CISSP Practice Question: An enterprise requires a security model that enforces mandatory access controls using…
Correct Answer: A. Bell-LaPadula Model
Explanation (CISSP Manager Logic):
The Bell-LaPadula model is the primary framework for enforcing confidentiality through Mandatory Access Control (MAC). It uses a lattice-based structure of clearances and classifications to prevent unauthorized disclosure of sensitive data across the enterprise.
By implementing this solution, you:
- Prevent data leakage using the "no read up" property.
- Maintain strict information flow control via the "no write down" property.
- Align security architecture with high-level confidentiality requirements for sensitive assets.
While the other options are relevant, they fall short because:
- B: The Biba model prioritizes data integrity and the prevention of unauthorized modification over confidentiality.
- C: The Clark-Wilson model focuses on commercial integrity through well-formed transactions and separation of duties.
- D: The Brewer and Nash model is designed to prevent conflicts of interest rather than enforcing static classification levels.
Think like a manager:
Select the security model that aligns with your primary business objective. When the goal is preventing data leakage, confidentiality-based models must take precedence over integrity or conflict-of-interest models.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial