The best answer from the listed options is B. DLP.
DLP, or Data Loss Prevention, is used to protect data from unauthorized access, disclosure, transfer, or misuse. Depending on the implementation, DLP can help enforce policies that restrict unauthorized handling or modification of sensitive data.
However, this question appears to be incomplete or poorly worded. If the goal is specifically to prevent unauthorized changes to system-level files or operating system data, a better answer would normally be a host-based control such as HIPS, endpoint protection, file integrity monitoring, or application allow listing. Those options are not provided.
Why the other options are incorrect:
A. NIDS
A Network Intrusion Detection System detects suspicious network traffic but does not prevent changes to system-level data.
C. NAC
Network Access Control controls whether devices can access the network. It does not directly prevent changes to system-level data.
Therefore, from the provided choices, DLP is the closest answer, but the question may be missing a stronger option.