問題文
The policy that Oracle Linux 8 uses by default applies its controls to a limited set of processes. In what state does the documentation say the remaining processes run, and why does it say a switch to the layered policy brings more denials?
選択肢
- They run outside any restricted domain, where the older discretionary rules alone apply, and the layered policy brings more denials because it turns off that unrestricted part and works with levels
- They run outside any restricted domain, where the older discretionary rules alone apply, and the layered policy brings more denials because it labels each file twice and compares the two labels
- They run inside a shared domain that carries the same rules for all of them, so the controls still apply, and the layered policy brings more denials because it turns off that unrestricted part and works with levels
- They run inside a shared domain that carries the same rules for all of them, so the controls still apply, and the layered policy brings more denials because it labels each file twice and compares the two labels