The only reliable way to prevent forceful browsing is checking authorization on every requested page before serving it. Naming schemes (B), directory organization (C), and ACLs (D) are all bypassable and do not enforce access control at the application level.