Answer:
c.
Explanation:
Based on the information provided within the question it seems that you should on a domain controller, configure constrained delegation on the service account. This would allow you to adjust the trust boundaries of the service by limiting the scope as to what it can do on a user's behalf. Therefore allowing (in this scenario) the application to connect to a back-end database server, BEdata, on behalf of users.