- Home
- All questions
- Question 541
CompTIA Security+ study material · question 541 of 611
Why should the same key not be used both to sign and to encrypt?
Show the answer
Answer: B. It weakens both uses and complicates rotation and revocation
A key should serve one purpose so that its lifecycle can be driven by that purpose alone.
Source: OWASP Key Management Cheat Sheet (OWASP) — OWASP Key Management Cheat Sheet › Key Usage