PT0-002 Attacks and Exploits Practice Question
During a penetration test, a tester successfully exploits a web application and gains a foothold. The tester needs to pivot to an internal network segment that is not directly accessible. Which THREE tools can the tester use to create a SOCKS proxy or tunnel for pivoting?
⚠ Common exam trap
The trap is assuming that Netcat can easily create a SOCKS proxy; it can only do simple port forwarding, not dynamic proxying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Chisel
Chisel (A) is correct because it is a fast TCP/UDP tunneling tool written in Go that can run a server on the compromised host and a client locally, creating a SOCKS5 proxy for pivoting into internal networks. Ligolo-ng (D) is correct because it provides a TUN-based reverse tunneling agent that establishes a SOCKS proxy and routes traffic to internal segments without needing a full VPN, making it ideal for pivoting during penetration tests. SSH with the -D flag (E) is correct because it opens a dynamic SOCKS proxy on a local port, allowing the tester to tunnel traffic through the compromised host if SSH access is available. Netcat (B) is not marked correct because, while it can create basic TCP relays, it does not natively provide a SOCKS proxy or full tunneling capability for pivoting. Nmap (C) is not marked correct because it is a port scanner and does not include SOCKS proxy or tunneling features for pivoting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Chisel
Why this is correct
Chisel tunnels TCP over HTTP/WebSocket, creating a SOCKS proxy through the foothold host. This satisfies the requirement to reach the internal segment that is not directly accessible, and works where only HTTP egress is permitted.
- ✗
Netcat
Why it's wrong here
Netcat relays raw TCP or UDP streams and can forward a single port, but it implements no SOCKS protocol negotiation, so dynamic multi-port pivoting through it fails. It is tempting because Netcat is a versatile listener and shell handler, and would suit simple port forwarding rather than a SOCKS proxy.
- ✗
Nmap
Why it's wrong here
Nmap is a scanner and does not implement SOCKS proxying or tunnelling; its --proxies flag only routes scan traffic through an existing proxy. It is tempting because Nmap can reach hosts via a compromised pivot, but that requires an external tunnel already built by another tool.
- ✓
Ligolo-ng
Why this is correct
Ligolo-ng creates a TUN interface on the tester's machine, tunnelling traffic to the agent running on the compromised host, which then forwards packets into the internal segment. This satisfies the requirement for a SOCKS proxy or tunnel enabling pivoting to the otherwise unreachable network.
- ✓
SSH with -D flag
Why this is correct
SSH's `-D` flag opens a local dynamic SOCKS proxy, forwarding arbitrary TCP connections through the compromised host to the unreachable internal segment. This satisfies the pivot requirement without predefining destination ports, unlike static `-L` forwarding, letting the tester reach multiple internal services through one foothold.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Pivoting
Pivoting is a post-exploitation technique where an attacker uses a compromised system as a relay to access other systems on a network that were not directly reachable.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.