<Directory> matches a filesystem path and everything below it. <Files> matches a file's base name wherever it sits and is the only one of the three allowed in .htaccess, which makes it the tool for blocking .env files and backups (Protecting Sensitive Files). <Location> matches the URL the client sent, before Apache 129 knows which file, if any, it maps to, so it suits content with no file behind it, as in Ubuntu 225 's <Location /server-status>.
The difference matters once two URLs reach the same file. Here site-b gains an Alias publishing a folder under a second path, and a <Location> that tries to protect it:
Alias "/mirror" "/var/www/site-b/private"
<Location "/private">
Require all denied
</Location>for u in /private/secret.txt /mirror/secret.txt; do
printf '%-22s ' "$u"
curl -s -o /dev/null -w '%{http_code}\n' -H 'Host: site-b.example' "http://localhost:8101$u"
done/private/secret.txt 403 /mirror/secret.txt 200
The second URL walks straight past the rule. With <Directory "/var/www/site-b/private"> in place of the <Location>, the same loop returns 403 for both URLs, because the rule now follows the files. A case-insensitive filesystem opens the same gap (/PRIVATE/ on a Mac), which is why the manual says never to use <Location> to restrict files, with one safe exception: <Location "/">, which matches everything.