Full AWS Practitioner Certification Question

A solutions architect is designing a highly available architecture for a public-facing website hosted on Amazon EC2 Windows instances. The website must remain online even during a large-scale distributed denial-of-service (DDoS) attack originating from thousands of IP addresses. Ensuring zero downtime is critical to business operations.Which two actions should the solutions architect take to help protect the application from such an attack?