Full AWS Practitioner Certification Question

An online retail company hosts its website on an Amazon EC2 instance in a public subnet. The instance is assigned an Elastic IP address and currently uses the default security group. However, the default network ACL has been manually updated to deny all traffic in both directions. The company now needs to allow global HTTPS access to the website on port 443.What combination of actions should a solutions architect take to enable secure web access to the EC2 instance from anywhere? (Select two.)