Which two statements are true about the security-related tags in a valid Java EE deployment descriptor?()
A.Every tag must have at least one tag.
B.A tag can have many tags.
C.A given tag can apply to only one tag.
D.A given tag can contain from zero to many tags.
E.It is possible to construct a valid tag such that,for a given resource,no user rolescan access that resource.