Why both no-cache and no-store should be used in HTTP response?

no-store should not be necessary in normal situations, and in some cases can harm speed and usability. It was intended as a privacy measure: it tells browsers and caches that the response contains sensitive information that should never be written to a disk-based cache (or other non-volatile storage). How it works: Normally, even if a response is marked as no-cache by the server, a user agent …

https://stackoverflow.com/questions/866822/why-both-no-cache-and-no-store-should-be-used-in-http-response