TechKnowSurge
CompTIA Security+ 4.6 NIST 800-53 IA-8 NIST CSF PR.AA-04 NIST NICE K0742
InteractiveSecurityFree

Follow the Trust

Follow the trust arrows between TechKnowDJ and its partners and decide who can sign in where.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you’re seeing: small diagrams of companies linked by trust, TechKnowDJ and its partners, with an arrow for every trust. Each one asks whether a user from one company can sign in to another company’s app. Why it matters: federation lets one organization accept sign-ins checked by another, and the direction of the trust decides who gets in. If A trusts B, B’s users can get into A’s apps, but not the reverse unless the trust is two-way. Transitive trust stretches along a chain, so a company can end up trusting another it never chose to, while non-transitive trust stops after one link. How to use it: read the arrows, pick the answer and the reason, and lock it in. The diagram then shows the path the sign-in travels or the link where it breaks.

How to play

You are TechKnowDJ’s new IAM analyst. Each scenario shows a few companies linked by trust and asks: can a user from one company sign in to another company’s app?

How to read the arrows. An arrow labelled trusts starts at the company doing the trusting and points at the company it trusts. If A trusts B, A accepts B’s sign-ins, so B’s users can get into A’s apps. Not the other way round, unless the trust is two-way.

  • One-way: one company trusts the other; the reverse is not true.
  • Two-way: they trust each other.
  • Transitive: if A trusts B and B trusts C, then A trusts C. Non-transitive: each trust covers only the two companies it links. The label above each diagram of three or more companies tells you which.

Pick the answer and the reason that fit, then press Lock it in. The diagram then marks the path, or the link where it breaks. You are only deciding whether the sign-in is accepted; what the user may do once inside is still up to that company’s permissions.

Each round is 7 scenarios, getting harder as you go. Get 6 of 7 to pass. Reset or Play again draws a new set.

What you'll learn

Aligned to

CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
NIST 800-53
IA-8 Identification and Authentication (Non-Organizational Users)
NIST CSF
PR.AA-04 Identity assertions are protected, conveyed, and verified.
NIST NICE
K0742 Knowledge of identity and access management (IAM) principles and practices

Key terms

Identity Federation
A system that establishes trust between separate organizations or domains so that users authenticated by one can access resources of another.
Transitive Trust
A trust relationship in which if Organization A trusts Organization B and Organization B trusts Organization C, then Organization A implicitly trusts Organization C.
Federated Identity
An electronic identity and its attributes that can be used to access resources across multiple distinct organizations or systems through established trust relationships.
Identity Provider
IdP
An Identity Provider is a trusted system that creates, maintains, and manages identity information for users and issues authentication tokens or assertions to relying party applications in federated identity and SSO architectures.
Authentication
The process of verifying the identity of a user, device, or system.

Topics

Identity Federation Transitive Trust Federated Identity Access Management

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →