CISSP Security Architecture and Engineering Practice Question
A security architect is implementing a system that must prevent conflicts of interest for a consulting firm serving competing clients. Which security model is best suited for this requirement?
⚠ Common exam trap
CISSP often tests the confusion between Brewer-Nash (conflict of interest) and Clark-Wilson (integrity) — candidates pick Clark-Wilson because both sound 'commercial' and integrity-focused, missing the conflict-of-interest keyword.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Brewer-Nash
The Brewer-Nash model (also called the Chinese Wall model) is specifically designed to prevent conflicts of interest by dynamically restricting access based on what a subject has already accessed. Once a consultant accesses data from one competing client, they are blocked from accessing data about that client's competitors. This dynamic, history-based access control is exactly what the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Take-Grant
Why it's wrong here
The Take-Grant protection model is primarily concerned with how access rights can be transferred or propagated between subjects and objects within a system. It defines a set of rules (take, grant, create, remove) that govern the dynamic evolution of access rights. While it addresses access control, its core purpose is not to prevent conflicts of interest, but rather to analyze the reachability and flow of privileges, making it unsuitable for enforcing separation of duties or preventing specific business conflicts.
- ✓
Brewer-Nash
Why this is correct
The Brewer-Nash model, also known as the Chinese Wall model, is specifically designed to prevent conflicts of interest by dynamically restricting access based on prior access history. It ensures that a subject who has accessed information from one company within a "conflict of interest class" cannot subsequently access information from a competing company within the same class. This dynamic access control mechanism effectively enforces ethical walls, making it the ideal choice for scenarios requiring the prevention of information leakage between competing entities.
- ✗
Clark-Wilson
Why it's wrong here
The Clark-Wilson integrity model focuses on maintaining data integrity through well-formed transactions and separation of duties. It uses constrained data items (CDIs), unconstrained data items (UDIs), transformation procedures (TPs), and certification rules to ensure that data is modified only in authorized ways by authorized users. While it enforces separation of duties to prevent fraud, its primary goal is not to prevent conflicts of interest arising from accessing competing datasets, but rather to ensure the validity and consistency of data.
- ✗
Graham-Denning
Why it's wrong here
The Graham-Denning model provides a foundational framework for defining and managing access control rights through a set of eight primitive operations. These operations include creating or deleting subjects and objects, and reading, granting, or deleting access rights for subjects over objects. While fundamental to access control system design, this model focuses on the mechanics of rights management rather than implementing policies to prevent specific business conflicts of interest, making it unsuitable for the stated requirement.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.