Ultimate access to all questions.
A media company is deploying a news website for a global audience, utilizing Amazon CloudFront as its content delivery network. The backend infrastructure consists of Amazon EC2 Windows instances managed by an Auto Scaling group and fronted by an Application Load Balancer (ALB). Customers access the website via the CloudFront custom domain name, service.example.com, with the CloudFront origin configured to point to the ALB using the domain name service-alb.example.com. The company’s security policy mandates that all traffic between users and the backend must be encrypted in transit.
Which three changes must the company implement to comply with this security requirement?