20+ practice questions focused on Port Redirection and Tunneling — one of the most tested topics on the OffSec PEN-200 / OSCP Concepts exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Port Redirection and Tunneling PracticeYou are performing a penetration test and have gained shell access to a Windows machine. You need to forward traffic to an internal database server at 10.0.0.5:3306. Which TWO of the following tools allow you to perform this task natively or via uploaded binaries on Windows?
Explanation: Port forwarding is essential when the target environment prevents direct network communication to sensitive infrastructure. Using reliable tools like PLINK or Chisel allows a penetration tester to establish tunnels through restrictive environments. Understanding which binaries are cross-platform or native is critical, as it dictates the stealth and efficiency of the pivot. These tools facilitate the movement from a low-privilege entry point to deeper, high-value assets within the internal segment.
Refer to the exhibit. You have executed Chisel on a compromised Windows host to establish a connection to your attacking machine. Based on the output, what is the current state of your proxy capability?
Explanation: The exhibit shows a successful connection to the Chisel server, with a dynamic SOCKS proxy enabled on the client side. By using the 'R:socks' directive, the tool opens a SOCKS listener on the server-side (attacker's machine). This allows the attacker to use tools like proxychains to route traffic through the compromised host into the internal network, effectively transforming the attacker's machine into a proxy client for the target environment.
You need to pivot through a compromised host to reach an internal database. You are using SSH remote port forwarding. If you execute 'ssh -R 9000:localhost:3306 user@attacker-ip', which direction does the traffic flow for this tunnel?
Explanation: Remote port forwarding (-R) maps a port on the remote (attacker) machine to a service accessible by the local (compromised) machine. Traffic directed to port 9000 on the attacker's machine is sent through the SSH tunnel to the compromised host, which then forwards the request to its own localhost on port 3306. This is essential when the attacker cannot initiate a direct connection to the compromised host, but the host can reach out.
When setting up a pivot using SSH tunneling, which THREE factors are critical to ensure the tunnel remains stable and functional for long-term access?
Explanation: Tunnel stability is a major challenge during penetration tests. If a connection times out or the process is killed, the pivot is lost. Proper flags like -N and -f help keep the background process alive, while keep-alive configurations prevent idle timeouts. These techniques ensure that once a foothold is established, the attacker can maintain persistent access to internal segments without needing to manually restart the tunnel after short periods of inactivity.
When using SSH for port redirection, what is the significance of binding to the loopback address (127.0.0.1) versus the 'all interfaces' (0.0.0.0) address?
Explanation: Binding to the loopback address (127.0.0.1) restricts access to the forwarded port to only the local machine, which is a security best practice. Binding to 0.0.0.0 exposes the forwarded port to the entire network segment, potentially allowing unauthorized third parties to access the tunnel. In a penetration test, limiting exposure is critical to prevent accidental unauthorized access to the internal network through your established pivot point.
+15 more Port Redirection and Tunneling questions available
Practice all Port Redirection and Tunneling questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Port Redirection and Tunneling. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Port Redirection and Tunneling questions on the PEN-200 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Port Redirection and Tunneling is tested as part of the OffSec PEN-200 / OSCP Concepts blueprint. Practicing with targeted Port Redirection and Tunneling questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PEN-200 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Port Redirection and Tunneling is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Port Redirection and Tunneling practice session with instant scoring and detailed explanations.
Start Port Redirection and Tunneling Practice →