mediumMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO of the following are principles of the…
Which TWO of the following are principles of the Bell-LaPadula security model?
⚠ Common exam trap
Many candidates confuse 'no write up' (which Bell-LaPadula allows) with 'no write down' (which it prohibits), or they misapply the Biba model's integrity rules (no read down, no write up) to Bell-LaPadula's confidentiality rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No read up
The Bell-LaPadula model enforces mandatory access control (MAC) to protect confidentiality. Option D (No read up) is correct because a subject cannot read an object at a higher classification level, preventing unauthorized access to sensitive information. Option E (No write down) is correct because a subject cannot write to an object at a lower classification level, preventing the downgrading of classified data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of duty
Why it's wrong here
Separation of duty is a fundamental administrative control and a core principle of the Clark-Wilson integrity model, not Bell-LaPadula. It mandates that no single individual should have sufficient privileges to complete a critical or sensitive task alone, requiring multiple parties to prevent fraud, error, or abuse. This control focuses on maintaining data integrity and accountability, which fundamentally differs from Bell-LaPadula's exclusive focus on confidentiality.
- ✗
No write up
Why it's wrong here
The 'no write up' rule is a core component of the Biba integrity model's *-integrity property, not a principle of Bell-LaPadula. It dictates that a subject cannot write information to an object that has a higher integrity level than the subject itself. This principle is designed to prevent subjects from corrupting high-integrity data with potentially untrusted or lower-integrity information, which is distinct from Bell-LaPadula's confidentiality objectives.
- ✗
No read down
Why it's wrong here
The 'no read down' rule, also known as the Simple Integrity Property in the Biba model, prevents a subject from reading data from an object with a lower integrity level. This is crucial for maintaining data integrity by ensuring that high-integrity subjects do not become contaminated by untrusted or less reliable information. Bell-LaPadula, conversely, is exclusively concerned with preventing unauthorized disclosure of information, not the preservation of data integrity.
- ✓
No read up
Why this is correct
The 'no read up' rule is formally known as the Simple Security Property within the Bell-LaPadula model. This principle states that a subject at a given security clearance level cannot read information from an object classified at a higher security level. Its purpose is to enforce confidentiality by preventing unauthorized disclosure of classified information to subjects with insufficient clearance, ensuring that users only access data they are authorized to view.
- ✓
No write down
Why this is correct
The 'no write down' rule is the Bell-LaPadula model's *-property (Star Property). It dictates that a subject cannot write information to an object that is classified at a lower security level than the subject itself. This property is vital for preventing information from flowing downwards to less secure classifications, thereby preventing covert channels and ensuring strict confidentiality by containing sensitive data within its authorized security level.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Bell-LaPadula
A formal security model that prevents users from reading information at a higher classification level than their own and from writing information down to a lower classification level.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.