Which of the following is the BEST countermeasure to brute force login attacks?

A.
Changing all canonical passwords
B.
Decreasing the number of concurrent user sessions
C.
Restricting initial password delivery only in person
D.
Introducing a delay after failed system access attempts