CISSP Security Architecture and Engineering Practice Question
A security architect is designing a system that must prevent conflicts of interest when a consultant works for two competing clients. Which security model ensures that the consultant cannot access data from one client if they have already accessed data from the other?
⚠ Common exam trap
CISSP often tests the confusion between Brewer-Nash and Bell-LaPadula, as both are confidentiality models, but candidates must remember that Brewer-Nash is uniquely defined by its conflict-of-interest prevention through dynamic access restrictions based on prior access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brewer-Nash
Brewer-Nash, also known as the Chinese Wall model, is specifically designed to prevent conflicts of interest by dynamically restricting access based on a user's previous access history. Once a consultant accesses data from one client, the model blocks access to any data belonging to a competing client. This is implemented through dynamically changing access control lists that track what each user has already accessed, ensuring that no user can simultaneously hold data from two competing companies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Clark-Wilson
Why it's wrong here
The Clark-Wilson integrity model is designed to maintain data integrity in commercial applications by enforcing well-formed transactions and separation of duties. It uses certification rules to ensure transformation procedures (TPs) are valid and enforcement rules to ensure subjects only access constrained data items (CDIs) via authorized TPs. This prevents unauthorized modification and ensures data consistency, which is distinct from preventing conflicts of interest.
- ✗
Biba
Why it's wrong here
The Biba integrity model prioritizes data integrity by preventing subjects from corrupting data at higher integrity levels. Its core rules, 'no write down' (simple integrity property) and 'no read up' (* integrity property), ensure that information flows only from lower to higher integrity levels. This prevents untrusted subjects from modifying critical data or reading data from less trusted sources, thereby protecting against data contamination.
- ✓
Brewer-Nash
Why this is correct
The Brewer-Nash model, also known as the Chinese Wall policy, is specifically designed to prevent conflicts of interest within organizations. It dynamically restricts a subject's access to information based on their past access history, ensuring that once a subject accesses data related to one company within a conflict-of-interest class, they cannot access data related to any competing company in that same class. This model is crucial in environments like financial services to maintain ethical conduct and prevent insider trading.
- ✗
Bell-LaPadula
Why it's wrong here
The Bell-LaPadula model is a state machine model primarily focused on enforcing confidentiality in military and government systems. It employs two fundamental rules: the 'simple security property' (no read up) and the '* security property' (no write down), which prevent subjects from accessing information at a higher classification level or writing information to a lower classification level. This strict information flow control is designed to prevent unauthorized disclosure of sensitive data.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.