CSSLP Secure Software Concepts Practice Question
An application utilizes the Clark-Wilson integrity model. Which mechanism does it use to ensure that subjects only perform authorized operations on objects?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transformation Procedures (TPs)
Clark-Wilson uses Transformation Procedures (TPs) to move system state from one consistent state to another, strictly controlling access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
RBAC is a general model, not specific to Clark-Wilson's integrity enforcement.
- ✗
Attribute-Based Access Control (ABAC)
Why it's wrong here
ABAC uses attributes, which is a different access model.
- ✗
Discretionary Access Control (DAC)
Why it's wrong here
Clark-Wilson is more rigid than DAC.
- ✗
Security Labels
Why it's wrong here
Labels are used in Bell-LaPadula.
- ✓
Transformation Procedures (TPs)
Why this is correct
TPs are the core of Clark-Wilson to ensure state transitions remain consistent.
About these practice questions
This CSSLP question is part of Courseiva's 198-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official (ISC)² exam blueprint
This CSSLP practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CSSLP exam.