Study. uk . com
  1. Home
  2. All questions
  3. Question 541

CompTIA Security+ study material · question 541 of 611

Why should the same key not be used both to sign and to encrypt?

  1. Signing and encryption require different key lengths
  2. It weakens both uses and complicates rotation and revocation
  3. Signing keys cannot be stored in hardware
  4. Encryption keys cannot be escrowed
Show the answer

Answer: B. It weakens both uses and complicates rotation and revocation

A key should serve one purpose so that its lifecycle can be driven by that purpose alone.

Source: OWASP Key Management Cheat Sheet (OWASP) — OWASP Key Management Cheat Sheet › Key Usage

Challenge yourself on this topic → Study as cards