The suggested answer is B.
When creating new application files in a scoped application, cross scope access is turned on by default for tables. By default, scoped applications have the necessary settings to read, write, create, and delete records in their own tables. Other application elements, such as REST messages, Script Includes, and Workflows, do not have cross scope access enabled by default and must be explicitly granted permission.