CISSP Practice Question: A financial institution requires a security model that enforces mandatory access controls…
Correct Answer: A. Bell-LaPadula Model
Explanation (CISSP Manager Logic):
The Bell-LaPadula model is the primary framework for enforcing confidentiality through Mandatory Access Control (MAC). It uses security labels and clearances to ensure sensitive data is protected from unauthorized disclosure, aligning with the business goal of data secrecy.
By implementing this solution, you:
- Enforce "no read up" to prevent unauthorized access to higher-level data.
- Enforce "no write down" to stop sensitive data from leaking to lower-security tiers.
- Establish a formal, rule-based architecture that prioritizes information confidentiality.
While the other options are relevant, they fall short because:
- B: Biba focuses exclusively on data integrity and preventing unauthorized modification rather than secrecy.
- C: Clark-Wilson manages integrity through well-formed transactions and separation of duties.
- D: Brewer-Nash is designed to prevent conflicts of interest by dynamically changing access based on user activity.
Think like a manager:
Select security models based on the primary business risk; when the objective is preventing data disclosure, confidentiality-focused models like Bell-LaPadula are the standard.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial