Q1: A design review cites RFC 9711. What decision is this RFC mainly useful for
Multiple Choice
**Judgment point:** Separate the role of Entity Attestation Token from nearby security functions and policy decisions.
**Related keywords:**
- **EAT**: Attestation claims token
- **freshness**: Protection against stale evidence
- **Relying Party**: Party using attestation results
**Options:**
- A: making every relying party trust an entity without verifier policy is not the central purpose of RFC 9711. It can be nearby work, but it is not the decision this RFC primarily supports.
- B: carrying attested claims about an entity so a relying party can evaluate trust in that entity is the reason this RFC belongs in the review path. It drives checks on inputs, validation, and boundaries.
- C: replacing the RATS architecture roles of Attester, Verifier, and Relying Party is outside the RFC boundary. Higher-layer policy and adjacent protocol responsibilities still need separate text.