CAS-004 Security Operations Practice Question
During a penetration test, the tester has gained initial access to a web server and wants to perform lateral movement to reach a database server. The tester enumerates the network and finds that the web server has two network interfaces: one connected to a DMZ and one to an internal network. The database server is on the internal network. Which TWO techniques could the tester use to pivot from the web server to the database server? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use SSH tunneling to create a local forward to the database server's port
Option A is correct because SSH local port forwarding (ssh -L) lets the tester tunnel traffic from their machine through the compromised web server to reach the database server's port on the internal network, effectively pivoting across the dual-homed host. Option E is correct because Metasploit's 'route add' command (e.g., route add <internal_subnet> <session_id>) configures the framework to route traffic for the internal subnet through the existing Meterpreter session on the web server, enabling pivoting to the database server. Option B is incorrect because SQL injection targets a database through a vulnerable web application and does not provide network-level pivoting from the web server to the internal database server. Option C is incorrect because a reverse shell only establishes command-and-control back to the tester's machine; it does not route traffic into the internal network. Option D is incorrect because a keylogger passively captures credentials on the web server and does not create a pivot path to the database server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use SSH tunneling to create a local forward to the database server's port
Why this is correct
SSH local port forwarding binds a listener on the tester's host that relays traffic through the compromised dual-homed web server to the database server's internal port, exploiting the web server's DMZ and internal interfaces to cross the network boundary.
- ✗
Perform a SQL injection attack against the database server
Why it's wrong here
SQL injection targets a database the tester cannot yet reach; the web server's internal interface must first be leveraged as a relay to forward traffic onto the internal network. It is tempting because SQL injection is a database attack, and would be correct once a reachable application endpoint already communicates with that database.
- ✗
Deploy a reverse shell from the web server to the tester's machine
Why it's wrong here
A reverse shell returns an interactive session to the tester's own machine, but that channel terminates outside the internal network, so it cannot forward traffic to the database. It is tempting because reverse shells provide command execution, and would be correct for maintaining access to the compromised web server itself.
- ✗
Install a keylogger on the web server to capture database credentials
Why it's wrong here
Capturing credentials with a keylogger yields authentication material but does not itself route traffic across the web server's dual-homed interfaces to reach the internal database server. It is tempting because credential harvesting supports later authenticated access, and would be correct where the target's login is typed interactively and no network path exists.
- ✓
Use Metasploit's route add command to add a route to the internal subnet through the web server
Why this is correct
Metasploit's route add command directs traffic for the internal subnet through the existing session on the dual-homed web server, using it as a pivot point. This exploits the web server's second interface to reach the database server on the internal network.
Visual reference
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.