Full AWS Practitioner Certification Question

A startup is preparing to launch a new mobile application and is building its backend using AWS. To distribute incoming traffic, the team has implemented an Application Load Balancer (ALB). They need to defend the application from common web-based threats, such as SQL injection and cross-site scripting (XSS), while keeping infrastructure maintenance to a minimum. With a small DevOps team and limited time to manage servers or third-party software, they prefer a managed security solution that reduces their operational burden.Which solution should the solutions architect recommend to meet these needs?