問題文
An administrator deploys into a subnet that already carries a non-default access control list. How do the two filtering layers combine, and what does that mean for traffic?
選択肢
- The subnet list and the instance group are evaluated in strict isolation, so traffic missing the permit at one of them meets the final refusal of that level even when the other allows the flow.
- The subnet list and the instance group are evaluated in joint isolation, so traffic missing the permit at one of them meets the advisory refusal of that level even when the other allows the flow.
- The subnet list and the instance group are evaluated in strict isolation, so traffic missing the permit at one of them meets the advisory refusal of that level even when the other allows the flow.
- The subnet list and the instance group are evaluated in joint isolation, so traffic missing the permit at one of them meets the final refusal of that level even when the other allows the flow.