful firewall tracks active connection state and uses that state to permit or deny packets. Return traffic that belongs to an established connection can be allowed while unsolicited traffic can be blocked. This aligns with Cisco CCNA 200-301 v1.1 because the exam blueprint requires engineers to recognize operational behaviour from configuration symptoms and topology requirements. Access points and WLCs handle wireless connectivity, and routers forward based on routing and policy rather than maintaining firewall session state by default. Treat the distractors carefully: most are real Cisco terms, but they solve a different problem or operate at a different layer. The selected answer is the one that would be used by an engineer on the device or in the design to produce the outcome stated in the question.