SSCP Systems Security Certified PractitionerCryptographyHard

A security auditor is reviewing an organization's cryptographic key management practices. The auditor discovers that the same symmetric key is used for both encrypting sensitive data at rest and for generating Message Authentication Codes (MACs) for data integrity. What is the most significant cryptographic risk introduced by this practice?

  1. AVulnerability to replay attacks
  2. BKey compromise leading to loss of both confidentiality and integrity
  3. CReduced key entropy
  4. DIncreased computational overhead
Show answer & explanation

Correct answer: B. Key compromise leading to loss of both confidentiality and integrity

Using the same key for different cryptographic functions (encryption and MAC generation) violates the principle of key separation. If this single key is compromised, an attacker gains both the ability to decrypt the data (breaking confidentiality) and to forge MACs (breaking integrity), allowing them to alter data undetectably.

Why the other options are wrong

  • A. Replay attacks are typically mitigated by sequence numbers or timestamps, not directly by key separation for encryption and MAC.
  • C. Key entropy is related to the randomness and length of the key, not directly to its reuse for different functions.
  • D. Using the same key does not inherently increase computational overhead; it might even slightly reduce it by avoiding a second key generation.

Key Separation (Cryptographic)

The principle that different cryptographic keys should be used for different cryptographic functions (e.g., encryption, signing, MAC generation) to prevent a compromise of one key from undermining the security of other functions.

  • Assigns distinct keys for distinct operations.
  • Minimizes impact of key compromise.
  • Prevents cryptanalytic attacks that exploit multi-use keys.

Memory trick: Separate Keys for Separate Security.

More Cryptography questions