PT0-002 Attacks and Exploits Practice Question
After exploiting a Linux server, you need to pivot to a restricted network subnet. You have SSH access to the compromised server. Which command would create a SOCKS proxy on the server to route traffic through it?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ssh -D 1080 user@server
SSH -D creates a SOCKS tunnel for dynamic port forwarding, allowing pivoting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ssh -L 1080:server:80 user@server
Why it's wrong here
The -L flag performs local port forwarding, not SOCKS. It creates a static mapping: anything sent to local port 1080 goes to server:80 via the SSH tunnel. This only reaches that one specific host:port combo, so it cannot dynamically route connections to arbitrary internal targets as a SOCKS proxy would. It's useful for reaching a single service, but not for general pivoting.
- ✗
ssh -R 1080:server:80 user@server
Why it's wrong here
The -R flag performs remote port forwarding, which binds a listening socket on the remote server and forwards traffic back to a specified local or remote address. In this invocation, it would open port 1080 on the server and forward it to server:80 on the remote side itself, which is meaningless and doesn't create a SOCKS proxy. Dynamic pivoting requires -D, not -R.
- ✗
ssh -J user@server:1080
Why it's wrong here
The -J flag specifies an SSH ProxyJump, which connects to a final destination through an intermediate host. Here no final destination is given, and -J only establishes an SSH connection; it does not create a local SOCKS proxy. The syntax also omits the required host:port for the jump and the target host, making it unusable for setting up a proxy for pivoting.
- ✓
ssh -D 1080 user@server
Why this is correct
The -D flag enables dynamic port forwarding, establishing a SOCKS4/5 proxy on local port 1080. All traffic sent to this proxy is relayed through the SSH server, which can then reach any host in the server's network. This is the correct way to pivot, as it provides a flexible proxy that supports arbitrary destination addresses.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.