easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A security architect is evaluating security…
A security architect is evaluating security models for a multilevel secure system. Which model enforces the * property (no write down) and is typically used for confidentiality?
⚠ Common exam trap
ISC2 often tests the confusion between Bell-LaPadula (confidentiality, no write down) and Biba (integrity, no write up), leading candidates to mistakenly select Biba when the question specifies confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Bell-LaPadula
The Bell-LaPadula model enforces the * (star) property, which prohibits subjects from writing to objects at a lower classification level (no write down). This property, combined with the simple security property (no read up), ensures that information cannot flow from higher to lower security levels, making it the standard model for enforcing confidentiality in multilevel secure systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Clark-Wilson
Why it's wrong here
Clark-Wilson is an integrity model primarily focused on commercial applications, ensuring data integrity through well-formed transactions and separation of duties. It utilizes constrained data items (CDIs), unconstrained data items (UDIs), transformation procedures (TPs), and integrity verification procedures (IVPs) to prevent unauthorized modifications and maintain internal consistency. This model is incorrect as its primary focus is on integrity within a structured business environment, not confidentiality.
- ✗
Brewer-Nash
Why it's wrong here
Brewer-Nash, also known as the Chinese Wall model, is designed to prevent conflicts of interest by dynamically restricting access to information based on a subject's past access history. It ensures that a user cannot access information from competing companies or datasets once they have accessed information from one, effectively creating a 'wall' between conflicting interests. This model is incorrect because its specific purpose is conflict of interest prevention, not general confidentiality or integrity enforcement.
- ✓
Bell-LaPadula
Why this is correct
Bell-LaPadula is a mandatory access control (MAC) model specifically designed to enforce confidentiality, primarily used in military and government systems. It prevents unauthorized disclosure of information by enforcing two key rules: the Simple Security Property ('no read down'), which states a subject cannot read an object with a higher security level, and the *-property ('no write up'), which states a subject cannot write to an object with a lower security level. This model is correct as it directly addresses confidentiality requirements.
- ✗
Biba
Why it's wrong here
Biba is an integrity model that is often considered the conceptual inverse of Bell-LaPadula, focusing on preventing data corruption rather than unauthorized disclosure. It enforces integrity through rules such as the Simple Integrity Property ('no read up'), preventing subjects from reading data at a higher integrity level, and the *-Integrity Property ('no write down'), preventing subjects from writing to data at a lower integrity level. This model is incorrect because its primary objective is data integrity, not confidentiality.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Bell-LaPadula
A formal security model that prevents users from reading information at a higher classification level than their own and from writing information down to a lower classification level.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.