TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.2 ISC2 CISSP 3.6 NIST 800-53 SC-17 CompTIA Security+ 1.2 ISC2 CC 4.2 NIST CSF PR.AA-03
InteractiveSecurityFree

Which Trust Model?

Sort each situation by how the trust gets there: direct, third-party, hierarchy, web of trust, or zero trust.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

The most secure network is one that is unplugged, and nobody can work that way. At some point you have to extend trust to devices and sites you do not control. A trust model is a way of doing that safely, and public key infrastructure is one place the lesson applies them. Direct trust is trust straight between two entities: the TechKnowSurge site's certificate is installed straight onto your own machine, and no third party is involved. It works, but it does not scale, because nobody installs a separate certificate for every site they visit. Third-party trust solves that. You trust a certificate authority, the certificate authority has checked the site, so you can trust the site. Hierarchy trust passes trust down: a top-level authority trusts a subordinate, which can pass it down again, building layers underneath one trusted core. A web of trust has no top at all: you trust a stranger because people you trust directly trust them. Zero trust sounds like the opposite of all this, and it is not. It is the rule that someone who simply plugs into the internal network is not trusted with its resources until they have been verified: never trust, always verify. A company can enforce it with an internal certificate authority of its own, which is itself a use of the models above. Zero trust does not mean nobody is ever trusted; it means trust is never given just for being on the inside. To sort each card, ask how the trust gets there. Straight between the two? Through one trusted outsider? Down through levels? Across a group of peers? Or is the point that being on the inside earns nothing until checked?

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
1.2 Summarize fundamental security concepts.
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.
ISC2 CISSP
3.6 Select and determine cryptographic solutions
NIST 800-53
SC-17 Public Key Infrastructure Certificates
ISC2 CC
4.2 Understand network security architecture
NIST CSF
PR.AA-03 Users, services, and hardware are authenticated

Key terms

Direct Trust
A trust model in which two entities establish trust directly with each other, such as by installing a certificate directly onto a machine.
Third-Party Trust
A trust model in which a mutually trusted third party, such as a certificate authority, vouches for and extends trust to other entities.
Hierarchy Trust
A trust model in which a top-level trust anchor delegates trust down through subordinate entities, forming a layered chain of authority.
Web of Trust
A trust model in which entities establish indirect trust through a network of direct peer-to-peer trust relationships rather than a central authority.
Zero Trust
A security model that assumes no user or device is trusted by default and requires continuous verification.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Public Key Infrastructure
PKI
A framework of hardware, software, policies, and standards used to create, manage, and distribute digital certificates.

Topics

Trust Models Public Key Infrastructure Zero Trust Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →