Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

An attacker has gained access to a Linux server and wants to use it as a pivot point to scan the internal network. The attacker executes `ssh -D 1080 user@compromised-server` from their machine. Which of the following best describes the capability this provides to the attacker?

⚠ Common exam trap

Many candidates confuse dynamic port forwarding with other SSH tunneling features like remote port forwarding or VPNs, which have different flags and capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A SOCKS proxy that allows the attacker to route TCP traffic through the compromised server

The `ssh -D` command establishes a dynamic port forwarding tunnel that acts as a SOCKS proxy. The attacker can then direct tools through this proxy to scan or access internal hosts as if originating from the compromised server. It does not provide a reverse shell, file transfer, or VPN functionality; those require different SSH options or tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A reverse shell from the compromised server back to the attacker

    Why it's wrong here

    A reverse shell is typically established using `ssh -R` (remote port forwarding) or other techniques, not `ssh -D`. The `-D` flag specifically creates a dynamic forwarding (SOCKS proxy) and does not by itself provide an interactive shell. While the attacker already has SSH access, the command described does not spawn a reverse shell; it only sets up a proxy for routing traffic.

  • ✓

    A SOCKS proxy that allows the attacker to route TCP traffic through the compromised server

    Why this is correct

    The `ssh -D` option creates a dynamic port forwarding tunnel, which sets up a SOCKS proxy on the local machine (here, port 1080). The attacker can then configure tools like proxychains or a web browser to use this SOCKS proxy, causing their traffic to be sent through the SSH tunnel and out from the compromised server. This enables pivoting into the internal network from the compromised host's perspective.

  • ✗

    An encrypted file transfer channel for exfiltrating data

    Why it's wrong here

    While SSH provides encryption, the `-D` option is not designed for file transfer. It creates a SOCKS proxy for arbitrary TCP connections. File transfer would typically use `scp` or `sftp`, or perhaps `ssh -L` for specific port forwarding. The scenario describes scanning the internal network, which requires a proxy, not a file transfer mechanism.

  • ✗

    A VPN tunnel that assigns the attacker an IP address on the internal network

    Why it's wrong here

    SSH dynamic port forwarding does not create a VPN or assign an IP address. It provides a SOCKS proxy on the attacker's local machine, and applications must be configured to use that proxy. The attacker's traffic is forwarded through the SSH connection, but the attacker does not get a network interface on the internal network. This distinction is important for understanding the limitations of SSH pivoting.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.