Courseiva

PEN-200 Port Redirection and Tunneling Practice Question

During an internal assessment, you compromise a Windows host that can reach a segmented network. You want to run a SOCKS proxy on the compromised Windows host so that your Kali tools can reach internal targets through it. Which tool is specifically designed for this purpose and commonly used in PEN-200 scenarios?

⚠ Common exam trap

The trap here is assuming any networking tool can act as a SOCKS proxy, when only dedicated tunneling tools like Chisel implement the SOCKS protocol on the server side.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Chisel

Chisel is purpose-built for tunneling and can run as a SOCKS proxy server on a compromised host, with a client on the attacker machine connecting back or forward. This makes it well suited for Windows pivots where you want a single binary that handles HTTP transport and SOCKS. Netcat, Nmap, and Wireshark serve different roles and cannot provide a SOCKS proxy service for arbitrary tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Chisel

    Why this is correct

    Chisel is a fast TCP/UDP tunnel transported over HTTP and secured with SSH, and it can operate as a SOCKS proxy server on the compromised host. Running the Chisel server on the Windows pivot and connecting a client from Kali with a reverse SOCKS configuration gives you a proxy into the internal network. It is a standard tool for pivoting when SSH is unavailable or inconvenient.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a packet capture and analysis tool. It can observe traffic on an interface but does not forward or proxy connections, and it certainly does not implement SOCKS. Using it on a pivot would only help with traffic analysis, not with routing your Kali tools into the segmented network.

  • ✗

    Netcat

    Why it's wrong here

    Netcat is a general-purpose networking utility for reading and writing data across TCP or UDP connections, often used for bind or reverse shells. It does not implement the SOCKS protocol, so it cannot act as a SOCKS proxy for your tools. While you can relay a single connection with netcat, it lacks the multiplexing and protocol handling needed for a functional proxy.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a port scanner and network mapping tool. Although it supports proxying its own scans through SOCKS4 proxies with the --proxies option, it cannot act as a SOCKS proxy server for other tools. The scenario requires a proxy service on the Windows pivot, which Nmap does not provide.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.