Q1: You fetch an Agent Card from a known domain. What should you do before sending a confidential task?
Multiple Choice
Explanation: An Agent Card tells a client what a server advertises and how it expects to be contacted. It is useful discovery input, but a sensitive task still needs the endpoint, authentication scheme, authorization boundary, and deployment trust policy to be checked.
A: Reachability does not independently prove every identity claim, skill, or permission in the document.
B: This keeps discovery separate from the security checks required before disclosing data or invoking a capability.
C: HTTPS protects a connection to the authenticated server name; it does not authorize every advertised operation.
D: The A2A 1.0 specification makes Agent Card signatures optional and recommends verifying them when present. An unsigned Card still needs a trusted delivery path and a local policy decision; absence of a signature alone is not a universal rejection rule.