Courseiva

CCNA Port Redirection and Tunneling Questions

20 questions · Port Redirection and Tunneling · All types, answers revealed

1
MCQeasy

When performing SSH dynamic port forwarding with the -D flag, what is the primary benefit compared to local port forwarding (-L)?

A.It provides a faster connection speed than local forwarding.
B.It enables routing to multiple internal hosts dynamically.
C.It is more secure because it disables encryption.
D.It allows the user to run commands on the remote machine.
AnswerB

Dynamic port forwarding acts as a SOCKS proxy, allowing client applications to route traffic through the SSH server to any destination reachable by that server. This eliminates the need to create individual -L tunnels for every specific internal IP or service, providing much greater flexibility during network enumeration.

Why this answer

Dynamic port forwarding creates a SOCKS proxy, which allows the user to route traffic to any destination reachable by the remote jump host. Unlike local port forwarding, which requires specifying a target IP and port upfront, dynamic forwarding is flexible. This is essential during the discovery phase of a penetration test, as it allows tools like Nmap or browser-based tools to explore an entire internal network segment without individual tunnel configurations.

Exam trap

Candidates often confuse dynamic port forwarding with local port forwarding, assuming they need to create a new tunnel every time they want to access a different internal service.

2
MCQmedium

When using SSH tunneling, what is the primary security risk of using the '-R' flag in a multi-user environment?

A.It exposes the tunnel to all users on the remote server.
B.It forces the remote server to enable password-less login.
C.It requires the remote server to have a GUI installed.
D.It automatically disables logs on the jump host.
AnswerA

By default, ports forwarded with -R bind to the loopback interface on the remote server. However, if the server configuration allows it or if you bind to all interfaces, any user on that server can access the forwarded port, effectively hijacking your pivot for their own network activities or malicious use.

Why this answer

The -R flag binds a port on the remote (attacker/server) machine. If that machine has other users logged in, they can potentially connect to the forwarded port and gain access to the internal network through the tunnel you established. This exposes your pivot to unintended access by other users on the same machine, which is a significant risk in shared lab or production environments.

Exam trap

Students frequently focus only on the functionality of the tunnel, missing the multi-user environment context where bound ports on shared servers expose sensitive entry points to unauthorized local users.

3
MCQmedium

You have an SSH dynamic forward running on port 1080 to a compromised Linux host, and you want to use it with a tool that supports SOCKS5 natively. Which environment variable or configuration is most appropriate to direct the tool through the proxy without using proxychains?

A.Set the ALL_PROXY environment variable to 127.0.0.1:1080.
B.Configure the tool to use a PAC file that points to 127.0.0.1:1080.
C.Use the tool's native SOCKS5 option, such as --proxy socks5://127.0.0.1:1080 or the equivalent for that tool.
D.Set the http_proxy environment variable to socks5://127.0.0.1:1080.
AnswerC

Tools that support SOCKS5 natively provide a command-line option or configuration setting to specify the proxy address and port. For example, curl uses --proxy socks5://127.0.0.1:1080, and many others have similar flags. This is the most direct and reliable way to route the tool's traffic through the SSH dynamic forward without additional wrappers.

Why this answer

When a tool supports SOCKS5 natively, the cleanest approach is to use its built-in proxy option, specifying the SOCKS5 scheme and the local address and port of the SSH dynamic forward. This avoids the limitations of LD_PRELOAD-based wrappers and ensures the tool handles proxy negotiation correctly. Environment variables can work in some cases but are less consistent across different tools and libraries.

Exam trap

The trap here is assuming that setting a generic proxy environment variable will work for all tools, when native SOCKS support is more reliable and explicit.

4
MCQmedium

During an internal penetration test, you compromise a Linux host that has outbound SSH access to your attacking machine but cannot directly reach an internal Windows server on 10.10.10.5:445. You need to forward SMB traffic through the compromised host so that your local tools can connect to 10.10.10.5:445. Which command should you run from your attacking machine to create the required tunnel?

A.ssh -R 127.0.0.1:4450:10.10.10.5:445 user@compromised-host
B.ssh -D 127.0.0.1:4450 user@compromised-host
C.ssh -L 10.10.10.5:445:127.0.0.1:4450 user@compromised-host
D.ssh -L 127.0.0.1:4450:10.10.10.5:445 user@compromised-host
AnswerD

This command creates a local port forward from your attacking machine's loopback interface on port 4450 to 10.10.10.5:445 through the compromised host. Because the compromised host can reach the internal Windows server, the SSH server relays the connection. You would then point your SMB client to 127.0.0.1:4450 to access the internal service.

Why this answer

A local port forward with -L listens on your attacking machine and forwards through the SSH server to a destination reachable from that server. The syntax is -L [bind_address:]local_port:target_host:target_port. Here, the compromised host can reach 10.10.10.5:445, so binding locally and pointing the forward at the internal SMB service provides the required access.

Exam trap

The trap here is confusing local and remote port forwarding directions, leading to a tunnel that listens on the pivot host instead of on the attacking machine.

5
MCQmedium

While pivoting through a compromised host, you want to route an Impacket tool through a SOCKS proxy you established with SSH dynamic forwarding. The tool does not support SOCKS natively. Which approach allows the Impacket tool to use the proxy correctly?

A.Add a static route on the attacking machine for the internal subnet pointing at the SSH server's IP address.
B.Set the HTTP_PROXY environment variable to point at the SSH dynamic forwarding port before launching the Impacket tool.
C.Run the Impacket tool under proxychains, ensuring the proxychains configuration lists the SOCKS proxy and uses the appropriate proxy type.
D.Re-run the SSH session with the -L flag instead of -D so Impacket can connect directly to the internal host through a fixed local port.
AnswerC

Proxychains intercepts the tool's socket calls and redirects them through the configured SOCKS proxy, which bridges the tool to the internal network. Because Impacket lacks native SOCKS support, wrapping it in proxychains is the standard method. The configuration must specify the correct proxy type and port for the SSH dynamic forward to work.

Why this answer

Proxychains is the standard bridge for tools that cannot speak SOCKS. It hooks the process's network calls and forwards them to the SOCKS listener created by SSH dynamic forwarding, allowing Impacket tools to reach internal services. The configuration file must correctly identify the proxy address, port, and SOCKS version, otherwise connections fail or leak outside the tunnel.

Exam trap

The trap here is assuming any proxy environment variable will redirect a raw-socket tool through a SOCKS listener created by SSH dynamic forwarding.

6
MCQmedium

During an internal penetration test, you compromise a Linux machine that acts as a pivot host, but the target internal web server only permits HTTP traffic from localhost. Which local port forwarding syntax allows you to securely access this web application via your attacking machine?

A.ssh -R 8080:10.0.4.5:80 user@pivot-host
B.ssh -D 1080 user@pivot-host
C.ssh -L 8080:10.0.4.5:80 user@pivot-host
D.ssh -w 0:0 user@pivot-host
AnswerC

This command correctly establishes local port forwarding by binding port 8080 on your attacking machine and forwarding traffic through the pivot host to the internal web server at 10.0.4.5 on port 80, satisfying the localhost restriction requirement.

Why this answer

Local port forwarding binds a port on your attacking machine and forwards any connections through the compromised pivot host to the destination service. This technique bypasses strict perimeter controls by tunneling traffic securely across an existing SSH session, enabling interaction with internal services restricted strictly to localhost interfaces.

Exam trap

Candidates frequently confuse local port forwarding with remote port forwarding, incorrectly choosing the reverse direction when trying to access internal targets from the attacker workstation.

7
MCQeasy

During an internal assessment, you compromise a Windows host that can reach a segmented network. You want to run a SOCKS proxy on the compromised Windows host so that your Kali tools can reach internal targets through it. Which tool is specifically designed for this purpose and commonly used in PEN-200 scenarios?

A.Chisel
B.Wireshark
C.Netcat
D.Nmap
AnswerA

Chisel is a fast TCP/UDP tunnel transported over HTTP and secured with SSH, and it can operate as a SOCKS proxy server on the compromised host. Running the Chisel server on the Windows pivot and connecting a client from Kali with a reverse SOCKS configuration gives you a proxy into the internal network. It is a standard tool for pivoting when SSH is unavailable or inconvenient.

Why this answer

Chisel is purpose-built for tunneling and can run as a SOCKS proxy server on a compromised host, with a client on the attacker machine connecting back or forward. This makes it well suited for Windows pivots where you want a single binary that handles HTTP transport and SOCKS. Netcat, Nmap, and Wireshark serve different roles and cannot provide a SOCKS proxy service for arbitrary tools.

Exam trap

The trap here is assuming any networking tool can act as a SOCKS proxy, when only dedicated tunneling tools like Chisel implement the SOCKS protocol on the server side.

8
MCQmedium

During an internal penetration test, you compromise a Windows host that has two network interfaces: one on your attack network (10.10.10.0/24) and one on a restricted internal network (172.16.5.0/24). You need to scan a web server at 172.16.5.20:80 from your Kali machine. You decide to use SSH dynamic port forwarding. Which command should you run on your Kali machine to create a SOCKS proxy listening on localhost port 1080 through the compromised Windows host (10.10.10.15) using SSH?

A.ssh -R 1080:172.16.5.20:80 user@10.10.10.15
B.ssh -D 1080 user@10.10.10.15
C.ssh -D 1080 -L 80:172.16.5.20:80 user@10.10.10.15
D.ssh -L 1080:172.16.5.20:80 user@10.10.10.15
AnswerB

This command creates a dynamic port forward (SOCKS proxy) on local port 1080 and connects to the SSH server at 10.10.10.15. Once authenticated, any traffic sent through the SOCKS proxy is tunneled through the SSH connection and forwarded to the target network, allowing you to reach 172.16.5.20.

Why this answer

To pivot into an internal network using SSH dynamic port forwarding, the -D option creates a SOCKS proxy on the specified local port. This allows tools like proxychains or browser proxies to route traffic through the SSH tunnel to any host reachable by the compromised server. The command must specify the SSH server address, which is the compromised host's IP on the attack network.

Exam trap

The trap here is confusing dynamic port forwarding (-D) with local port forwarding (-L), which only forwards to a single predetermined destination and does not provide a general-purpose SOCKS proxy.

9
MCQeasy

Why might a penetration tester use a 'jump host' when attempting to access an internal network segment?

A.To increase the bandwidth of the connection.
B.To hide the attacker's IP from the destination server.
C.Because the target segment is firewalled from the attacker.
D.To provide a GUI-based interface for database management.
AnswerC

A jump host is used when the attacker cannot directly communicate with the target network. By establishing a tunnel through the jump host, the attacker effectively extends their reach into the internal segment, circumventing the firewalls that prevent direct connections from the outside world to the target internal resources.

Why this answer

A jump host acts as an intermediary system that has dual-homed network access, connecting the untrusted zone (or the internet) to the restricted internal segment. By compromising the jump host, the tester gains a foothold within the internal network. This is a standard strategy because direct access to backend servers is often blocked by firewalls, and the jump host is often the only permitted pathway for remote administration.

Exam trap

Candidates frequently mistake jump hosts for simple proxies or VPNs. They fail to recognize that the jump host's primary purpose is bridging two distinct network segments that have no direct routing.

10
MCQmedium

In the context of pivoting, what is 'double pivoting'?

A.Running two separate SSH processes to the same host.
B.Using two different protocols simultaneously for redundancy.
C.Tunneling through one compromised host to reach another.
D.Encrypting the tunnel twice for double security.
AnswerC

Double pivoting involves establishing a chain of tunnels through a sequence of compromised hosts. This allows the attacker to reach deep into an internal network where the target is separated by multiple firewalls or isolated VLANs that are only reachable by sequentially pivoting through multiple intermediate jump hosts.

Why this answer

Double pivoting involves chaining two or more tunnels together to reach a network segment that is not reachable from the primary jump host. You use the first compromised host to tunnel into a second host, then tunnel from that second host into the target network. This is a complex but necessary technique when navigating multi-layered network security architectures where subnets are isolated from each other.

Exam trap

Candidates confuse double pivoting with simple multi-homing. They fail to realize that double pivoting requires chaining two distinct tunnel processes, not just accessing a machine with two network cards.

11
MCQhard

Refer to the exhibit. You are attempting a local port forward using PLINK, but receive a 'Connection refused' error. Which of the following is the most likely cause?

A.The internal target (10.0.0.5) is down.
B.The SSH service on the jump host is unavailable.
C.The password provided is incorrect.
D.The local port 8080 is already in use.
AnswerB

Connection refused implies the target IP address is reachable, but the specific port (typically 22 for SSH) is closed or not accepting connections. This is common if the SSH service is disabled, misconfigured, or if an egress firewall on your local network is blocking outbound connections to port 22.

Why this answer

A 'Connection refused' error typically indicates that the SSH service is not running on the target jump host (192.168.1.10) or that a firewall is blocking the connection to port 22. Even if the internal destination (10.0.0.5:80) is unreachable, the SSH connection to the jump host itself must be established first. If the initial SSH handshake fails, the tunnel cannot be created.

Exam trap

Candidates often assume a 'Connection refused' error means the internal target service is down, overlooking the fact that the initial SSH connection to the jump host failed completely.

12
MCQmedium

You have gained a foothold on an internal Linux host (10.10.10.20) that can reach a segregated network containing a web server at 192.168.100.50:80. Your attack machine cannot reach 192.168.100.50 directly. You want to use the compromised host to forward traffic from your machine's local port 8080 to 192.168.100.50:80. Which SSH command should you run from your attack machine?

A.ssh -D 8080 user@10.10.10.20
B.ssh -L 80:192.168.100.50:8080 user@10.10.10.20
C.ssh -R 8080:192.168.100.50:80 user@10.10.10.20
D.ssh -L 8080:192.168.100.50:80 user@10.10.10.20
AnswerD

This command creates a local port forward: it listens on your local port 8080 and forwards connections through the SSH tunnel to 192.168.100.50:80 from the perspective of the compromised host. This is exactly what is needed to reach the internal web server via the pivot.

Why this answer

To reach an internal service through a compromised host, you use SSH local port forwarding. The -L option binds a local port on your machine and tunnels connections through the SSH server to the specified destination. The correct syntax maps local port 8080 to 192.168.100.50:80 via the pivot host.

This allows you to access the internal web server by connecting to localhost:8080.

Exam trap

The trap here is confusing local and remote port forwarding: remembering that -L forwards local traffic to a remote destination, while -R does the opposite, is crucial.

13
MCQeasy

You are using Proxychains to route your Nmap scan through a SOCKS proxy. Which configuration file must you modify to ensure that the proxy settings are correctly applied during your scan?

A./etc/nmap/nmap.conf
B./etc/proxychains.conf
C./etc/ssh/ssh_config
D./etc/network/interfaces
AnswerB

This is the default configuration file for Proxychains. It defines the proxy servers, the chain type, and other operational parameters. Editing this file to add your SOCKS proxy entry at the bottom is the standard procedure to enable Proxychains to successfully route traffic through your established pivot tunnel.

Why this answer

Proxychains relies on a configuration file to determine which proxy servers to use for traffic redirection. Misconfiguring this file is a common pitfall that leads to scans either failing or leaking traffic directly from your machine. Correctly setting the proxy type, IP address, and port ensures that all traffic generated by the tools you prefix with proxychains is routed through the specified tunnel, maintaining your stealth and reachability.

Exam trap

Candidates often waste time searching for dynamic command-line flags to set proxy details, forgetting that Proxychains relies entirely on editing a static local configuration file.

14
MCQmedium

You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?

A.ssh -R 8080:192.168.1.50:80 user@jump-host
B.ssh -D 8080 user@jump-host
C.ssh -L 8080:192.168.1.50:80 user@jump-host
D.ssh -fN -L 192.168.1.50:80:8080 user@jump-host
AnswerC

Local port forwarding uses the -L flag to map a local port (8080) to the destination internal IP and port (192.168.1.50:80). This connection is tunneled through the SSH session, allowing you to access the web application by pointing your local web browser to http://127.0.0.1:8080, effectively bypassing the firewall limitations.

Why this answer

Local port forwarding allows you to tunnel traffic from a local port to a destination reachable by the SSH server. By mapping a local port to the internal web server's address, you bypass network restrictions imposed by firewalls. This technique is fundamental for pivoting through compromised hosts, enabling tools like Burp Suite or browsers to interact with internal services as if they were running locally, which is vital for further web application vulnerability assessment.

Exam trap

Candidates often mix up the local and remote port numbers in the -L command syntax, leading to connection failures because the local port is not bound to the intended target service.

15
MCQmedium

You have compromised a Linux host that sits on both your external network and an isolated internal network containing a Windows server with SMB exposed. From your Kali machine you need to interact with the SMB service as if it were local. Which single command creates the correct tunnel?

A.ssh -D 445 user@10.10.10.10
B.ssh -R 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
C.ssh -L 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
D.ssh -L 0.0.0.0:445:10.10.10.20:445 user@10.10.10.10
AnswerC

This local forward binds port 445 on your own loopback and tunnels traffic through the pivot at 10.10.10.10 to the internal SMB host 10.10.10.20 on port 445. Because the pivot can reach both networks, your SMB client can now connect to 127.0.0.1:445 and reach the internal server without exposing the port on your external interface.

Why this answer

A local port forward created with -L makes your attacking machine listen on a chosen local address and port, then relays that traffic through the SSH server to a destination reachable from the pivot. Binding to 127.0.0.1 keeps the forwarded port private to your host, which is appropriate when only your local tools need to reach the internal SMB service. Remote and dynamic forwards solve different problems and do not give a direct local-to-internal mapping here.

Exam trap

The trap here is confusing the direction of -L and -R, assuming a remote forward will somehow expose an internal service to your local machine.

16
MCQeasy

A penetration tester has compromised a Linux host and wants to use it as a pivot to reach an internal network. The tester decides to use SSH local port forwarding to access an internal web server at 10.0.0.5:80 from their attacking machine. Which command should the tester run on the attacking machine?

A.ssh -D 8080 user@pivot
B.ssh -R 8080:10.0.0.5:80 user@pivot
C.ssh -L 8080:10.0.0.5:80 user@pivot
D.ssh -L 10.0.0.5:80:8080 user@pivot
AnswerC

This command creates a local port forward: the attacking machine listens on port 8080 and forwards any connections through the SSH tunnel to the pivot host, which then connects to 10.0.0.5:80. This allows the tester to access the internal web server by browsing to localhost:8080 on their machine.

Why this answer

Local port forwarding with SSH uses the -L local_port:remote_host:remote_port syntax. The attacking machine listens on the local port and forwards connections through the SSH tunnel to the pivot, which then connects to the specified remote host and port. This is the standard way to access an internal service from an external machine.

Exam trap

The trap here is mixing up local and remote port forwarding, or misordering the parameters in the -L option, which can lead to a non-functional tunnel or an error.

17
MCQeasy

You have a Windows host with outbound internet access but want to avoid installing a full agent. You decide to use Chisel to pivot. Which statement accurately describes how Chisel establishes the tunnel in this scenario?

A.Chisel encrypts traffic only when the --tls flag is used, and otherwise sends plaintext over the wire.
B.The Chisel server must run on the compromised host so the client on your attacking machine can pull traffic from the internal network.
C.The Chisel client on the compromised host connects outbound to the Chisel server on your attacking machine, and the server can expose a SOCKS proxy on your side.
D.Chisel requires a kernel TUN interface on both endpoints to carry the tunneled traffic.
AnswerC

Chisel uses a client-server model where the client dials the server. Running the server with reverse tunneling and SOCKS options lets the server-side listener present a SOCKS proxy on your attacking machine, while the client on the victim maintains the outbound connection. This fits hosts that cannot accept inbound connections.

Why this answer

Chisel's client dials the server, so a compromised host with only outbound access can still establish a tunnel. When the server is started with reverse tunneling and SOCKS support, the operator gets a SOCKS proxy locally that routes through the client into the internal network. This makes Chisel a practical choice when a full agent is undesirable.

Exam trap

The trap here is reversing the client and server roles and assuming the tool requires a routed interface like a TUN device.

18
MCQhard

Refer to the exhibit. If you attempt an SSH remote port forward (-R) to bind a port to all network interfaces on the server, what will happen?

A.The request will be rejected and the connection will close.
B.The port will be bound to 127.0.0.1 instead of 0.0.0.0.
C.The server will allow the binding because it is a superuser request.
D.The connection will hang indefinitely.
AnswerB

Because GatewayPorts is set to 'no', the SSH daemon forces all forwarded ports to bind to the loopback interface, regardless of the user's request. This effectively enforces a security policy where only local processes on the jump host can interact with the forwarded port, preventing external access.

Why this answer

The 'GatewayPorts no' setting in the sshd_config specifically prevents forwarded ports from binding to any interface other than the loopback (localhost). Even if the user specifies 0.0.0.0 or a public IP in their SSH command, the server will ignore this request and bind the port only to 127.0.0.1. This is a common security hardening measure to prevent unauthorized access to forwarded ports from external networks.

Exam trap

Candidates assume that specifying 0.0.0.0 in an SSH command overrides server-side configurations, forgetting that 'GatewayPorts no' strictly enforces loopback-only bindings on the remote host.

19
MCQhard

You have compromised a dual-homed Linux host that can reach an internal network. You want to use it as a SOCKS proxy so that tools like Nmap and Metasploit can route traffic into that internal network. You decide to use SSH dynamic port forwarding. Which command should you run from your attacking machine to create a SOCKS proxy on local port 1080 that tunnels through the compromised host?

A.ssh -D 1080 -L 1080:127.0.0.1:1080 user@compromised-host
B.ssh -L 1080:compromised-host:1080 user@compromised-host
C.ssh -D 1080 user@compromised-host
D.ssh -R 1080 user@compromised-host
AnswerC

The -D option enables dynamic port forwarding, turning the SSH client into a SOCKS proxy listening on local port 1080. Applications configured to use that SOCKS proxy will send traffic through the SSH tunnel to the compromised host, which then makes the outbound connections. This matches the requirement to route tools into the internal network without specifying individual static forwards.

Why this answer

Dynamic port forwarding with ssh -D creates a local SOCKS proxy that forwards connections through the SSH server. Applications configured to use that SOCKS proxy can reach any host the SSH server can reach, making it ideal for pivoting into internal networks with tools like Nmap and Metasploit.

Exam trap

The trap here is assuming that a static local forward (-L) can act as a SOCKS proxy, when only dynamic forwarding (-D) provides that capability.

20
MCQmedium

During an internal penetration test, you gain shell access to a Linux machine. You want to pivot deeper into a segmented internal network that is completely unreachable directly from your attack host. Which tunneling approach establishes a true layer 2 network tunnel by creating a virtual network interface, allowing you to route raw Ethernet frames and perform ARP scanning?

A.Local port forwarding using SSH (-L flag)
B.Remote port forwarding using SSH (-R flag)
C.Setting up a TAP network interface tunnel
D.Dynamic port forwarding using an SSH SOCKS proxy (-D flag)
AnswerC

A TAP interface operates at the Data Link Layer (Layer 2) of the OSI model, capturing and tunneling raw Ethernet frames. This enables protocols like ARP and allows attackers to perform comprehensive ping sweeps and layer 2 scanning through the pivot host.

Why this answer

Creating a TUN or TAP device using tools like sshuttle or OpenVPN establishes a Layer 3 or Layer 2 tunnel respectively. A TAP interface operates at Layer 2, allowing raw Ethernet frames to cross the boundary. This capability is essential when standard TCP/UDP port forwarding fails because you need to execute broadcast-dependent reconnaissance or vulnerability scanning against hidden internal subnets.

Exam trap

Many candidates confuse Layer 2 TAP interfaces with Layer 3 TUN interfaces or simple SSH port forwarding. Remember that port forwarding only handles TCP or UDP streams, whereas Layer 2 tunneling allows raw framing and ARP scanning across boundaries.

Ready to test yourself?

Try a timed practice session using only Port Redirection and Tunneling questions.