CISSP Security Architecture and Engineering Practice Question
A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?
⚠ Common exam trap
CISSP often tests the confusion between Bell-LaPadula and Biba by swapping the direction of the no-read/no-write rules; candidates who memorize 'no read up, no write down' without associating it to confidentiality will pick Bell-LaPadula for an integrity scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Biba
The Biba integrity model is defined by the 'no write up' and 'no read down' rules, which prevent subjects at a lower integrity level from writing to higher levels and prevent subjects at a higher level from reading lower-level (potentially tainted) data. This directly matches the scenario's requirement to prevent unauthorized modifications by preserving integrity across levels. Biba is the integrity counterpart to Bell-LaPadula, which focuses on confidentiality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bell-LaPadula
Why it's wrong here
The Bell-LaPadula model is primarily concerned with confidentiality, preventing unauthorized disclosure of information. It enforces two main rules: the Simple Security Property (no read up) and the *-Property (no write down). These rules ensure that information flows only from lower to higher classification levels, thereby protecting sensitive data from being accessed by subjects at lower security levels, which is the inverse of an integrity requirement.
- ✗
Graham-Denning
Why it's wrong here
The Graham-Denning model is a foundational access control matrix model that defines a set of eight primitive protection rights or operations. These operations describe how subjects can create or delete subjects and objects, and how they can grant, delete, or transfer access rights. It provides a framework for specifying and managing access control policies, but it does not inherently enforce specific integrity or confidentiality rules like 'no write up' or 'no read down'.
- ✗
Clark-Wilson
Why it's wrong here
The Clark-Wilson model focuses on maintaining data integrity through well-formed transactions and separation of duties. It uses certification rules and integrity verification procedures to ensure that data items are modified only by authorized transformation procedures, which are executed by authorized users. This model distinguishes between constrained data items (CDIs) and unconstrained data items (UDIs) to enforce strict controls over data modification, aiming to prevent fraud and errors rather than protecting against information flow in a lattice-based manner.
- ✓
Biba
Why this is correct
The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity. It operates on two core principles: the Simple Integrity Axiom (no read down) and the * (Star) Integrity Axiom (no write up). These rules ensure that subjects cannot read data of lower integrity (to prevent being corrupted) and cannot write to data of higher integrity (to prevent corrupting it), making it ideal for applications requiring strict integrity controls.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Biba
Biba is a security model that uses a lattice-based system to enforce integrity, ensuring that data cannot be corrupted by unauthorized or less trustworthy subjects.
Key term
Bell-LaPadula
A formal security model that prevents users from reading information at a higher classification level than their own and from writing information down to a lower classification level.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.