Locking down a administrator account especially if it's a production account can be disruptive, I don't like the options CompTIA gives here.
A better answer would be to setup whitelisting from specific IP addresses. Locking the account due to many failed attemps can cause A LOT of problems. What is stopping the attacker from doing it again?
Blocking them IP address here, would make the most real world practical sense as it does not affect production. But they can easily switch IP addresses, so that's why I think setting up whitelisting would be a better option, or even setting up rate limiting or requiring MFA are better options too. I'm gonna go with A, but I don't really agree with either of these answers.