Q1: A spec says "Clients must validate certificates" but does not define BCP 14 keyword interpretation. What is the most likely problem
Multiple Choice
**Explanation:**
**Terms:** must (lowercase), normative requirement, BCP 14, ambiguity. A requirement needs an agreed interpretation rule so implementers can test conformance consistently.
**Correct (B):** Without explicit BCP 14 interpretation, readers may disagree whether lowercase must is a strict conformance requirement or just strong prose. That disagreement leads to inconsistent implementations.
**Options:**
- A (incorrect): Nothing forces all readers to interpret lowercase must as normative unless the spec explicitly defines that convention.
- B (correct): This is the real risk: ambiguity in normative intent and therefore inconsistent behavior.
- C (incorrect): The sentence is still meaningful English. The issue is clarity, not validity.
**Related:** If the requirement is security relevant, write it so conformance can be checked and cite BCP 14 interpretation rules.