Study. uk . com
  1. Home
  2. All questions
  3. Question 539

CompTIA Security+ study material · question 539 of 611

What determines the appropriate cryptoperiod for a key?

  1. The consequence of compromise and the volume of data protected
  2. The vendor's default configuration
  3. The key's length alone
  4. The organisation's audit cycle
Show the answer

Answer: A. The consequence of compromise and the volume of data protected

A key protecting more data or higher-consequence data warrants a shorter period before rotation.

Source: NIST SP 800-57 Part 1 Rev. 5 (NIST) — SP 800-57 Part 1 Rev. 5 § 5.3 Cryptoperiods

Challenge yourself on this topic → Study as cards