B. Manual review works, unless there is a sufficient incentive to break it. Here's an example of PlayStation Network struggling with hackers disabling 2FA via customer support - https://waypoint.vice.com/en_us/article/43ebpd/the-long-weir...
C. If a user is resetting 2FA then most likely they've lost the device on which they had the authenticator app installed. If they still had access to it, authorizing them to perform a 2FA reset would be trivial.
D. Reset via email is the most commonly used one. It's scalable, unlike manual review. Less secure, arguably.
> This is the most tricky issue about 2FA: who's going to authenticate the authentication system
100% agree here. It's a hard problem.