Be able to choose and write the correct SSH -L, -R, or -D command, Chisel client/server invocation, or socat relay for a given pivot, and know which interface a forward binds to. Getting the direction and bind address right is the single most important thing.
Start practicing
Port Redirection and Tunneling — choose a session length
Free · No account required
Domain overview
Port redirection and tunneling on PEN-200 covers pivoting through compromised hosts to reach isolated internal services. You must build SSH local/remote/dynamic forwards, use Chisel and socat, and route tools like nmap and CrackMapExec through proxies. Questions present a pivot scenario and ask which syntax, bind behavior, or tool mode reaches the target service correctly.
Exam objectives
SSH local forwarding (-L) syntax to reach a service bound to localhost on a pivot host
SSH remote forwarding (-R) and how GatewayPorts controls binding to all interfaces
Chisel client/server reverse tunneling over HTTP to bypass outbound firewall restrictions
Using proxychains with SSH -D SOCKS proxy to run nmap, SMB, and other tools through a pivot
Confusing -L and -R direction: -L pulls a remote port to your machine, -R pushes your port to the remote host
Assuming SSH -R binds all interfaces by default; GatewayPorts no restricts it to loopback on the server
Forgetting proxychains only proxies TCP connect, so nmap needs -sT and no ICMP or UDP scans
Click any question to see the full explanation and answer options, or start a focused practice session above.
You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?
2When performing SSH dynamic port forwarding with the -D flag, what is the primary benefit compared to local port forwarding (-L)?
3Why might a penetration tester use a 'jump host' when attempting to access an internal network segment?
4Refer to the exhibit. You are attempting a local port forward using PLINK, but receive a 'Connection refused' error. Which of the following is the most likely cause?
5When using SSH tunneling, what is the primary security risk of using the '-R' flag in a multi-user environment?
6In the context of pivoting, what is 'double pivoting'?
7Refer to the exhibit. If you attempt an SSH remote port forward (-R) to bind a port to all network interfaces on the server, what will happen?
8You are using Proxychains to route your Nmap scan through a SOCKS proxy. Which configuration file must you modify to ensure that the proxy settings are correctly applied during your scan?
9During an internal penetration test, you gain shell access to a Linux machine. You want to pivot deeper into a segmented internal network that is completely unreachable directly from your attack host. Which tunneling approach establishes a true layer 2 network tunnel by creating a virtual network interface, allowing you to route raw Ethernet frames and perform ARP scanning?
10During an internal penetration test, you compromise a Linux machine that acts as a pivot host, but the target internal web server only permits HTTP traffic from localhost. Which local port forwarding syntax allows you to securely access this web application via your attacking machine?
11During an internal penetration test, you compromise a Linux host that has outbound SSH access to your attacking machine but cannot directly reach an internal Windows server on 10.10.10.5:445. You need to forward SMB traffic through the compromised host so that your local tools can connect to 10.10.10.5:445. Which command should you run from your attacking machine to create the required tunnel?
12You have compromised a dual-homed Linux host that can reach an internal network. You want to use it as a SOCKS proxy so that tools like Nmap and Metasploit can route traffic into that internal network. You decide to use SSH dynamic port forwarding. Which command should you run from your attacking machine to create a SOCKS proxy on local port 1080 that tunnels through the compromised host?
13During an internal penetration test, you compromise a Windows host that has two network interfaces: one on your attack network (10.10.10.0/24) and one on a restricted internal network (172.16.5.0/24). You need to scan a web server at 172.16.5.20:80 from your Kali machine. You decide to use SSH dynamic port forwarding. Which command should you run on your Kali machine to create a SOCKS proxy listening on localhost port 1080 through the compromised Windows host (10.10.10.15) using SSH?
14While pivoting through a compromised host, you want to route an Impacket tool through a SOCKS proxy you established with SSH dynamic forwarding. The tool does not support SOCKS natively. Which approach allows the Impacket tool to use the proxy correctly?
15You have a Windows host with outbound internet access but want to avoid installing a full agent. You decide to use Chisel to pivot. Which statement accurately describes how Chisel establishes the tunnel in this scenario?
16A penetration tester has compromised a Linux host and wants to use it as a pivot to reach an internal network. The tester decides to use SSH local port forwarding to access an internal web server at 10.0.0.5:80 from their attacking machine. Which command should the tester run on the attacking machine?
17You have compromised a Linux host that sits on both your external network and an isolated internal network containing a Windows server with SMB exposed. From your Kali machine you need to interact with the SMB service as if it were local. Which single command creates the correct tunnel?
18During an internal assessment, you compromise a Windows host that can reach a segmented network. You want to run a SOCKS proxy on the compromised Windows host so that your Kali tools can reach internal targets through it. Which tool is specifically designed for this purpose and commonly used in PEN-200 scenarios?
19You have an SSH dynamic forward running on port 1080 to a compromised Linux host, and you want to use it with a tool that supports SOCKS5 natively. Which environment variable or configuration is most appropriate to direct the tool through the proxy without using proxychains?
20You have gained a foothold on an internal Linux host (10.10.10.20) that can reach a segregated network containing a web server at 192.168.100.50:80. Your attack machine cannot reach 192.168.100.50 directly. You want to use the compromised host to forward traffic from your machine's local port 8080 to 192.168.100.50:80. Which SSH command should you run from your attack machine?
Be able to choose and write the correct SSH -L, -R, or -D command, Chisel client/server invocation, or socat relay for a given pivot, and know which interface a forward binds to. Getting the direction and bind address right is the single most important thing.
The Courseiva PEN-200 question bank contains 20 questions in the Port Redirection and Tunneling domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Port Redirection and Tunneling domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included