Answer: A
Option A is CORRECT because all the 3 requirements can be implemented using Monitored activities
Option B is incorrect because only Password Protections options are available
Option C is incorrect because it is used for Identity Protections only
Option D is incorrect because it is used only for the important resources
Microsoft Defender for Identity (formerly Azure Advanced Threat Protection, also known as Azure ATP) is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
Defender for Identity enables SecOp analysts and security professionals struggling to detect advanced attacks in hybrid environments to: Monitor users, entity behavior, and activities with learning-based analytics
Protect user identities and credentials stored in Active Directory
Identify and investigate suspicious user activities and advanced attacks throughout the kill chain
Provide clear incident information on a simple timeline for fast triage
Reference:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/monitored-activities
https://docs.microsoft.com/en-us/defender-for-identity/what-is