PT0-002 Attacks and Exploits Practice Question
During a penetration test, a tester gains initial access to a Linux server and wants to pivot to an internal network that is not directly accessible. Which of the following tools is specifically designed for creating SOCKS proxies for pivoting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chisel
Chisel is a tool that creates tunnels and SOCKS proxies over HTTP, ideal for pivoting through restrictive networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
chisel
Why this is correct
Chisel is a high-performance tunneling tool that creates encrypted channels over HTTP/HTTPS, allowing an attacker to pivot into internal networks. It supports both TCP port forwarding and SOCKS5 proxy mode, enabling dynamic routing of traffic from tools like Nmap or proxychains through the compromised host. Its design specifically addresses the need for stealthy and flexible post-exploitation access, making it the appropriate choice for establishing a proxy-based pivot.
- ✗
netcat
Why it's wrong here
Netcat is a robust utility for raw TCP/UDP data transfer, commonly employed for reverse shells, file exfiltration, and simple port listening. However, it lacks native support for SOCKS protocols or dynamic port forwarding, so it cannot directly relay arbitrary application traffic through an intermediate host without additional scripting or third-party wrappers. While clever piping can simulate some tunneling, it is neither practical nor designed for the persistent, multi-connection proxy requirements that Chisel fulfills.
- ✗
nmap
Why it's wrong here
Nmap is a network reconnaissance tool focused on discovery, port scanning, service enumeration, and scripting engine probes. It does not contain any mechanism for creating outbound tunnels or SOCKS proxies; its Nmap Scripting Engine (NSE) can interact with services but not redirect traffic. Using Nmap to directly pivot would require already having a proxy or tunnel in place, so it cannot be used as a standalone access expansion tool.
- ✗
hydra
Why it's wrong here
Hydra is an offline/online brute-force password cracking tool that attempts to guess credentials against network services like SSH, FTP, SMB, and HTTP forms. It performs rapid authentication attempts but has no capability for traffic tunneling, port forwarding, or proxying — its entire function is credential guessing. Even when combined with other tools, it would rely on a pre-existing tunnel rather than providing one.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.