Ultimate access to all questions.
A company operates an application in the AWS Cloud, which includes microservices running on Amazon EC2 instances across multiple Availability Zones, managed by an Application Load Balancer. Recently, a new REST API was integrated using Amazon API Gateway. Certain legacy microservices on EC2 instances require access to this new API. The company seeks to restrict public internet access to the API and prevent proprietary data from traversing the public internet. What solution should a solutions architect implement to fulfill these security requirements?