An administrator is running `ansible-playbook -i inventories/prod site.yml` against the `prod` inventory, which contains a group `web` and a group `db`. The play is defined with `hosts: web:&db`. Which hosts will the play target?
In an Ansible host pattern, the `&` separator means intersection (logical AND). Writing `web:&db` selects only hosts that appear in the `web` group and also in the `db` group. This is the correct behavior: the pattern applies both group filters and targets the overlap, which is exactly what the play declares.
Why this answer
The `:&` syntax in a host pattern performs set intersection, so the play runs only against hosts that are members of both the `web` and `db` groups. The `:` alone would create a union, and a leading `!` would exclude. Because the play uses `web:&db`, the correct target set is the overlap of the two groups.
Exam trap
The trap here is confusing the colon union operator with the ampersand intersection operator, which leads to selecting every host in either group instead of the shared members.