Where should the jar file be placed inside the web application to ensure the resources it contains are accessible by clients?
Which two actions protect a resource file from direct HTTP access within a web application? (Choose two)
Which two statements are true about the security-related tags in a valid Java EE deployment descriptor? (Choose two)