Courseiva

CISSP Security Architecture and Engineering Practice Question

A security analyst is evaluating access control models for a healthcare organization that needs to enforce both confidentiality and integrity. Which TWO models should be considered? Select two.

⚠ Common exam trap

CISSP often tests the pairing of confidentiality and integrity models, tricking candidates into selecting Clark-Wilson (integrity only) or Brewer-Nash (conflict of interest) when the question explicitly requires both confidentiality and integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Bell-LaPadula

Bell-LaPadula (B) is correct because it is the classic mandatory access control model designed to enforce confidentiality through the no-read-up and no-write-down rules, which fits the healthcare requirement to protect sensitive patient data from unauthorized disclosure. Biba (C) is correct because it is the complementary integrity model that enforces no-read-down and no-write-up, preventing untrusted or lower-integrity data from corrupting higher-integrity records, which addresses the stated need to enforce integrity. Together these two models directly map to the scenario's dual requirement for confidentiality and integrity. Take-Grant (A) is not the best fit because it focuses on modeling how rights can be transferred or granted in a graph-based access control system rather than enforcing confidentiality or integrity policies. Clark-Wilson (D) is an integrity model based on well-formed transactions and separation of duties, but it does not enforce confidentiality, so it does not satisfy both requirements. Brewer-Nash (E) is the Chinese Wall model, which addresses conflict-of-interest access control rather than the general confidentiality and integrity enforcement described here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Take-Grant

    Why it's wrong here

    The Take-Grant model is a formal access control model focused on the propagation of access rights within a system. It uses a graph-based approach to determine how subjects can acquire or transfer rights to objects, or even to other subjects. While useful for analyzing the flow of privileges and potential for privilege escalation, it does not inherently enforce specific confidentiality (e.g., preventing unauthorized disclosure) or integrity (e.g., preventing unauthorized modification) policies directly through its core rules.

  • ✓

    Bell-LaPadula

    Why this is correct

    The Bell-LaPadula model is a state-machine model primarily designed to enforce confidentiality, particularly in military and government systems. It operates on the principles of 'no read up' (Simple Security Property) and 'no write down' (*-property), ensuring that subjects can only access information at or below their security clearance level and cannot write information to a lower security level. This prevents unauthorized disclosure of classified information by strictly controlling information flow.

  • ✓

    Biba

    Why this is correct

    The Biba model is a formal state-machine model specifically designed to enforce integrity, often considered the inverse of Bell-LaPadula. Its core principles are 'no read down' (Simple Integrity Axiom) and 'no write up' (*-Integrity Axiom), meaning subjects can only read data at or above their integrity level and can only write to data at or above their integrity level. This prevents subjects from corrupting data at a higher integrity level and ensures data quality by restricting information flow from lower-integrity sources.

  • ✗

    Clark-Wilson

    Why it's wrong here

    The Clark-Wilson model is an integrity model that focuses on well-formed transactions and separation of duties to maintain data integrity, particularly in commercial applications. It employs constrained data items (CDIs), transformation procedures (TPs), and user-defined procedures (UDPs) to ensure data is modified only in authorized ways by authorized users. While highly effective for ensuring data accuracy and preventing fraud, it does not include mechanisms to enforce confidentiality based on classification levels or prevent unauthorized information disclosure.

  • ✗

    Brewer-Nash

    Why it's wrong here

    The Brewer-Nash model, also known as the Chinese Wall model, is designed to prevent conflicts of interest by dynamically changing access permissions based on a subject's prior access history. Its primary goal is to ensure that a subject cannot access information from competing companies or datasets once they have accessed information from one. This model does not directly enforce general confidentiality (like Bell-LaPadula) or integrity (like Biba), but rather manages access to prevent specific ethical or business conflicts.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.