AWS Certified Solutions Architect - Professional (#287)

A government client needs you to set up secure cryptographic key storage for some of their extremely confidential data. You decide that the AWS CloudHSM is the best service for this. However, there seem to be a few pre-requisites before this can happen, one of those being a security group that has certain ports open. Which of the following is correct in regards to those security groups?

A security group that has no ports open to your network.
A security group that has only port 3389 (for RDP) open to your network.
A security group that has only port 22 (for SSH) open to your network.
A security group that has port 22 (for SSH) or port 3389 (for RDP) open to your network.