GCIH Endpoint Attack and Pivoting Practice Question
A compromised Windows 10 workstation has an active Meterpreter session. The responder observes that the attacker used the `portfwd` command to redirect traffic from the victim's TCP port 8080 to an internal HR server's TCP port 3389. The internal HR server is not directly reachable from the responder's analysis host. Which mechanism is the attacker leveraging to pivot into the HR server?
⚠ Common exam trap
A common mix-up: candidates confuse port forwarding with a reverse shell or SOCKS proxy, which serve different purposes and require different configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A TCP relay created by the Meterpreter `portfwd` command.
The `portfwd` command in Meterpreter creates a TCP relay on the compromised host, forwarding traffic from a local port to a specified remote address and port. This allows the attacker to reach internal services that are not directly accessible from their own machine, effectively using the victim as a pivot point. The other options describe different pivoting techniques that do not match the observed command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A reverse TCP shell bound to the HR server's port 3389.
Why it's wrong here
A reverse TCP shell would have the HR server initiate a connection back to the attacker, but the attacker is redirecting traffic through the compromised workstation to a specific internal port. The HR server is not initiating a connection; it is receiving forwarded traffic from the victim host. This does not match the observed `portfwd` behavior.
- ✗
An SSH tunnel using the compromised workstation as a jump host.
Why it's wrong here
SSH tunneling would require an SSH server on the compromised host and the attacker to authenticate and establish a tunnel. The scenario does not mention SSH; it specifically notes the use of Meterpreter's `portfwd` command, which operates at the TCP level without SSH. Thus, an SSH tunnel is not the mechanism in play.
- ✓
A TCP relay created by the Meterpreter `portfwd` command.
Why this is correct
The `portfwd` command in Meterpreter creates a TCP relay that listens on a specified port on the compromised host and forwards all incoming connections to a target IP and port. Here, it listens on TCP 8080 on the victim and relays to the HR server's TCP 3389, effectively pivoting into the internal network segment.
- ✗
A SOCKS proxy established via the Meterpreter `socks` command.
Why it's wrong here
A SOCKS proxy would allow the attacker to route arbitrary application traffic through the compromised host, but it requires the attacker to configure a proxy-aware client. The scenario specifically describes a port forwarding rule that maps a local port on the victim to a remote internal service, not a general-purpose SOCKS proxy.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.