Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a penetration test, a tester gains initial access to a Linux server and wants to pivot to an internal network that is not directly accessible. Which of the following tools is specifically designed for creating SOCKS proxies for pivoting?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

chisel

Chisel is a tool that creates tunnels and SOCKS proxies over HTTP, ideal for pivoting through restrictive networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    chisel

    Why this is correct

    Chisel is a high-performance tunneling tool that creates encrypted channels over HTTP/HTTPS, allowing an attacker to pivot into internal networks. It supports both TCP port forwarding and SOCKS5 proxy mode, enabling dynamic routing of traffic from tools like Nmap or proxychains through the compromised host. Its design specifically addresses the need for stealthy and flexible post-exploitation access, making it the appropriate choice for establishing a proxy-based pivot.

  • ✗

    netcat

    Why it's wrong here

    Netcat is a robust utility for raw TCP/UDP data transfer, commonly employed for reverse shells, file exfiltration, and simple port listening. However, it lacks native support for SOCKS protocols or dynamic port forwarding, so it cannot directly relay arbitrary application traffic through an intermediate host without additional scripting or third-party wrappers. While clever piping can simulate some tunneling, it is neither practical nor designed for the persistent, multi-connection proxy requirements that Chisel fulfills.

  • ✗

    nmap

    Why it's wrong here

    Nmap is a network reconnaissance tool focused on discovery, port scanning, service enumeration, and scripting engine probes. It does not contain any mechanism for creating outbound tunnels or SOCKS proxies; its Nmap Scripting Engine (NSE) can interact with services but not redirect traffic. Using Nmap to directly pivot would require already having a proxy or tunnel in place, so it cannot be used as a standalone access expansion tool.

  • ✗

    hydra

    Why it's wrong here

    Hydra is an offline/online brute-force password cracking tool that attempts to guess credentials against network services like SSH, FTP, SMB, and HTTP forms. It performs rapid authentication attempts but has no capability for traffic tunneling, port forwarding, or proxying — its entire function is credential guessing. Even when combined with other tools, it would rely on a pre-existing tunnel rather than providing one.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.