Courseiva
Security Architecture and EngineeringmediumMultiple ChoiceObjective-mapped

CISSP Security Architecture and Engineering Practice Question

An organization requires a commercial integrity model where users cannot modify data in higher integrity levels and cannot read data from lower integrity levels. Which model should they implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Biba

The Biba model addresses integrity through *no write up* and *no read down* rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Bell-LaPadula

    Why it's wrong here

    The Bell-LaPadula model is fundamentally designed to enforce confidentiality, preventing unauthorized disclosure of information. Its core rules, 'no read up' (Simple Security Property) and 'no write down' (*-Property), ensure that subjects cannot access information at a higher security level or write information to a lower security level. This strict hierarchical control prioritizes secrecy over data integrity, making it unsuitable for a primary integrity requirement.

  • Clark-Wilson

    Why it's wrong here

    The Clark-Wilson integrity model focuses on preventing unauthorized modification of data through well-formed transactions and separation of duties. It employs constrained data items (CDIs) and transformation procedures (TPs) to ensure that data modifications are only performed by authorized subjects using approved methods. Unlike models based on hierarchical levels, Clark-Wilson emphasizes strict control over processes and user roles, ensuring internal and external consistency rather than a simple 'no write up' rule.

  • Biba

    Why this is correct

    The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity by enforcing a strict hierarchical integrity policy. Its primary rules are 'no write up' (Simple Integrity Property) and 'no read down' (*-Integrity Property), which prevent subjects from writing to objects of higher integrity or reading from objects of lower integrity. This model ensures that high-integrity data is not contaminated by low-integrity data, making it ideal for scenarios requiring strong data trustworthiness.

  • Take-Grant

    Why it's wrong here

    The Take-Grant model is a graph-based access control model primarily concerned with how access rights can be transferred or propagated between subjects and objects. It defines specific rules—take, grant, create, and remove—that govern the dynamic modification of access rights within a system. This model focuses on the reachability and transferability of permissions rather than enforcing hierarchical integrity levels or preventing data modification, making it unsuitable for a commercial integrity requirement.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.