Standard — your team's fixed password for the domain, applied on the server. It never travels through the browser before the mailbox exists, and it means one password your staff already know opens every mailbox made this way. Fine for a 22 MB activation inbox; think twice for a client's long-term mailbox.
Random — generated on the server, shown to you once. Use it for anything long-lived. cPanel never reveals a mailbox password through any API, so if it is not copied at the moment of creation it is gone — though you can always set a new one.
Custom — you type it, within the length the administrator allows. This option can be switched off for a domain, in which case it is greyed out.