A web application is running on Amazon EC2 instances behind an Elastic Load Balancing Application Load Balancer (ALB). The EC2 instances should receive no traffic, except for web requests to the application.Based on these requirements, what security group rules should be put on the Amazon EC2 instances?