The application takes unfiltered traffic straight from the internet — no WAF to block common exploits and bots — and the tiers behind the ALB are loosely exposed.
By the end, nothing should reach the ALB except through a WAF, and the app and database tiers should sit somewhere the internet can't reach directly — with the database encrypted at rest and private-subnet egress still working.