Guessing D is right, since the Veeam server can't directly touch those EC2 VMs. "Cloud machines" lets you use AWS APIs for discovery, which works even with no network connectivity from the distribution server. That's pretty much the only way here. Someone correct me if I'm missing a scenario though.
D . Since these EC2s are in AWS and the Veeam server can’t reach them directly, "Cloud machines" is the protection group type made for this setup. Seen similar in the official guide and labs. Pretty sure that's what Veeam expects for public cloud discovery, but open to corrections if I missed something.

Looks like it's A. The performance tier should still have the weekly GFS full backup if retention is up to 14 weeks. Unless I'm missing something here.
Doesn’t fallback mean changes from the replica VM go back to production? Fallback copies the delta back so you don’t lose updates made during failover. Or am I missing something about how "permanent" works in Veeam here?
Hard to say, it's D, since RPO is about how much data loss is ok after an incident. It's not about downtime (that would be RTO). If anyone thinks otherwise let me know.