New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 2 Question 86 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 86
Topic #: 2
[All CSSLP Questions]

Which of the following security issues does the Bell-La Padula model focus on?

Show Suggested Answer Hide Answer
Suggested Answer: A

The Recovery Point Objective (RPO) describes the acceptable amount of data loss measured in time. It is the point in time to which data must

be recovered as defined by the organization. The RPO is generally a definition of what an organization determines is an 'acceptable loss' in a

disaster situation. If the RPO of a company is 2 hours and the time it takes to get the data back into production is 5 hours, the RPO is still 2

hours. Based on this RPO the data must be restored to within 2 hours of the disaster.

Answer B is incorrect. The Recovery Time Objective (RTO) is the duration of time and a service level within which a business process

must be restored after a disaster or disruption in order to avoid unacceptable consequences associated with a break in business continuity. It

includes the time for trying to fix the problem without a recovery, the recovery itself, tests and the communication to the users. Decision time

for user representative is not included. The business continuity timeline usually runs parallel with an incident management timeline and may

start at the same, or different, points.

In accepted business continuity planning methodology, the RTO is established during the Business Impact Analysis (BIA) by the owner of a

process (usually in conjunction with the Business Continuity planner). The RTOs are then presented to senior management for acceptance.

The RTO attaches to the business process and not the resources required to support the process.

Answer D is incorrect. The Recovery Time Actual (RTA) is established during an exercise, actual event, or predetermined based on

recovery methodology the technology support team develops. This is the time frame the technology support takes to deliver the recovered

infrastructure to the business.

Answer C is incorrect. The Recovery Consistency Objective (RCO) is used in Business Continuity Planning in addition to Recovery Point

Objective (RPO) and Recovery Time Objective (RTO). It applies data consistency objectives to Continuous Data Protection services.


Contribute your Thoughts:

0/2000 characters
Jettie
3 months ago
Really? I didn't know it focused only on confidentiality.
upvoted 0 times
...
Glenn
3 months ago
Definitely B, no doubt there!
upvoted 0 times
...
Sina
3 months ago
Wait, I thought it was more about integrity?
upvoted 0 times
...
Louvenia
4 months ago
Totally agree, B is the right choice.
upvoted 0 times
...
Carole
4 months ago
It's all about confidentiality!
upvoted 0 times
...
Vallie
4 months ago
I feel like I’ve seen similar questions before, and they all pointed to confidentiality as the key issue in the Bell-La Padula model.
upvoted 0 times
...
Lorrie
4 months ago
I’m a bit confused; I thought it also touched on authorization, but now I’m leaning towards confidentiality being the main focus.
upvoted 0 times
...
Aron
4 months ago
I remember practicing a question like this, and I think the focus was definitely on confidentiality, especially with the "no read up, no write down" rules.
upvoted 0 times
...
Leontine
5 months ago
I think the Bell-La Padula model is mainly about confidentiality, but I'm not entirely sure if it covers anything else.
upvoted 0 times
...
Lamonica
5 months ago
I'm a little confused by this question. I know the Bell-La Padula model is important in computer security, but I can't recall the exact security issue it addresses. I'll have to review my notes and try to eliminate the options that don't seem right.
upvoted 0 times
...
Frank
5 months ago
Okay, I remember learning about the Bell-La Padula model in class. I believe it's focused on controlling access and preventing unauthorized access to sensitive information, so I'll select option B for confidentiality.
upvoted 0 times
...
Patria
5 months ago
Hmm, I'm a bit unsure about this one. I know the Bell-La Padula model deals with security, but I can't remember if it's specifically about confidentiality or something else. I'll have to think this through carefully.
upvoted 0 times
...
Krystal
5 months ago
I'm pretty sure the Bell-La Padula model focuses on confidentiality, so I'll go with option B.
upvoted 0 times
...
Veronica
5 months ago
The Bell-La Padula model is all about ensuring the confidentiality of information, so I'm confident that option B is the correct answer here.
upvoted 0 times
...
Stefan
5 months ago
This is a tough one, but I feel confident I can work through it step-by-step and arrive at the right answer.
upvoted 0 times
...
Edda
5 months ago
I think we need to consider the overall complexity of the architecture due to extra components. That sounds familiar from the case studies we reviewed.
upvoted 0 times
...
Darrin
10 months ago
Haha, I bet the Bell-La Padula model is all about keeping the boss's diary under lock and key. Confidentiality all the way!
upvoted 0 times
Peggie
9 months ago
C) Integrity
upvoted 0 times
...
Justine
9 months ago
B) Confidentiality
upvoted 0 times
...
Casie
10 months ago
A) Authorization
upvoted 0 times
...
...
Adelaide
10 months ago
I'm gonna go with B. Confidentiality. Wouldn't want any unauthorized eyes on those juicy secrets, would we?
upvoted 0 times
Jesse
8 months ago
B) Confidentiality
upvoted 0 times
...
Maynard
8 months ago
I agree, keeping information confidential is crucial.
upvoted 0 times
...
Veda
8 months ago
D) Authentication
upvoted 0 times
...
Ahmad
8 months ago
C) Integrity
upvoted 0 times
...
Brice
8 months ago
B) Confidentiality
upvoted 0 times
...
Alaine
10 months ago
A) Authorization
upvoted 0 times
...
...
Arlen
10 months ago
Easy peasy, it's B. Confidentiality. Keeping the bad guys out of the good stuff, that's what it's all about.
upvoted 0 times
...
Delsie
10 months ago
Confidentiality, for sure. Protecting sensitive information is the name of the game with this model.
upvoted 0 times
Alesia
9 months ago
B) Integrity
upvoted 0 times
...
Vesta
9 months ago
A) Confidentiality
upvoted 0 times
...
...
Dortha
10 months ago
Actually, the Bell-La Padula model focuses on authorization, not confidentiality.
upvoted 0 times
...
Oretha
10 months ago
Hmm, I think the Bell-La Padula model is all about confidentiality. Gotta keep those secrets safe, you know?
upvoted 0 times
...
Golda
10 months ago
I agree with Hui, confidentiality is a major concern in the Bell-La Padula model.
upvoted 0 times
...
Hui
10 months ago
I think the Bell-La Padula model focuses on confidentiality.
upvoted 0 times
...

Save Cancel