Courseiva
mediumMultiple SelectObjective-mapped

CISSP Practice Question: Which TWO of the following are principles of the…

Which TWO of the following are principles of the Bell-LaPadula security model?

⚠ Common exam trap

Many candidates confuse 'no write up' (which Bell-LaPadula allows) with 'no write down' (which it prohibits), or they misapply the Biba model's integrity rules (no read down, no write up) to Bell-LaPadula's confidentiality rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

No read up

The Bell-LaPadula model enforces mandatory access control (MAC) to protect confidentiality. Option D (No read up) is correct because a subject cannot read an object at a higher classification level, preventing unauthorized access to sensitive information. Option E (No write down) is correct because a subject cannot write to an object at a lower classification level, preventing the downgrading of classified data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Separation of duty

    Why it's wrong here

    Separation of duty is a fundamental administrative control and a core principle of the Clark-Wilson integrity model, not Bell-LaPadula. It mandates that no single individual should have sufficient privileges to complete a critical or sensitive task alone, requiring multiple parties to prevent fraud, error, or abuse. This control focuses on maintaining data integrity and accountability, which fundamentally differs from Bell-LaPadula's exclusive focus on confidentiality.

  • No write up

    Why it's wrong here

    The 'no write up' rule is a core component of the Biba integrity model's *-integrity property, not a principle of Bell-LaPadula. It dictates that a subject cannot write information to an object that has a higher integrity level than the subject itself. This principle is designed to prevent subjects from corrupting high-integrity data with potentially untrusted or lower-integrity information, which is distinct from Bell-LaPadula's confidentiality objectives.

  • No read down

    Why it's wrong here

    The 'no read down' rule, also known as the Simple Integrity Property in the Biba model, prevents a subject from reading data from an object with a lower integrity level. This is crucial for maintaining data integrity by ensuring that high-integrity subjects do not become contaminated by untrusted or less reliable information. Bell-LaPadula, conversely, is exclusively concerned with preventing unauthorized disclosure of information, not the preservation of data integrity.

  • No read up

    Why this is correct

    The 'no read up' rule is formally known as the Simple Security Property within the Bell-LaPadula model. This principle states that a subject at a given security clearance level cannot read information from an object classified at a higher security level. Its purpose is to enforce confidentiality by preventing unauthorized disclosure of classified information to subjects with insufficient clearance, ensuring that users only access data they are authorized to view.

  • No write down

    Why this is correct

    The 'no write down' rule is the Bell-LaPadula model's *-property (Star Property). It dictates that a subject cannot write information to an object that is classified at a lower security level than the subject itself. This property is vital for preventing information from flowing downwards to less secure classifications, thereby preventing covert channels and ensuring strict confidentiality by containing sensitive data within its authorized security level.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.